Privacy Policy – Tree Surgeons Addiscombe
This Privacy Policy explains how Tree Surgeons Addiscombe collects, uses, stores, shares, and protects personal data when providing tree surgery, arboricultural, and related services. It applies to all Tree Surgeons Addiscombe customers in the area, including individuals, landlords, property managers, businesses, and any other clients who request or receive our services. We are committed to handling personal data in a lawful, fair, and transparent manner in accordance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
By engaging Tree Surgeons Addiscombe, making enquiries, requesting quotations, or otherwise interacting with our services, you acknowledge that your personal data may be processed as described in this policy.
1. Personal Data We Collect
We collect only the information necessary to provide our services, manage our business operations, and meet legal obligations. The types of data we may collect include:
- Identity data: your name, title, and, where relevant, company name or property ownership details.
- Contact data: address, email address, telephone number, and other communication details.
- Service and property data: information about the trees, site access, photographs, work instructions, risk considerations, and details of the property where work will be carried out.
- Transaction data: quotations, invoices, payment status, and service records.
- Technical data: limited device or browsing information if you contact us through digital channels, such as IP address or basic website interaction logs, where applicable.
- Communication data: records of emails, messages, calls, estimates, complaints, and service feedback.
- Legal and compliance data: records required for insurance, health and safety, tax, and accounting purposes.
We do not intentionally collect special category personal data unless it is strictly necessary and you choose to provide it, or we are required to process it for a legitimate legal or safety reason. If such information is provided, we will only use it where permitted by law and with appropriate safeguards.
2. How We Use Personal Data
Tree Surgeons Addiscombe uses personal data for the following purposes:
- to respond to enquiries and provide quotations;
- to assess work requirements and plan tree surgery services;
- to complete scheduled and emergency tree work;
- to manage customer accounts, invoices, and payments;
- to maintain service records and job history;
- to comply with legal, tax, insurance, and regulatory obligations;
- to manage health and safety, site risk, and operational planning;
- to handle complaints, disputes, and service follow-up;
- to improve our services and internal business processes;
- to keep appropriate business records and protect our legal rights.
We only use your personal data for the purpose for which it was collected, unless we reasonably need to use it for a compatible purpose that is permitted by law.
3. Lawful Basis for Processing
Under UK GDPR, we must have a lawful basis for using personal data. Tree Surgeons Addiscombe relies on the following lawful bases, depending on the context:
Contract
We process personal data where it is necessary to enter into or perform a contract with you. This includes preparing quotations, arranging appointments, carrying out tree surgery services, issuing invoices, and managing aftercare or follow-up related to the agreed work.
Legal Obligation
We may process data where necessary to comply with legal requirements, including accounting rules, tax obligations, insurance obligations, and health and safety duties.
Legitimate Interests
We may process personal data when it is necessary for our legitimate business interests, provided those interests do not override your rights and freedoms. This may include managing customer relationships, maintaining service records, preventing fraud, improving service quality, and protecting our business from legal claims.
Consent
Where required by law, we will rely on your consent. If we ask for consent, you may withdraw it at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before consent was withdrawn.
Vital Interests
In rare circumstances, we may process personal data where it is necessary to protect someone’s life or physical safety, for example during an emergency tree-related risk situation.
4. Data Sharing and Processors
We may share personal data with trusted third parties where necessary to operate our business and provide services. These third parties may act as processors on our behalf, meaning they only process data according to our instructions and under appropriate contractual safeguards.
Examples of processors and service providers may include:
- accounting and bookkeeping providers;
- payment processing providers;
- IT, cloud storage, and email service providers;
- customer record and scheduling software providers;
- professional advisors such as insurers, solicitors, or auditors;
- subcontractors or specialist operatives engaged to complete part of a project;
- regulatory authorities, local authorities, courts, or law enforcement where required by law.
Where personal data is shared with processors, we require them to protect it appropriately and to use it only for the agreed purpose. We do not sell personal data to third parties.
5. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, insurance, or reporting requirements. Retention periods vary depending on the nature of the data and the reason for processing.
As a general approach:
- quotation and enquiry data may be kept for a reasonable period to manage follow-up and business records;
- customer service and job records are kept for the duration needed to evidence work completed and handle any query or dispute;
- financial and accounting records are retained in line with statutory requirements;
- health and safety records are kept for as long as necessary to meet legal and insurance obligations.
When data is no longer required, we will securely delete, anonymise, or destroy it. We review retention on a regular basis to ensure that we do not keep personal data longer than necessary.
6. Security of Personal Data
We take appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures may include access controls, secure storage, staff confidentiality requirements, and the use of trusted service providers. While we work hard to protect data, no system can be guaranteed to be completely secure.
7. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. Subject to legal conditions and exemptions, these may include:
- the right to be informed about how your data is used;
- the right of access to request a copy of your personal data;
- the right to rectification to correct inaccurate or incomplete data;
- the right to erasure in certain circumstances, sometimes called the right to be forgotten;
- the right to restrict processing in certain situations;
- the right to data portability where processing is based on consent or contract and carried out by automated means;
- the right to object to processing based on legitimate interests or direct marketing;
- rights related to automated decision-making, where applicable.
If you wish to exercise any of these rights, we will respond in accordance with applicable law. We may need to verify your identity before responding, and in some cases we may not be able to comply fully where legal obligations or other lawful grounds apply.
8. International Transfers
Where any service provider stores or processes data outside the UK, we will ensure that appropriate safeguards are in place to protect your information. These safeguards may include adequacy regulations, standard contractual clauses, or other approved transfer mechanisms.
9. Cookies and Similar Technologies
If we use online tools that involve cookies or similar technologies, these may be used for basic functionality, security, analytics, or performance purposes. Where required, we will obtain consent for non-essential cookies. You can manage cookie settings through your browser or device settings.
10. Children’s Data
Our services are generally aimed at adults and property-related customers. We do not knowingly collect personal data from children except where it is necessary and lawful in connection with a service request, site safety, or property management context.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our services, legal obligations, or data processing practices. Any updated version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically to stay informed about how personal data is handled.
12. Summary of Our Approach
Tree Surgeons Addiscombe handles personal data carefully and only for clear business, legal, and service-related reasons. We collect the minimum necessary information, rely on lawful bases under UK GDPR, limit access to trusted processors, and keep data only as long as needed. We also respect your rights and aim to be open and accountable in all data processing activities.
This Privacy Policy applies to all Tree Surgeons Addiscombe customers in area.