Privacy Policy for Gardeners Crystal Palace Customers
This Privacy Policy explains how Gardeners Crystal Palace collects, uses, stores, shares, and protects personal data relating to customers in the Crystal Palace area. It applies to all Gardeners Crystal Palace customers in the area, including people who request quotes, make bookings, receive garden services, or otherwise contact us in connection with our work. We are committed to handling personal data in a lawful, fair, and transparent way in accordance with the UK General Data Protection Regulation and the Data Protection Act 2018.
Who We Are
Gardeners Crystal Palace provides gardening and related services to customers in and around Crystal Palace. In the context of this policy, we are the controller of the personal data we collect directly from customers and prospective customers. This means we decide how and why personal data is used. We take privacy seriously and only collect information needed to deliver our services, manage our business, and meet our legal obligations.
Personal Data We Collect
We may collect personal data that you provide to us directly when you ask for information, request a quote, arrange a visit, confirm a booking, make a payment, or communicate with us about a service. This may include your name, address, service location, and details about the work you would like completed. We may also collect information about access arrangements, property or garden preferences, service history, and notes relevant to the services we provide.
In some cases, we may collect limited technical information when you visit our website or interact with our digital systems, such as basic device, browser, or usage data. We may also receive personal data from third parties where you have asked them to refer you to us, or where another person books a service on your behalf. We only collect data that is necessary and relevant for the purposes described in this policy.
How We Use Your Data
We use personal data to respond to enquiries, provide quotes, schedule appointments, deliver gardening services, issue invoices, process payments, maintain service records, handle complaints, and improve our customer experience. We may also use your information to communicate about changes to appointments, service updates, or matters connected with an ongoing job.
We may use personal data for administration, accounting, tax, business management, and quality control. Where permitted by law, we may also use certain information to prevent fraud, protect our rights, and keep accurate records of work carried out. We do not sell personal data.
Lawful Basis for Processing
We only process personal data where we have a lawful basis to do so. The main lawful bases we rely on are contract, legal obligation, legitimate interests, and consent where appropriate. We process data on the basis of contract when it is necessary to provide a quote, arrange services, carry out work, or manage your account. We process data on the basis of legal obligation where we must keep records for tax, accounting, or regulatory purposes.
We may rely on legitimate interests for activities such as managing our business, maintaining service quality, communicating about services, and keeping records of previous work, provided that your interests and rights do not override those interests. Where we ask for your consent, we will make that clear at the time and you may withdraw consent at any time. If consent is withdrawn, this will not affect processing already carried out lawfully before withdrawal.
Sharing Your Data and Processors
We may share personal data with carefully selected processors and service providers who help us operate our business. These may include accounting providers, payment processors, scheduling or administrative software providers, IT and data storage providers, website support providers, and other professional advisers who help us with business operations. These processors are only allowed to process personal data on our instructions and must keep it secure and confidential.
We may also disclose personal data where required by law, where necessary to establish or defend legal claims, or where needed to protect our rights, customers, staff, or property. If a processor or service provider is used, we take steps to ensure appropriate data protection safeguards are in place. We only share the minimum personal data necessary for the relevant purpose.
Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, or for longer where required by law. Customer and service records are generally retained for the duration of the customer relationship and for a reasonable period afterwards in case of queries, disputes, warranty issues, accounting needs, or legal obligations. Financial and tax-related records are typically kept for the periods required by law.
When personal data is no longer needed, we securely delete it or anonymise it so that it can no longer identify you. In deciding how long to keep data, we consider the nature of the information, the purposes of processing, legal requirements, and the risk of harm from continued storage. We apply retention practices designed to avoid keeping personal data longer than necessary.
Your Rights
Under data protection law, you have a number of rights in relation to your personal data. These may include the right to access the data we hold about you, the right to correct inaccurate or incomplete information, the right to request deletion of your data in certain circumstances, the right to restrict or object to some forms of processing, and the right to data portability where applicable. Where we rely on consent, you also have the right to withdraw that consent.
You may also have the right to object to processing based on legitimate interests in certain situations. Some rights may be limited by law, for example where we must keep data for legal, accounting, or security reasons. If you wish to exercise any of your rights, we will respond in line with applicable data protection law and may ask for information to verify your identity before dealing with your request.
Security
We use appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, or disclosure. These measures may include access controls, secure storage, staff confidentiality obligations, and careful management of third-party systems. While no method of storage or transmission is completely risk-free, we take reasonable steps to keep your information secure.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply from the time it is published or otherwise made available. We encourage customers to review this policy periodically so they remain informed about how their personal data is used.
Contact and Complaints
If you have questions about this Privacy Policy, concerns about how your data is handled, or wish to exercise your rights, you may contact us using the details provided through our usual customer contact channels. You also have the right to lodge a complaint with the Information Commissioner’s Office if you believe your data protection rights have been infringed. We would appreciate the chance to address any concerns first and will aim to respond promptly and constructively.
