Privacy Policy - Gardeners Romford

Gardeners Romford is committed to protecting the privacy and personal data of all customers in the Romford area. This Privacy Policy explains how we collect, use, store, share, and protect personal information when we provide gardening services to residents, landlords, letting agents, and commercial clients throughout the local area. It also sets out the rights available to individuals under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This policy applies to all Gardeners Romford customers in the area, including anyone who enquires about our services, receives a quote, books a visit, or engages us for ongoing or one-off garden work. We aim to keep all personal information lawful, fair, transparent, and secure.

1. Data We Collect

We only collect personal data that is necessary for providing and managing our services. The type of information we may collect includes:

  • Identity information, such as name and title.
  • Contact information, such as address, telephone number, and email address.
  • Service details, such as the type of gardening work requested, property access notes, preferred visit times, and service history.
  • Billing information, such as payment status, invoice records, and transaction details.
  • Communications, including messages, feedback, complaints, and service-related correspondence.
  • Technical data, if you interact with our digital systems, such as basic device or usage information collected for security and service improvement.

We do not intentionally collect special category data unless it is strictly required and you have provided it yourself in connection with a service request. We ask customers not to share unnecessary sensitive information unless it is relevant to the service being arranged.

2. How We Use Your Data

We use personal data for the following purposes:

  • To respond to enquiries and provide quotations.
  • To deliver gardening services and manage appointments.
  • To issue invoices, process payments, and maintain business records.
  • To communicate with customers about bookings, schedule changes, and service updates.
  • To handle complaints, requests, and customer support matters.
  • To improve service quality, safety, and operational efficiency.
  • To comply with legal obligations, tax requirements, and regulatory responsibilities.
  • To prevent fraud, misuse, or unauthorised access to our systems and records.

We only use personal information in ways that are compatible with the reasons it was collected. Where appropriate, we may also use data in a pseudonymised or aggregated form for internal analysis, provided that it does not identify individual customers.

3. Lawful Basis for Processing

Under UK GDPR, we must have a lawful basis for processing personal data. Gardeners Romford relies on one or more of the following lawful bases depending on the situation:

Contract

We process personal data where it is necessary to perform a contract or to take steps at your request before entering into a contract. This includes preparing quotes, arranging visits, carrying out gardening work, and managing invoices.

Legal Obligation

We process certain records where required to meet legal obligations, including accounting, taxation, insurance, and record-keeping duties.

Legitimate Interests

We may process data where it is necessary for our legitimate business interests and where those interests are not overridden by your rights and freedoms. This may include maintaining customer records, improving services, protecting systems, or responding to enquiries.

Consent

In limited circumstances, we may rely on consent, for example where you agree to receive optional marketing communications or where another lawful basis is not appropriate. If processing is based on consent, you may withdraw it at any time.

Gardeners Romford carefully assesses each processing activity to make sure the chosen lawful basis is appropriate and proportionate.

4. Data Sharing and Processors

We do not sell personal data. However, we may share limited information with trusted third parties known as processors or service providers, but only where necessary for our business operations and always subject to appropriate safeguards.

Examples of processors may include:

  • IT and cloud service providers that host secure data storage or communication systems.
  • Accountants or bookkeeping providers who support invoicing, tax, and financial records.
  • Payment service providers who help process transactions securely.
  • Administrative or scheduling tools used to manage service bookings and customer records.

Where processors handle personal data on our behalf, they are required to act only on our instructions, keep information confidential, and implement appropriate technical and organisational security measures. We may also disclose data where required by law, court order, or a valid request from a regulatory or enforcement authority.

Any third party receiving personal data must only use it for the agreed purpose and must not retain it longer than necessary.

5. Data Retention

We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.

Retention periods may vary depending on the type of data and the reason for processing. In general:

  • Quote and enquiry records may be kept for a reasonable period to manage follow-up communication and service history.
  • Customer service and contract records may be retained for the duration of the service relationship and for a period after completion.
  • Financial and tax-related records may be kept for the period required by law.
  • Complaint records may be kept as long as needed to resolve issues and demonstrate proper handling.

When data is no longer required, we will securely delete, anonymise, or destroy it. We apply retention practices designed to ensure that information is not stored longer than necessary.

6. Security of Personal Data

We take data security seriously and use appropriate measures to protect personal information from loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage practices, staff confidentiality obligations, and regular review of data handling processes.

While no system can be guaranteed completely secure, we work to reduce risks and respond promptly to any suspected data incident. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will act in accordance with applicable legal requirements.

7. Your Rights

Individuals whose data we process have a number of rights under data protection law. These rights may include:

  • Right of access - to request a copy of the personal data we hold about you.
  • Right to rectification - to ask us to correct inaccurate or incomplete information.
  • Right to erasure - to request deletion of personal data in certain circumstances.
  • Right to restrict processing - to ask us to limit how we use your data in certain cases.
  • Right to object - to object to processing based on legitimate interests or direct marketing.
  • Right to data portability - to receive certain data in a structured, commonly used format where applicable.
  • Right to withdraw consent - where processing relies on consent.

You also have the right to lodge a complaint with the UK Information Commissioner's Office if you believe your data protection rights have been infringed. Before doing so, we encourage you to raise any concerns with us first so we can try to resolve the matter fairly and promptly.

8. Marketing Communications

If we send optional marketing messages, we will only do so where permitted by law. You can choose not to receive such communications, and you may withdraw your preference at any time. Service-related messages, such as booking updates or invoice information, are not marketing and may still be necessary for us to provide our services.

We aim to ensure that all customer communications are relevant, proportionate, and respectful.

9. Children’s Data

Our services are aimed at adults and property owners or authorised representatives. We do not knowingly collect personal data from children as part of our normal business activities. If we become aware that such data has been collected unintentionally, we will take appropriate steps to delete it unless there is a lawful reason to retain it.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in the law, our services, or our data handling practices. Any revised version will apply from the date it is made available. We encourage customers to review this policy periodically so they remain informed about how personal data is handled.

11. Summary of Our Approach

At Gardeners Romford, we only collect what is necessary, use it for clear and lawful purposes, retain it for appropriate periods, and share it only with trusted processors or where required by law. We respect the rights of our customers in the Romford area and remain committed to safeguarding personal data with care and transparency.

Gardeners Romford

Gardeners Romford is committed to protecting the privacy and personal data of all customers in the Romford area.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.