Privacy Policy - Gardeners Hillingdon
Last updated: August 2026
This Privacy Policy explains how Gardeners Hillingdon collects, uses, stores, shares, and protects personal data. It applies to all Gardeners Hillingdon customers in the Hillingdon area, including anyone who enquires about, books, receives, or manages our gardening services. We are committed to handling personal information lawfully, fairly, and transparently in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By using our services, you acknowledge that your information may be processed as described in this policy. We aim to keep data handling clear, secure, and limited to what is necessary for providing our services and meeting legal obligations.
1. Data We Collect
We collect only the personal data needed to deliver and manage our gardening services. Depending on how you interact with us, this may include the following:
- Identity details: name, title, and any information you provide when making an enquiry or booking.
- Contact details: address, telephone number, and email address.
- Service details: property access notes, preferred appointment times, service instructions, and gardening preferences.
- Billing information: payment records, invoice details, and transaction history. We do not store full payment card details where a secure payment processor is used.
- Communications: messages, complaints, feedback, and records of conversations related to your service.
- Website and device data: if you use any online form or digital service associated with us, we may collect technical data such as IP address, browser type, and basic usage information.
We do not intentionally collect special category data unless you voluntarily provide it and it is necessary for a specific service request. Such information may include accessibility needs or health-related access notes, and it will be handled with extra care and only where appropriate.
2. How We Use Your Data
We use personal data to operate our business and deliver gardening services efficiently. This includes:
- responding to enquiries and preparing quotations;
- booking and managing appointments;
- providing gardening, maintenance, and related services;
- processing payments and issuing invoices;
- keeping records of services provided;
- handling complaints, service updates, and customer support;
- meeting legal, tax, and accounting duties;
- improving our service quality and business operations;
- protecting against fraud, misuse, or unauthorised access.
We only use data for purposes that are compatible with the reason it was collected. We do not sell your personal information.
3. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for processing personal data. Gardeners Hillingdon relies on the following lawful bases where applicable:
Contract
We process data when it is necessary to enter into or perform a contract with you. This includes taking bookings, carrying out gardening work, sending invoices, and managing your account or service arrangements.
Legal Obligation
We may process and retain information where required by law, including tax, accounting, record-keeping, insurance, and business compliance obligations.
Legitimate Interests
We may process data for our legitimate business interests, provided your rights and freedoms do not override those interests. Examples include improving services, responding to enquiries, maintaining accurate records, preventing fraud, and ensuring the safety and efficiency of our operations. Where required, we balance our interests against your privacy rights.
Consent
In limited cases, we may rely on your consent, for example for certain optional communications or when you voluntarily provide sensitive information not required for the service. You may withdraw consent at any time where consent is the basis for processing.
4. Data Sharing and Processors
We may share personal data with trusted third parties only when necessary for the delivery and administration of our services. These third parties act as processors or independent controllers depending on the role they perform.
Typical processors may include:
- Payment providers: to process secure transactions.
- Accounting and bookkeeping providers: to manage invoices, records, and tax compliance.
- IT and cloud service providers: to store data securely and support business systems.
- Communication tools: to send messages or manage customer correspondence.
- Professional advisers: such as insurers, legal advisers, or auditors where necessary.
We require processors to protect personal data, use it only on our instructions, and apply appropriate security measures. Where personal data is transferred outside the UK, we ensure that suitable safeguards are in place in accordance with data protection law.
We may also disclose data where required to comply with law, enforce agreements, protect our rights, or prevent unlawful activity.
5. Data Retention
We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, and reporting requirements. Retention periods may vary depending on the type of information and the nature of the service provided.
As a general rule:
- Enquiry data: kept for a reasonable period after the enquiry, unless it becomes a customer record.
- Customer and service records: kept while the service relationship is active and for a period afterwards to manage follow-up, disputes, or legal claims.
- Financial records: kept for the period required by tax and accounting law.
- Communications and complaints: retained as long as needed to resolve the matter and maintain records of service quality.
When data is no longer required, we will securely delete or anonymise it. We do not retain data indefinitely without a clear business or legal reason.
6. Data Security
We take appropriate technical and organisational measures to protect personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, limited user permissions, and regular review of data handling practices.
Although we work hard to protect information, no system can be guaranteed completely secure. If a data breach occurs that is likely to result in a risk to your rights and freedoms, we will act in accordance with data protection law and notify the relevant authorities and affected individuals where required.
7. Your Rights
Under data protection law, you have important rights regarding your personal data. These rights may apply depending on the circumstances and the legal basis for processing.
- Right of access: you can request a copy of the personal data we hold about you.
- Right to rectification: you can ask us to correct inaccurate or incomplete data.
- Right to erasure: you can ask us to delete your data in certain situations.
- Right to restriction: you can request limits on how we use your data in certain circumstances.
- Right to object: you can object to processing based on legitimate interests or direct marketing.
- Right to data portability: you can request certain data in a structured, commonly used format where applicable.
- Right to withdraw consent: where we rely on consent, you may withdraw it at any time.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data protection rights have been infringed. We encourage you to raise concerns with us first so we can try to resolve the issue promptly.
8. Automated Decision-Making
Gardeners Hillingdon does not use fully automated decision-making that produces legal or similarly significant effects about you. If this changes in the future, we will update this policy and provide appropriate information about the process involved.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal requirements, or data handling practices. Any updated version will apply from the date it is published. We recommend reviewing this policy periodically so you remain informed about how your data is handled.
10. Our Commitment to Privacy
Gardeners Hillingdon recognises that privacy is an essential part of trust. We therefore aim to process all personal data lawfully, fairly, and transparently, while collecting only what is necessary and keeping it only for as long as needed. We apply this policy consistently to all customers in the Hillingdon area and use sensible safeguards to reduce risk and support responsible data management.
If you are a customer or prospective customer in the area, this policy explains how your information is handled whenever you contact us, request a quote, arrange a visit, receive a service, or correspond with us about your gardening needs.