Privacy Policy - Gardeners Grove Park
Last updated: August 2026
This Privacy Policy explains how Gardeners Grove Park collects, uses, stores, shares, and protects personal data relating to its customers in the area. It applies to all Gardeners Grove Park customers in area, including visitors, registered users, and anyone who makes use of our services, facilities, or booking options. We are committed to handling personal data in a lawful, fair, and transparent manner in line with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
1. Who We Are
Gardeners Grove Park provides local park-related services and customer support to individuals and households in the surrounding area. For the purposes of data protection law, Gardeners Grove Park acts as the data controller for the personal data described in this policy. This means we decide how and why your personal data is processed.
We take privacy seriously and aim to ensure that any processing of personal data is limited to what is necessary for the operation, improvement, and administration of our services.
2. Data We Collect
We may collect and process the following categories of personal data:
- Identity data such as your name, and where relevant, household or customer reference details.
- Contact data such as postal address, email address, and telephone number where provided.
- Service data including records of bookings, purchases, enquiries, preferences, and service requests.
- Payment data where needed to process transactions, such as payment confirmation, billing information, and limited payment identifiers.
- Technical data such as device information, log data, and usage data if you interact with our online systems.
- Communication data including messages, feedback, complaints, and correspondence with us.
- Security data such as information needed for fraud prevention, access control, or safeguarding our operations.
We generally do not seek to collect special category data unless it is necessary and you choose to provide it, or we are required to do so for a specific lawful purpose. Special category data may include information about health, disability, or other sensitive matters. If such data is collected, it will only be processed where a valid legal condition applies.
How We Collect Data
We may collect personal data directly from you when you:
- make an enquiry or booking;
- use our services or facilities;
- complete forms or provide information voluntarily;
- communicate with us by email, phone, or written correspondence;
- participate in surveys, feedback requests, or service updates.
We may also receive data from third parties where permitted by law, such as payment providers, service platforms, or operational partners acting on our behalf.
3. How We Use Personal Data
We process personal data for the following purposes:
- to provide and manage services requested by customers;
- to process bookings, transactions, and related administrative tasks;
- to respond to enquiries, complaints, and support requests;
- to maintain records and improve service delivery;
- to meet legal, regulatory, accounting, and reporting obligations;
- to ensure safety, security, and appropriate use of our services;
- to analyse service performance and customer satisfaction;
- to prevent fraud, misuse, and unauthorised access;
- to communicate important updates related to services or policy changes.
We use personal data only for specified purposes and do not process it in ways that are incompatible with those purposes.
4. Lawful Basis for Processing
Under data protection law, we must have a lawful basis for processing your personal data. Depending on the activity, Gardeners Grove Park may rely on one or more of the following lawful bases:
- Contract – where processing is necessary to provide a service or fulfil an agreement with you.
- Legal obligation – where processing is required to comply with a legal or regulatory duty.
- Legitimate interests – where processing is necessary for our legitimate business and operational interests, provided your rights and freedoms do not override those interests.
- Consent – where you have given clear permission for a specific purpose, such as optional communications or certain forms of processing.
- Vital interests – in rare cases where processing is needed to protect someone’s life.
- Public task – where processing is necessary for tasks carried out in the public interest, if applicable.
Where we rely on consent, you can withdraw it at any time. This will not affect the lawfulness of processing carried out before consent was withdrawn.
5. Data Sharing and Processors
We may share personal data with selected third parties where necessary and lawful. These parties may act as processors or, in some cases, as independent controllers. Processors are organisations that process personal data on our instructions and only for the purposes we specify.
Examples of processors or service providers may include:
- IT and cloud hosting providers;
- customer administration and booking system providers;
- payment processing services;
- professional advisers such as accountants or legal advisers;
- security, maintenance, and operational support providers;
- data storage and back-up providers;
- communications and email service providers.
All processors are required to protect personal data, act only on our documented instructions, and apply appropriate technical and organisational safeguards. We do not sell personal data.
We may also disclose data where required by law, court order, or to protect the rights, property, or safety of Gardeners Grove Park, our customers, or others.
6. International Transfers
If personal data is transferred outside the UK, we will ensure that appropriate safeguards are in place, such as adequacy regulations or approved contractual protections. We take steps to ensure that international transfers are handled securely and in compliance with applicable data protection requirements.
7. Data Retention
We keep personal data only for as long as necessary to fulfil the purposes for which it was collected, including for legal, accounting, reporting, or operational needs. Retention periods vary depending on the type of data and the reason it is held.
In general:
- Customer and service records are retained for the period needed to manage the relationship and resolve queries.
- Transaction and accounting records are kept for the period required under financial and tax laws.
- Communication records are retained as long as needed to handle enquiries, complaints, or follow-up actions.
- Technical and security logs are kept for a limited time unless a longer period is required for investigation or legal compliance.
When data is no longer required, we will delete it securely or anonymise it so that it can no longer identify you.
8. Data Security
We use appropriate technical and organisational measures to protect personal data against accidental loss, misuse, unauthorised access, alteration, or disclosure. These measures may include access controls, secure storage, staff training, monitoring, and contractual safeguards with processors.
Although we work hard to protect your data, no method of transmission or storage is completely secure. We therefore cannot guarantee absolute security, but we continually review and improve our protections.
9. Your Rights
Under data protection law, you have a number of rights in relation to your personal data. These rights may apply in full or in part depending on the reason for processing and any legal exemptions.
- Right of access – you can request a copy of the personal data we hold about you.
- Right to rectification – you can ask us to correct inaccurate or incomplete data.
- Right to erasure – in certain circumstances, you can ask us to delete your data.
- Right to restriction – you can ask us to limit how we use your data in some situations.
- Right to object – you can object to processing based on legitimate interests or direct marketing.
- Right to data portability – in certain circumstances, you can request your data in a structured, commonly used format.
- Right to withdraw consent – where we rely on consent, you may withdraw it at any time.
You also have the right to lodge a complaint with the relevant data protection supervisory authority if you believe your data rights have not been respected. We encourage you to raise any concerns with us first so that we can try to resolve them promptly.
10. Children’s Data
Where services may involve children or family use, we process personal data with extra care. We only collect children’s data where it is necessary, lawful, and appropriate. If consent is required and the child is below the relevant age, we will seek consent from a person with parental responsibility where applicable.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal, operational, or service-related changes. Any revised version will apply from the date it is published or otherwise communicated. We encourage customers to review this policy periodically so they remain informed about how personal data is handled.
12. Our Commitment
Gardeners Grove Park is committed to processing personal data in a lawful, fair, and transparent way. We aim to collect only the data we need, keep it no longer than necessary, and use it responsibly in support of our services. If you are a customer in our area, this policy describes how your information is managed and the rights available to you under data protection law.
By using our services, you acknowledge that you have read and understood this Privacy Policy.