1. Introduction and company information
This Privacy Policy explains how Greenhaven Garden Services Ltd collects, uses, stores, shares, and protects personal data when you use our services, contact us, visit our website, or otherwise interact with us. We are committed to handling personal data lawfully, fairly, and transparently in accordance with applicable privacy laws.
Data controller: Greenhaven Garden Services Ltd
Registered address: Unit 4, Northgate Business Park, Northgate Street, Bury St Edmunds, IP32 6AS, United Kingdom
Email: [email protected]
Phone: +44 1284 739 582
We provide garden services, which may include garden maintenance, landscaping, planting, lawn care, hedge trimming, seasonal clean-ups, soft landscaping, and related property and outdoor maintenance services.
2. Data collection and processing
We may collect and process the following categories of personal data:
- Identity data: name, title, and business name where applicable.
- Contact data: address, email address, telephone number, and other communication details.
- Service and property data: information about your garden, premises, access arrangements, service preferences, photos provided by you or taken by us for service planning, quotations, or record-keeping.
- Payment and transaction data: invoicing details, payment status, billing records, and related financial information.
- Communication data: enquiries, feedback, complaints, call records, emails, and correspondence.
- Technical data: IP address, browser type, device information, and website usage data where you visit our website.
- Marketing preferences: your consent preferences regarding direct marketing, where applicable.
We collect personal data directly from you, from your representatives, through our website, by telephone, by email, through site visits, and where necessary from third-party sources such as payment providers or business partners who help us deliver our services.
We do not intentionally collect special category data unless you choose to provide it to us, and only where there is a lawful basis to process it.
3. Purpose of data processing
We use personal data for the following purposes:
- to provide quotations, schedule visits, and deliver garden services;
- to communicate with you about appointments, service requirements, and updates;
- to manage customer accounts and maintain business records;
- to issue invoices, receive payments, and manage financial administration;
- to respond to enquiries, complaints, and requests;
- to assess site conditions, plan work, and ensure health and safety;
- to improve our services, processes, and customer experience;
- to comply with legal, tax, accounting, and regulatory obligations;
- to send marketing communications where permitted by law and where you have not opted out;
- to protect our business, staff, customers, and property from fraud, misuse, or other unlawful activity.
4. Legal basis for processing
We process personal data only where we have a valid legal basis. Depending on the circumstances, our processing is based on one or more of the following:
- Contract: where processing is necessary to enter into or perform a contract with you, including providing garden services and managing payments.
- Legal obligation: where processing is necessary to comply with applicable laws, tax rules, accounting requirements, or regulatory duties.
- Legitimate interests: where processing is necessary for our legitimate business interests, such as managing our business, improving services, preventing fraud, maintaining records, and ensuring security, provided those interests are not overridden by your rights and freedoms.
- Consent: where you have given clear consent for a specific purpose, such as certain marketing communications or processing of optional information.
- Vital interests: in rare cases, where processing is necessary to protect someone’s vital interests.
Where we rely on legitimate interests, we will consider and balance any potential impact on you and your rights.
5. Data sharing and third parties
We may share personal data with trusted third parties where necessary for the purposes described in this Privacy Policy. These may include:
- service providers that support our business operations, such as IT hosting, email, cloud storage, scheduling, and administrative services;
- payment processors, banks, and accounting software providers;
- professional advisers such as accountants, insurers, lawyers, and consultants;
- subcontractors or temporary workers engaged to help deliver services at your property;
- regulatory bodies, law enforcement, courts, or other authorities where required by law;
- marketing or communications providers, where relevant and lawful.
We require third parties to respect the security of your personal data and to process it only in accordance with our instructions and applicable law. We do not sell personal data.
6. Data transfer to third countries
Where personal data is transferred outside the United Kingdom or other applicable protected jurisdictions, we will take appropriate steps to ensure that your data receives a similar level of protection. This may include using standard contractual clauses, adequacy decisions, or other lawful transfer mechanisms.
If a third-party service provider stores or processes data in a country outside the UK, we will ensure that appropriate safeguards are in place before any such transfer occurs.
7. Storage duration
We keep personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax, insurance, and reporting requirements.
In general, retention periods are determined by the nature of the data and the purpose of processing. For example:
- customer and contract records are retained for the duration of the business relationship and for a period afterward as required for legal and operational purposes;
- financial and tax records are retained for the period required by law;
- communications and service records are retained for as long as necessary to manage queries, disputes, and service history;
- marketing records are retained until you opt out or withdraw consent, where applicable.
When personal data is no longer required, we will securely delete, anonymise, or archive it in accordance with our retention practices.
8. User rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Access: the right to request a copy of the personal data we hold about you.
- Rectification: the right to request correction of inaccurate or incomplete data.
- Erasure: the right to request deletion of your data in certain circumstances.
- Restriction: the right to request that we limit the processing of your data in certain circumstances.
- Data portability: the right to receive certain personal data in a structured, commonly used, machine-readable format and to request transfer to another controller where technically feasible.
- Objection: the right to object to processing based on legitimate interests and to object at any time to direct marketing.
To exercise any of these rights, please contact us using the details in the Contact Information section. We may need to verify your identity before responding to your request. We will respond within the timeframe required by applicable law.
9. Withdrawal of consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before your withdrawal.
You can withdraw consent by contacting us at [email protected]. If you withdraw consent, we may not be able to provide certain optional services or communications, but this will not affect processing that is based on another lawful basis.
10. Right to complain
If you have concerns about how we handle your personal data, please contact us first so we can try to resolve the issue directly.
You also have the right to lodge a complaint with the relevant data protection supervisory authority in your jurisdiction. If you are in the United Kingdom, this is typically the Information Commissioner’s Office (ICO). We encourage you to contact us first so that we can address your concerns promptly.
11. Data security
We implement appropriate technical and organisational measures to protect personal data against accidental loss, unauthorised access, misuse, alteration, disclosure, or destruction. These measures may include access controls, secure storage, staff confidentiality obligations, and internal procedures for handling data securely.
While we take reasonable steps to protect your information, no method of transmission over the internet or method of electronic storage is completely secure. We therefore cannot guarantee absolute security, but we work to maintain a level of protection appropriate to the risks involved.
12. Contact information
If you have any questions about this Privacy Policy or how Greenhaven Garden Services Ltd processes personal data, please contact us:
Greenhaven Garden Services Ltd
Unit 4, Northgate Business Park, Northgate Street, Bury St Edmunds, IP32 6AS, United Kingdom
Email: [email protected]
Phone: +44 1284 739 582
13. Changes to privacy policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or operational requirements. Any updates will be posted on our website or otherwise made available to you where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how Greenhaven Garden Services Ltd handles personal data. The date of the latest version should be checked where provided.