Privacy Policy - Gardeners Hatton

This Privacy Policy explains how Gardeners Hatton collects, uses, stores, shares, and protects personal data when providing gardening services. It applies to all Gardeners Hatton customers in the area and to anyone who enquires about our services, receives a quotation, books a visit, or otherwise interacts with us. We are committed to handling personal information in a lawful, fair, transparent, and secure manner in line with the UK GDPR and the Data Protection Act 2018.

1. Who We Are

Gardeners Hatton provides gardening and outdoor maintenance services to residential and commercial customers. In the context of this policy, we act as the data controller for personal data we collect directly from customers and prospective customers. This means we decide how and why your personal information is processed for the purposes described in this policy.

2. Personal Data We Collect

We only collect the personal data that is necessary to provide our services, manage our relationship with you, and meet legal or regulatory obligations. Depending on how you use our services, we may collect the following categories of information:

  • Identity details, such as your name or the name of your business or property owner.
  • Contact details, such as address, telephone number, and email address.
  • Service information, including details of the work requested, garden preferences, access instructions, and service history.
  • Billing and payment information, where needed to issue invoices, confirm payments, or manage account records.
  • Communication records, such as messages, notes from phone calls, complaints, and feedback.
  • Technical information, if you interact with us through digital systems, such as basic device or usage data collected for security and operational purposes.

We do not seek to collect unnecessary information. We also ask that you do not provide special category data unless it is essential and relevant to our services. Special category data may include information about health, religion, political views, ethnicity, or other sensitive details. If such information is provided, we will only process it where lawful and necessary.

3. How We Use Your Data

We process personal data only for specific and legitimate purposes. These include:

  • responding to enquiries and arranging quotations;
  • delivering gardening services and managing appointments;
  • maintaining customer records and service notes;
  • issuing invoices and processing payments;
  • handling complaints, requests, and feedback;
  • meeting legal, tax, insurance, and accounting obligations;
  • protecting the security of our staff, customers, and business operations;
  • improving our service quality and customer experience.

We will not use your personal data for purposes that are incompatible with the original reason it was collected unless we have a lawful basis to do so and you are informed where required.

4. Lawful Basis for Processing

Under data protection law, we must have a valid lawful basis before processing your data. Gardeners Hatton relies on the following bases:

Contract

We process personal data when it is necessary to perform a contract with you or to take steps at your request before entering into a contract. For example, this applies when we provide a quotation, confirm a booking, carry out gardening work, or manage ongoing service arrangements.

Legal Obligation

We may process personal data where required to comply with legal obligations, including accounting, tax record-keeping, insurance, and other statutory duties.

Legitimate Interests

We may process certain data where it is necessary for our legitimate interests and where your rights do not override those interests. This may include maintaining secure business records, preventing fraud, improving service delivery, resolving disputes, and managing operational efficiency. When relying on this basis, we ensure that processing is proportionate and limited to what is reasonably necessary.

Consent

In limited situations, we may rely on your consent, particularly where the law requires it. Where consent is used, you may withdraw it at any time. Withdrawal of consent will not affect processing carried out before the withdrawal.

5. Data Sharing and Processors

We may share personal data with trusted third parties, known as processors, who act on our behalf and only under our instructions. These processors help us operate our services efficiently and securely. They may include:

  • Accounting and bookkeeping providers, used to manage financial records and compliance.
  • Payment service providers, used to process card or electronic payments.
  • IT and cloud storage providers, used for secure data storage, communication, and backup.
  • Administrative service providers, used for scheduling, invoicing, or business support functions.
  • Professional advisers, such as insurers, auditors, or legal advisers where necessary.

We require all processors to protect personal data, keep it confidential, and process it only for the agreed purpose. We do not sell your personal data. We do not share it with third parties for their own marketing purposes.

In some cases, data may be shared with public authorities or regulatory bodies where required by law or where necessary to establish, exercise, or defend legal claims.

6. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, or reporting requirements. Retention periods depend on the type of information and the reason for holding it.

  • Customer and service records are typically kept for the duration of the customer relationship and for a reasonable period afterwards.
  • Financial and invoicing records are retained for the period required by tax and accounting laws.
  • Communication records may be kept where needed to resolve disputes, maintain service quality, or evidence instructions.
  • Technical and security logs are retained only for as long as needed for operational security and system integrity.

When personal data is no longer required, we will delete it securely or anonymise it so it can no longer identify you. Retention periods may vary depending on the nature of the data and any legal obligations that apply.

7. Security of Your Data

We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, confidentiality obligations, and regular review of our data-handling procedures. While no system is completely risk-free, we work to ensure your data is handled responsibly and with care.

8. Your Rights

Under data protection law, you have a number of rights in relation to your personal data. These may include:

  • Right of access – to request a copy of the personal data we hold about you.
  • Right to rectification – to ask us to correct inaccurate or incomplete data.
  • Right to erasure – to request deletion of your data in certain circumstances.
  • Right to restrict processing – to ask us to limit how we use your data in some cases.
  • Right to object – to object to processing based on legitimate interests, and in some cases direct marketing.
  • Right to data portability – to receive certain data in a structured, commonly used format, where applicable.
  • Right to withdraw consent – where processing is based on consent.

To protect your privacy, we may need to verify your identity before acting on a request. Some rights are subject to exceptions and may not apply in every situation. We will explain the outcome of any request in a clear and timely manner.

9. International Transfers

Where personal data is stored or processed using third-party services outside the UK, we will ensure that appropriate safeguards are in place to protect it. These may include adequacy regulations, contractual protections, or other lawful transfer mechanisms. We will only transfer data where it is necessary and where suitable protections are available.

10. Children’s Data

Our services are intended for adults responsible for properties, gardens, or businesses. We do not knowingly collect personal data from children unless it is necessary and provided by a parent, guardian, or authorised adult in connection with our services. If we become aware that we have collected children’s data unlawfully, we will take steps to delete it.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in law, our services, or our data-handling practices. Any updated version will replace the previous version once in effect. We encourage customers to review this policy periodically to stay informed about how we protect personal data.

12. Summary of Our Commitment

Gardeners Hatton is committed to processing personal data with respect, transparency, and accountability. We collect only what we need, use it for lawful and clearly defined purposes, retain it for no longer than necessary, and protect it through appropriate safeguards. If you are a customer in the area, your privacy matters to us, and we will continue to handle your information in a way that supports trust and compliance.

Gardeners Hatton

This Privacy Policy explains how Gardeners Hatton handles personal data for all customers in the area, including lawful basis, retention, processors, and user rights.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.