Privacy Policy - Gardeners St Helier
This Privacy Policy explains how Gardeners St Helier collects, uses, stores, shares, and protects personal data relating to its customers in the St Helier area. It applies to all Gardeners St Helier customers in the area, including individuals who enquire about services, request quotations, book appointments, receive garden maintenance, or otherwise engage with our services. We are committed to handling personal data lawfully, fairly, transparently, and in a way that respects your rights under the UK GDPR and the Data Protection Act 2018.
By using our services, you acknowledge that personal data may be processed for the purposes described in this policy. We only collect data that is necessary for legitimate business and service-related purposes, and we aim to keep it accurate, secure, and retained only for as long as needed.
1. Data We Collect
Gardeners St Helier may collect several categories of personal data depending on how you interact with us. The exact data collected will vary according to the nature of the service, the communication channel used, and any information you choose to provide.
Information you provide directly
- Identity details such as your name.
- Contact details such as address, email address, and telephone number.
- Service details including property access notes, preferred appointment times, garden requirements, and instructions for the work requested.
- Billing and transaction information if needed for invoicing, payment processing, and records.
- Communication records including messages, queries, complaints, and feedback.
Information collected automatically
When you contact us electronically or interact with our systems, we may collect limited technical information such as device data, communication timestamps, and basic usage details. This information is used to support security, improve service performance, and maintain accurate records.
Information from third parties
We may receive personal data from trusted third parties when necessary for service delivery, administration, or legal compliance. This may include information from subcontractors, payment providers, property managers, or professional advisers. We will only use such information where it is appropriate and lawful to do so.
2. How We Use Personal Data
We use personal data only for specified, explicit, and legitimate purposes. These include:
- Responding to enquiries and providing quotations.
- Managing bookings, site visits, and service delivery.
- Carrying out garden maintenance, landscaping, planting, pruning, and related work.
- Handling invoices, payments, and account administration.
- Keeping service records and internal job notes.
- Communicating about changes, service updates, or customer requests.
- Managing complaints, disputes, and quality assurance.
- Meeting legal, regulatory, tax, and insurance obligations.
- Protecting the security of our operations, staff, and customers.
We do not use personal data in ways that are incompatible with these purposes. Where a new purpose arises, we will assess the legal basis and ensure the processing is consistent with data protection requirements.
3. Lawful Basis for Processing
Under the UK GDPR, we must have a lawful basis for every processing activity. Gardeners St Helier relies on the following bases where appropriate:
- Contract: We process personal data when it is necessary to provide a service you have requested, prepare a quotation, manage a booking, or complete a contract.
- Legal obligation: We may process data to comply with accounting, tax, insurance, health and safety, and other legal requirements.
- Legitimate interests: We may process data for routine business administration, service improvement, fraud prevention, record keeping, and customer communication, provided our interests are not overridden by your rights and freedoms.
- Consent: In limited situations, we may rely on consent, for example where you have clearly agreed to a particular form of communication. You may withdraw consent at any time where it is used as the lawful basis.
We do not rely on consent where another lawful basis is more appropriate. If we process special category data or data requiring additional protection, we will apply stricter safeguards and only process it where a valid legal ground exists.
4. Data Sharing and Processors
We may share personal data with carefully selected processors and service providers who help us operate our business. These third parties process data on our instructions and are required to protect it appropriately. Typical processors may include:
- IT and hosting providers that support our systems, storage, and communications.
- Payment service providers that process card or electronic payments.
- Accounting and bookkeeping providers that assist with invoicing and financial records.
- Professional advisers such as insurers, auditors, legal advisers, and tax advisers.
- Subcontractors or specialist service partners who help complete certain garden work where required.
We may also disclose personal data where necessary to comply with law, to respond to lawful requests from public authorities, to establish or defend legal claims, or to protect the rights, property, or safety of Gardeners St Helier, our customers, or others.
Where processors are engaged, we take steps to ensure appropriate contractual protections are in place, including confidentiality, security obligations, and limits on how data may be used. We do not permit processors to use personal data for their own purposes unless they are independently acting as controllers and have their own lawful basis.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, reporting, and insurance requirements. Retention periods depend on the type of record and the reason it is kept.
- Enquiry records are kept for a limited period if no service is booked, to allow follow-up and business administration.
- Customer service and job records are generally retained for the period needed to manage the relationship and any reasonable follow-up matters.
- Financial and tax records are kept for the period required by law.
- Complaint, dispute, and legal records may be retained longer where necessary to defend or establish legal claims.
When personal data is no longer needed, we will delete, anonymise, or securely archive it in accordance with our retention practices. We do not keep data indefinitely.
6. Security of Personal Data
We use appropriate technical and organisational measures to protect personal data from unauthorised access, loss, alteration, disclosure, or destruction. These measures are designed to reflect the nature of the information processed and the risks involved. Access to personal data is restricted to people who need it for legitimate business purposes.
Although no system can be guaranteed completely secure, we work to maintain a level of protection that is reasonable and proportionate. We review our practices periodically and take corrective action where needed.
7. Your Rights
As a data subject under the UK GDPR, you have a number of rights in relation to your personal data. These rights may be subject to legal exceptions or limitations. You may have the right to:
- Access your personal data and receive a copy of the information we hold about you.
- Rectification of inaccurate or incomplete data.
- Erasure of your data in certain circumstances.
- Restriction of processing in certain cases.
- Object to processing based on legitimate interests or direct marketing, where applicable.
- Data portability for information you have provided to us, where the legal conditions are met.
- Withdraw consent at any time if processing is based on consent.
If you wish to exercise any of these rights, we will assess your request and respond within the time limits required by law. To protect your privacy, we may ask for information to verify your identity before taking action.
You also have the right to raise concerns with the relevant data protection authority if you believe your rights have been infringed. We would, however, appreciate the opportunity to address any issue directly first.
8. Children’s Data
Gardeners St Helier services are intended for adult customers and property-related service arrangements. We do not knowingly collect personal data from children unless it is incidental and necessary in a household or property context, and only where lawful. If we become aware that we have collected data improperly, we will take appropriate steps to delete or correct it.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our services, or our internal practices. Any revised version will apply from the date it is made available. We encourage customers to review this policy periodically to stay informed about how personal data is handled.
10. Summary of Our Commitment
Gardeners St Helier is committed to responsible and lawful data processing. We only collect data that supports service delivery, legal compliance, and efficient administration. We use appropriate safeguards, work with trusted processors, retain data for defined periods, and respect your rights under data protection law. This policy applies to all Gardeners St Helier customers in the St Helier area.
By placing privacy, transparency, and security at the centre of our operations, we aim to maintain trust in every customer relationship.