Privacy Policy - Gardeners Hoxton

Last updated: August 2026

This Privacy Policy explains how Gardeners Hoxton collects, uses, stores, shares, and protects personal data in connection with our gardening services. It applies to all Gardeners Hoxton customers in the area, including prospective customers, current customers, former customers, and anyone who interacts with us regarding our services. We are committed to handling personal data in a lawful, fair, and transparent manner in line with the UK GDPR and the Data Protection Act 2018.

1. Who We Are

Gardeners Hoxton provides gardening and related outdoor maintenance services for residential and commercial customers. In this Privacy Policy, “we,” “us,” and “our” refer to Gardeners Hoxton. “You” means any person whose personal data we process, including customers, potential customers, and website or service enquirers.

We act as a data controller for the personal information we collect and use to manage our services, communicate with customers, arrange appointments, complete work, and maintain business records.

2. Personal Data We Collect

We collect only the personal data necessary to provide and manage our services effectively. Depending on your interactions with us, this may include:

  • Identity details such as your name, title, and, where relevant, business name.
  • Contact details such as address, email address, and telephone number.
  • Service details including property access notes, service preferences, appointment history, quotations, and job instructions.
  • Payment and transaction details such as records of payments made, invoices issued, and basic billing information.
  • Communication records including messages, queries, complaint details, and notes from phone calls or emails.
  • Technical data if you interact with digital systems used in our business, such as device information, IP address, or browser details.
  • Special category data only where strictly necessary and usually only if you voluntarily provide it, for example access or safety information that may relate to health or disability needs.

We do not intentionally collect more information than is required for legitimate business purposes. If we need additional data for a specific reason, we will explain why it is required.

3. How We Use Personal Data

We use personal data for the following purposes:

  • To provide quotations, arrange services, and carry out gardening work.
  • To manage bookings, rescheduling, and service delivery.
  • To communicate with customers about appointments, instructions, and account matters.
  • To issue invoices, record payments, and maintain accounting records.
  • To respond to enquiries, feedback, and complaints.
  • To maintain business administration, record keeping, and service quality.
  • To meet legal, tax, insurance, and regulatory obligations.
  • To protect our business, staff, customers, and property from fraud, misuse, or security incidents.

We only process personal data to the extent necessary for these purposes and apply data minimisation principles wherever possible.

4. Lawful Basis for Processing

We process personal data only where we have a lawful basis under the UK GDPR. Depending on the activity, the lawful basis may be one or more of the following:

a. Contract

We process data where it is necessary to enter into or perform a contract with you. This includes preparing quotes at your request, booking services, completing the work, and managing payment arrangements.

b. Legal Obligation

We process certain data to comply with legal requirements, including tax record keeping, accounting duties, health and safety obligations, and any lawful requests from public authorities.

c. Legitimate Interests

We may process personal data where it is necessary for our legitimate interests, provided your rights and freedoms do not override those interests. Examples include service administration, customer relationship management, business planning, security monitoring, and maintaining records of work carried out. We always consider whether our interests are proportionate and whether the processing is reasonable.

d. Consent

In limited cases, we may rely on your consent, particularly for optional communications or where special category data is involved and consent is the most appropriate lawful basis. Where consent is used, you may withdraw it at any time. Withdrawal will not affect any processing carried out before consent was withdrawn.

5. Data Sharing and Processors

We may share personal data with trusted third parties who help us operate our business. These organisations act as processors or independent controllers depending on the service they provide. We require all processors to handle data securely, only use it according to our instructions, and comply with applicable data protection law.

Examples of processors or service providers may include:

  • Accounting and bookkeeping providers for financial administration and tax compliance.
  • Payment processing providers for handling card or electronic payments.
  • IT and cloud storage providers for secure data storage, email, and business systems.
  • Appointment and scheduling tools used to organise service visits and customer records.
  • Professional advisers such as accountants, insurers, or legal advisers where needed.
  • Public authorities where disclosure is required by law or in connection with legal proceedings.

We do not sell personal data. We do not share it for unrelated marketing by third parties without a lawful basis. Where data is transferred outside the UK, we take appropriate safeguards to protect it.

6. Data Retention

We keep personal data only for as long as necessary for the purposes for which it was collected, including legal, accounting, insurance, and reporting requirements. Retention periods depend on the type of information and the reason it is held.

Typical retention practices include:

  • Customer service records: retained for the duration of the customer relationship and for a reasonable period afterward to manage follow-up, disputes, or warranty issues.
  • Financial and tax records: retained for the period required by law.
  • Communication records: kept as long as needed to respond to enquiries, maintain service history, and resolve issues.
  • Consent-based records: retained until consent is withdrawn or the relevant purpose ends.

When data is no longer needed, we delete it securely or anonymise it so that it can no longer identify you.

7. Security of Personal Data

We use appropriate technical and organisational measures to protect personal data from unauthorised access, loss, misuse, alteration, or disclosure. These measures may include access controls, secure storage, password protection, and limiting access to data to those who need it for legitimate business purposes.

Although we take security seriously, no system can be guaranteed completely secure. If a personal data breach occurs and we are legally required to notify affected individuals or the regulator, we will do so in accordance with applicable law.

8. Your Rights

Under data protection law, you have a number of rights in relation to your personal data. These rights may apply in full or in part depending on the circumstances of the processing.

  • Right of access – to request a copy of the personal data we hold about you.
  • Right to rectification – to ask us to correct inaccurate or incomplete information.
  • Right to erasure – to request deletion of your data where there is no lawful reason for us to keep it.
  • Right to restriction – to ask us to limit how we use your data in certain situations.
  • Right to object – to object to processing based on legitimate interests or direct marketing, where applicable.
  • Right to data portability – to request transfer of certain data in a structured, commonly used format where technically feasible.
  • Right to withdraw consent – where processing relies on consent, you may withdraw it at any time.

If you wish to exercise any of these rights, we may need to verify your identity before responding. We aim to respond within the time limits required by law.

9. Children’s Data

Our services are generally intended for adults. We do not knowingly collect personal data from children unless it is necessary in relation to a property, booking, or household arrangement and provided by an adult with authority to do so. If we become aware that we have collected data inappropriately, we will take steps to delete it where appropriate.

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data handling practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage you to review this policy periodically so you remain informed about how your data is used.

11. Fair and Transparent Processing

We are committed to processing personal data in a way that is lawful, fair, and transparent. This means we only use data for clear and legitimate purposes, we avoid excessive collection, and we take care to respect your privacy rights. If you have concerns about how your personal data is handled, you are entitled to raise those concerns with the relevant data protection authority in the UK.

Summary: Gardeners Hoxton processes customer personal data lawfully and securely, with clear purposes, retention limits, trusted processors, and rights for individuals under UK GDPR.

Gardeners Hoxton

This Privacy Policy explains how Gardeners Hoxton collects, uses, stores, shares, and protects personal data in connection with our gardening services.

Get In Touch With Us.

Please fill out the form below to send us an email and we will get back to you as soon as possible.