Privacy Policy - Gardeners Hook

This Privacy Policy explains how Gardeners Hook collects, uses, stores, shares, and protects personal data when providing gardening services. It applies to all Gardeners Hook customers in the area, including prospective customers, current customers, and people who contact us for quotes, bookings, or support. We are committed to handling personal data in a lawful, fair, and transparent way in line with the UK GDPR and the Data Protection Act 2018.

By using our services, requesting a quotation, making a booking, or communicating with us, you acknowledge that your personal data will be processed as described in this policy. We only collect data that is relevant and necessary for the services we provide, and we aim to keep that information accurate, secure, and retained only for as long as needed.

1. Personal Data We Collect

We collect different types of information depending on how you interact with us. This may include:

  • Identity details such as your name and, where relevant, the name of your household or business.
  • Contact details such as telephone number and email address.
  • Address information such as the property location where services are provided.
  • Service information including details about the work requested, job history, service preferences, and scheduling notes.
  • Payment information such as invoice details and transaction records. We do not store full card details where payment is processed by a third-party payment provider.
  • Communication records including emails, messages, call notes, and feedback.
  • Site and access information relevant to carrying out gardening work safely, such as access instructions, parking notes, or health and safety considerations.
  • Technical data if you interact with our digital systems, such as IP address or basic device and browser information, where applicable.

We do not intentionally collect special category data unless it is necessary and you choose to provide it, for example if it is relevant to access arrangements or safety requirements. Where such data is provided, we handle it with extra care and only for a valid legal reason.

2. How We Use Personal Data

We use personal data for the following purposes:

  • To provide quotations, confirm bookings, and deliver gardening services.
  • To manage appointments, service schedules, and customer records.
  • To communicate with you about your enquiry, service updates, and operational matters.
  • To issue invoices, process payments, and maintain financial records.
  • To improve our services, including responding to feedback and resolving issues.
  • To meet legal, accounting, insurance, and tax obligations.
  • To maintain safety, security, and service quality.
  • To protect our legitimate business interests, including defending legal claims and preventing fraud.

We only use personal data for the purposes explained in this policy or for closely related purposes that would reasonably be expected. We do not sell personal data to third parties.

3. Lawful Basis for Processing

Under GDPR, we must have a lawful basis to process your personal data. Gardeners Hook relies on one or more of the following lawful bases:

Contract

We process personal data where it is necessary to enter into or perform a contract with you. This includes providing quotes, arranging services, completing work, and handling billing.

Legal Obligation

We process information when we are required to do so by law, including tax, accounting, insurance, and record-keeping obligations.

Legitimate Interests

We may process personal data where it is necessary for our legitimate interests and where those interests are not overridden by your rights. This may include managing enquiries, service administration, improving operations, maintaining security, and keeping business records.

Consent

In limited situations, we may rely on your consent. For example, if we need permission to use information that is not otherwise covered by another lawful basis. Where consent is used, you may withdraw it at any time.

If we process special category data, we will only do so where an additional condition under GDPR applies and only when necessary.

4. Sharing Your Data and Processors

We may share personal data with trusted third parties who support our business operations. These parties act as processors or, in some cases, independent controllers. We only share information when needed and we require appropriate safeguards to protect your data.

Typical processors may include:

  • Payment service providers used to process customer payments securely.
  • Accounting and bookkeeping providers used to manage invoices, tax records, and financial reporting.
  • IT and cloud storage providers used to store data, manage communications, or maintain systems.
  • Booking or administration tools used to arrange appointments and manage service records.
  • Professional advisers such as insurers, lawyers, or accountants, where required for legitimate business purposes.

We may also disclose personal data if required by law, court order, or to protect our rights, property, customers, staff, or the public. Where data is transferred to a third party, we take reasonable steps to ensure it is handled securely and only for the intended purpose.

5. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including to meet legal, accounting, insurance, and reporting requirements. Retention periods vary depending on the type of information and the reason it was obtained.

As a general approach:

  • Quotation and enquiry records may be kept for a reasonable period to support service follow-up, business administration, and dispute resolution.
  • Customer service and invoicing records are retained for as long as needed for contract management, tax, and accounting purposes.
  • Communication records are retained where necessary to document decisions, arrangements, or issues relating to services.
  • Legal and compliance records may be retained for longer where required by law or where needed to establish, exercise, or defend legal claims.

When personal data is no longer needed, we will delete it securely or anonymise it so that it can no longer identify you.

6. Data Security

We use appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, restricted permissions, and regular review of our data handling practices.

While no system can be guaranteed completely secure, we take data protection seriously and work to reduce risks to your information. If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will act in accordance with GDPR requirements.

7. Your Rights

You have several rights under data protection law. These rights may be limited in certain situations, but we will always assess any request carefully and respond appropriately.

  • Right of access – you can request a copy of the personal data we hold about you.
  • Right to rectification – you can ask us to correct inaccurate or incomplete information.
  • Right to erasure – in some cases, you can ask us to delete your personal data.
  • Right to restrict processing – you may request that we limit how your data is used in certain circumstances.
  • Right to data portability – you may request a copy of data you provided to us in a structured, commonly used format where applicable.
  • Right to object – you can object to processing based on legitimate interests or direct marketing, where relevant.
  • Right to withdraw consent – where processing is based on consent, you may withdraw it at any time.

If you wish to exercise a right, we may need to verify your identity before responding. We aim to respond within the time limits set by law.

8. Children’s Data

Our services are not directed at children. We do not knowingly collect personal data from children unless it is necessary for a service-related reason and provided by a parent, guardian, or authorised adult. If we become aware that we have collected such data inappropriately, we will take reasonable steps to delete it.

9. International Transfers

Where any processor or service provider stores or accesses personal data outside the UK, we will ensure that appropriate safeguards are in place. This may include approved transfer mechanisms and contractual protections designed to keep your data secure and compliant with applicable law.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal duties, or data handling practices. Any updated version will apply from the time it is published or otherwise communicated. We encourage you to review this policy periodically so that you remain informed about how your personal data is used.

11. Summary of Our Commitment

Gardeners Hook is committed to responsible data protection practices. We collect only the information needed to deliver gardening services, we process it on a valid lawful basis, we share it only with appropriate processors when necessary, and we keep it only for as long as required. You also have clear rights over your personal data, and we will respect and support those rights in line with GDPR.

This policy is intended to be clear, practical, and compliant while reflecting the way we operate for customers in the area.

Gardeners Hook

This Privacy Policy explains how Gardeners Hook collects, uses, stores, shares, and protects personal data for all customers in the area.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.