Privacy Policy - Gardeners Tolworth

This Privacy Policy explains how Gardeners Tolworth collects, uses, stores, shares, and protects personal data. It applies to all Gardeners Tolworth customers in the area, including people who request quotations, book services, communicate with us, or receive gardening work at a property within Tolworth and the surrounding local area. We are committed to handling personal data lawfully, fairly, and transparently in accordance with the UK GDPR and the Data Protection Act 2018.

This policy is intended to help you understand what information we collect, why we collect it, how long we keep it, and what rights you have. We take privacy seriously and only process personal data where we have a valid reason to do so.

1. Information We Collect

We collect only the information that is necessary to provide our gardening services, manage our relationship with customers, and operate our business responsibly. The categories of data we may collect include:

  • Identity details, such as your name or the name of a business or property manager;
  • Contact details, such as address, email address, telephone number, and preferred method of communication;
  • Service and property information, including details of the garden, access arrangements, service preferences, and instructions relevant to the work;
  • Billing and payment information, such as payment status, invoices, and records of transactions;
  • Communication records, including messages, notes from calls, and service-related correspondence;
  • Technical information, where applicable, such as basic website or device data collected through standard analytics or security tools;
  • Operational records, including job history, scheduling notes, and service completion records.

We do not seek to collect sensitive personal data unless it is strictly necessary and you have chosen to provide it. If such information is ever required, it will be handled with enhanced care and only where a lawful basis applies.

2. How We Use Personal Data

We use personal data for the following purposes:

  • To provide quotations and respond to enquiries;
  • To plan, deliver, and manage gardening services;
  • To contact customers about appointments, changes, or service updates;
  • To process payments and maintain financial records;
  • To keep accurate business and service records;
  • To handle complaints, queries, or disputes;
  • To improve our services and customer experience;
  • To meet legal, tax, accounting, and regulatory obligations;
  • To protect our business, staff, customers, and property from fraud or misuse.

We only use personal data in ways that are compatible with the reason it was collected. Gardeners Tolworth does not sell personal data to third parties.

3. Lawful Basis for Processing

Under data protection law, we must have a lawful basis for each use of personal data. Depending on the situation, our lawful bases may include:

Contract

We process data when it is necessary to enter into or perform a contract with you. This includes providing quotes, arranging service visits, managing bookings, and carrying out agreed gardening work.

Legal Obligation

We may process data where we are required to do so by law, such as keeping tax records, accounting records, or complying with regulatory duties.

Legitimate Interests

We may process data where it is necessary for our legitimate business interests and where those interests are not overridden by your rights and freedoms. This may include maintaining service records, improving operations, preventing fraud, and communicating about active services.

Consent

In limited circumstances, we may rely on your consent, for example where it is appropriate to use optional marketing communications. Where consent is used, you can withdraw it at any time.

We carefully assess the lawful basis before processing data and only collect what is needed for the specific purpose.

4. Data Sharing and Processors

We may share personal data with trusted third parties who help us operate our business. These organisations act as processors or, in some cases, separate controllers. They are only allowed to use your data for the agreed purpose and must protect it appropriately.

Examples of processors or service providers may include:

  • Booking and scheduling tools used to organise jobs and appointments;
  • Accounting and invoicing providers used for financial administration;
  • IT and cloud storage providers used to securely store business records;
  • Email and communication services used to manage correspondence;
  • Payment processing services used to complete transactions safely;
  • Professional advisers, such as accountants or legal advisers, where necessary.

Where we use processors, we put appropriate data processing terms in place to ensure they handle personal data securely and lawfully. We do not authorise processors to use personal data for their own unrelated purposes.

We may also disclose data if required by law, court order, or official request from a public authority.

5. Data Retention

We keep personal data only for as long as necessary to fulfil the purpose for which it was collected, including legal, accounting, and reporting requirements. Retention periods may vary depending on the type of record and the nature of our relationship with you.

In general:

  • Customer and service records are kept for the duration of the working relationship and for a reasonable period afterwards;
  • Financial and tax records are retained for the period required by law;
  • Communication records are retained as long as needed to handle enquiries, complaints, or ongoing services;
  • Data no longer needed is securely deleted, anonymised, or destroyed.

When data is no longer required, we take steps to ensure it is removed safely from our systems and records.

6. Security of Personal Data

We use appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, misuse, alteration, or disclosure. These measures may include access controls, secure storage, staff awareness, and limited access to personal data on a need-to-know basis.

While no system can be guaranteed completely secure, we work to reduce risk and protect personal information to a high standard. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will take the required action under applicable law.

7. Your Rights

As a data subject, you have important rights in relation to your personal data. Subject to certain legal limits, you may have the right to:

  • Access the personal data we hold about you;
  • Rectification of inaccurate or incomplete data;
  • Erasure of your data in certain circumstances;
  • Restriction of processing in some situations;
  • Object to processing based on legitimate interests or direct marketing;
  • Data portability for information you have provided to us, where applicable;
  • Withdraw consent where processing is based on consent;
  • Complain to the UK Information Commissioner's Office if you believe your rights have been infringed.

We will respond to requests in line with legal requirements and may need to verify your identity before acting on a request. Some rights may not apply in every situation, for example where we must keep records for legal obligations or where a request would affect the rights of others.

8. Children’s Data

Our services are intended for adult customers, property owners, landlords, tenants, and authorised representatives. We do not knowingly collect personal data from children except where it is incidental and necessary in the context of service provision, such as family contact details included in instructions. If we become aware that we have collected data from a child inappropriately, we will take steps to delete it where appropriate.

9. International Transfers

If any processor stores or accesses data outside the United Kingdom, we will ensure that appropriate safeguards are in place to protect the information. This may include approved transfer mechanisms or ensuring the destination country provides adequate protection under applicable law.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data processing practices. Any updates will apply from the date they are published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how personal data is handled.

11. Summary of Our Commitment

Gardeners Tolworth is committed to processing personal data with care, transparency, and respect. We only collect information that is needed to provide our gardening services and run our business effectively. We rely on appropriate lawful bases, use trusted processors, retain data only for necessary periods, and support customer rights under data protection law.

By using our services, requesting a quote, or communicating with us, you acknowledge that your personal data may be processed as described in this policy.

Gardeners Tolworth

This Privacy Policy explains how Gardeners Tolworth collects, uses, stores, shares, and protects personal data for customers in the area.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.