Privacy Policy - Gardeners Cowley

This Privacy Policy explains how Gardeners Cowley collects, uses, stores, shares, and protects personal data. It applies to all Gardeners Cowley customers in the area, including anyone who requests a quotation, books a service, communicates with us, or otherwise engages our gardening services. We are committed to handling personal information fairly, lawfully, and transparently in line with the UK GDPR and the Data Protection Act 2018.

1. Who this policy applies to

This policy applies to current, former, and prospective customers, as well as individuals acting on behalf of residential or commercial properties within the Gardeners Cowley service area. It also applies to people who provide data to help us deliver a service, such as tenants, landlords, property managers, or site representatives where relevant.

2. Information we collect

We only collect personal data that is necessary for legitimate business and service purposes. Depending on how you interact with us, we may collect the following types of information:

  • Identity details such as your name and, where needed, your role or relationship to a property.
  • Contact details such as address, telephone number, and email address.
  • Service information including property details, service preferences, access instructions, scheduling information, and notes about the work requested.
  • Billing and transaction data such as payment status, invoicing details, and records of services provided.
  • Communication records including enquiries, messages, complaints, feedback, and correspondence history.
  • Technical information where relevant, such as basic website or device data used to support security and service management.

We do not intentionally collect special category data unless it is strictly necessary and you have provided it, or it is required for a specific legal or operational reason. If such data is ever needed, we will handle it with additional care and in accordance with applicable law.

3. How we use your personal data

We use personal data to provide our gardening services effectively and to manage our relationship with you. Typical uses include:

  • responding to enquiries and preparing quotes;
  • booking, carrying out, and managing gardening work;
  • maintaining service records and customer preferences;
  • handling invoices, payments, and account administration;
  • communicating about appointments, changes, or service updates;
  • resolving complaints, disputes, or service issues;
  • meeting legal, tax, accounting, and insurance obligations;
  • protecting the security of our operations, staff, customers, and property;
  • improving our services and internal processes.

We take a data minimisation approach and only use information that is relevant and necessary for the purpose for which it was collected.

4. Lawful basis for processing

Under GDPR, we must have a lawful basis for every use of personal data. We rely on the following lawful bases:

Contract

We process your data where it is necessary to enter into or perform a contract with you. This includes providing quotes, arranging services, delivering gardening work, taking payment, and managing the customer relationship.

Legitimate interests

We may process data where it is necessary for our legitimate business interests, provided those interests are not overridden by your rights and freedoms. Examples include customer service management, record keeping, service improvement, fraud prevention, and operational security. Where we rely on legitimate interests, we consider the impact on your privacy and ensure the processing is proportionate.

Legal obligation

We may process and retain information where required to comply with legal obligations, including tax, accounting, insurance, health and safety, and regulatory requirements.

Consent

In limited situations, we may rely on your consent. This will usually be for optional communications or any processing that is not covered by another lawful basis. Where consent is used, you may withdraw it at any time.

5. Sharing your data and processors

We may share personal data with trusted processors and service providers who act on our behalf and only process information under our instructions. These may include:

  • administration and bookkeeping providers;
  • payment processing services;
  • IT, cloud storage, and data backup providers;
  • communication and scheduling tools;
  • professional advisers, such as accountants or legal advisers;
  • insurers or claims handlers where necessary;
  • subcontractors or staff members involved in delivering the service.

We require processors to implement appropriate security measures and to use personal data only for the contracted purpose. We do not sell personal data. We will only share information where necessary, lawful, and proportionate.

6. International transfers

Where data is stored or processed outside the UK, we will ensure appropriate safeguards are in place. These safeguards may include UK adequacy regulations, approved contractual clauses, or other legally recognised transfer mechanisms. Our aim is to keep personal data protected to a standard consistent with UK GDPR requirements.

7. Data retention

We keep personal data only for as long as necessary for the purpose for which it was collected, including to meet legal, tax, accounting, or insurance obligations. Retention periods depend on the type of data and the reasons for processing. In general:

  • quotation and enquiry records are retained for a limited period to manage follow-up and business administration;
  • customer service and invoicing records are kept for the duration of the business relationship and for a reasonable period afterwards;
  • financial and accounting records are retained for the period required by law;
  • complaint and dispute records may be retained longer where necessary to establish, exercise, or defend legal claims.

When personal data is no longer needed, we will securely delete, anonymise, or archive it in line with our retention practices.

8. Security of your information

We use reasonable technical and organisational measures to protect personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, staff awareness, and limiting access to those who need the information for legitimate business purposes.

While no system can be guaranteed completely secure, we work to maintain appropriate safeguards and to review our practices regularly. In the event of a personal data breach that presents a risk to your rights and freedoms, we will act in accordance with applicable legal obligations.

9. Your rights under GDPR

Depending on the circumstances, you have the following rights regarding your personal data:

  • Right of access – you can request a copy of the personal data we hold about you.
  • Right to rectification – you can ask us to correct inaccurate or incomplete data.
  • Right to erasure – in some cases, you can ask us to delete your data.
  • Right to restriction – you can request limited processing in certain situations.
  • Right to data portability – you may request your data in a structured, commonly used format where applicable.
  • Right to object – you can object to processing based on legitimate interests or direct marketing.
  • Right to withdraw consent – where we rely on consent, you can withdraw it at any time.

These rights are not absolute and may be subject to legal exceptions. If you exercise a right, we may need to verify your identity before responding.

10. Children’s data

Our services are not aimed at children, and we do not knowingly collect personal data from children unless it is necessary for a service arrangement involving a household or property and is provided by an appropriate adult. Where children’s data is inadvertently collected, we will handle it carefully and delete it where appropriate.

11. Marketing communications

If we send any optional marketing communications, we will do so only where permitted by law. You may opt out at any time. We will always respect your preferences and will not use your data for marketing purposes in a way that conflicts with your rights or expectations.

12. Updates to this policy

We may update this Privacy Policy from time to time to reflect changes in law, our services, or our operational practices. When changes are made, the updated version will apply from the date it is published or otherwise communicated. We encourage customers to review the policy periodically so they remain informed about how personal data is used.

13. Summary of our approach

Gardeners Cowley is committed to handling personal information with care, transparency, and respect. We only collect what we need, we use it for clear and lawful purposes, we keep it only as long as necessary, and we share it only with trusted processors or where required by law. We also recognise and support your rights over your personal data.

By using our services within the Gardeners Cowley area, you acknowledge that this Privacy Policy applies to your personal data as described above.

Gardeners Cowley

This Privacy Policy explains how Gardeners Cowley collects, uses, stores, shares, and protects personal data.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.