Privacy Policy - Gardeners Preston
Last updated: August 2026
This Privacy Policy explains how Gardeners Preston collects, uses, stores, shares, and protects personal data relating to its customers, prospective customers, and website or service users in the Preston area. It applies to all Gardeners Preston customers in the area, including individuals who enquire about, arrange, receive, or manage gardening services, as well as anyone whose personal information is processed in connection with those services.
We are committed to handling personal data in a fair, transparent, and secure way in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy describes the types of data we process, the lawful bases we rely on, how long we keep information, the processors we may use, and the rights you have over your personal data.
1. Personal data we collect
Gardeners Preston collects only the information needed to provide, manage, and improve our gardening services. The exact information we hold depends on the nature of the service and the way you interact with us.
Categories of data
- Identity data: name, title, and any account or customer reference number.
- Contact data: address, email address, telephone number, and service location details.
- Service data: details about gardens, outdoor spaces, requested tasks, appointment notes, and service preferences.
- Billing and payment data: invoicing details, payment status, and limited transaction information needed to process or record payments.
- Communication data: messages, call notes, complaints, feedback, and correspondence history.
- Technical data: basic device, browser, or usage information where collected through digital systems used to support our services.
- Special category data: generally we do not seek this type of data. If you voluntarily provide information that may reveal health, accessibility, or other sensitive details, we will only process it where necessary and lawful.
We normally collect personal data directly from you when you request a quote, make an enquiry, book a service, communicate with us, or provide feedback. In some cases, we may receive data from a third party, such as a landlord, property manager, family member, or contractor acting on your behalf, where they have authority to share it.
2. How we use your personal data
We use your information for specific and limited purposes connected with our gardening services.
Typical uses include
- responding to enquiries and providing quotes;
- arranging and delivering gardening services;
- maintaining customer records and service notes;
- managing invoices, payments, and account administration;
- communicating appointments, service updates, and changes;
- handling complaints, disputes, and customer support requests;
- meeting legal, tax, accounting, and regulatory obligations;
- protecting our business, staff, and customers from fraud or misuse;
- improving the quality, efficiency, and safety of our services.
We will not use your personal data for purposes that are incompatible with the reasons it was collected, unless we have a lawful basis to do so and we have informed you where required.
3. Lawful basis for processing
Under UK GDPR, we must have a lawful basis before processing your personal data. Gardeners Preston relies on the following lawful bases depending on the context:
- Contract: where processing is necessary to provide a quote, enter into an agreement, deliver gardening services, or manage payment and service administration.
- Legal obligation: where we must keep records for tax, accounting, health and safety, or other legal requirements.
- Legitimate interests: where processing is needed to run and protect our business, improve services, keep records, respond to enquiries, and manage customer relationships, provided our interests do not override your rights and freedoms.
- Consent: where we rely on your consent, for example for certain optional communications or if we process special category data in limited circumstances. You can withdraw consent at any time, without affecting processing already carried out lawfully.
If we ever need to process special category data, we will ensure an additional condition under data protection law is met. We only do this when necessary and appropriate.
4. Sharing your data and processors
We may share your personal data only when necessary and only with organisations that help us operate our services or where the law requires it.
Processors and recipients
- IT and hosting providers: companies that store or support our digital records, scheduling systems, or email services.
- Accounting and bookkeeping providers: organisations that assist with invoicing, tax records, and financial administration.
- Payment service providers: providers that help process card or electronic payments.
- Customer management tools: software providers used to manage bookings, reminders, and service records.
- Professional advisers: such as insurers, legal advisers, and auditors where required.
- Public authorities: where disclosure is required by law or necessary to protect rights, safety, or legal interests.
When we use a processor, we ensure appropriate contractual safeguards are in place so your data is processed only on our instructions and with appropriate security measures. We do not sell personal data.
If data is transferred outside the UK, we will take steps to ensure it is protected using lawful transfer mechanisms and appropriate safeguards.
5. Data retention
We keep personal data only for as long as necessary to fulfil the purposes described in this policy, including legal, accounting, and service-related requirements. Retention periods vary depending on the type of information and why it is held.
Retention principles
- quotation and enquiry records are generally kept for a limited period to manage future queries, business analysis, and record-keeping;
- customer and service records are retained for the length of the service relationship and for a reasonable period afterward;
- financial and tax records are kept for the period required by law;
- complaints and dispute records are retained for as long as needed to resolve the issue and defend legal claims;
- where we no longer need data, we delete it securely or anonymise it.
In some cases, we may need to keep information longer if there is a legal claim, regulatory issue, insurance matter, or other legitimate reason to do so.
6. Your rights
Depending on the legal basis for processing and your location, you have rights over your personal data. Gardeners Preston will respond to valid requests in accordance with data protection law.
Your rights may include
- Right of access: to request a copy of the personal data we hold about you.
- Right to rectification: to ask us to correct inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restrict processing: to ask us to limit how your data is used in certain situations.
- Right to object: to object to processing based on legitimate interests, including some direct communications.
- Right to data portability: to receive certain data in a structured, commonly used format where applicable.
- Right to withdraw consent: where processing is based on consent, you may withdraw it at any time.
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you are unhappy with how your data has been handled. We encourage you to contact us first so we can try to resolve any concerns promptly and fairly.
7. Security of your data
We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, secure storage, limited permissions, staff awareness, and careful supplier selection.
Although we work hard to protect your information, no system can be guaranteed completely secure. If a data breach occurs that is likely to pose a risk to your rights and freedoms, we will act in accordance with legal requirements, which may include notifying affected individuals and relevant authorities.
8. Children’s data
Our services are generally intended for adult customers and property managers. We do not knowingly collect personal data from children unless it is provided by a parent, guardian, or authorised representative in connection with the service. If we become aware that we have collected a child’s data without appropriate authority, we will take steps to delete it or obtain the necessary permission.
9. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how their data is used.
10. Summary of our approach
Gardeners Preston processes personal data only when necessary, lawfully, and transparently. We collect limited information to provide gardening services, manage customer relationships, meet legal obligations, and maintain business records. We use trusted processors, retain data for no longer than necessary, and respect your rights under data protection law. This policy applies to all Gardeners Preston customers in the area and is intended to make our data practices clear and accountable.