1. Introduction and Company Information
This Privacy Policy explains how Evergreen Glasshouse Solutions Ltd collects, uses, stores, shares, and protects personal data when you visit our website, contact us, request information, purchase our products or services, or otherwise interact with us.
Evergreen Glasshouse Solutions Ltd is the data controller responsible for the processing of your personal data described in this Privacy Policy.
Company details:
Evergreen Glasshouse Solutions Ltd
Unit 4, River Bridge Business Park, 5 Sturton Road, Lincoln, LN2 4JX, United Kingdom
Email: [email protected]
Phone: +44 1522 694 783
We operate in the greenhouse sector, including the supply, installation, maintenance, support, and related services for greenhouse systems and associated products. This Privacy Policy is intended to provide clear information about our data processing practices in a professional and transparent manner.
2. Data Collection and Processing
We may collect and process the following categories of personal data:
- Identity data: name, title, company name, job title, and similar identifiers.
- Contact data: postal address, email address, telephone number, and other communication details.
- Enquiry and correspondence data: details you provide when you contact us, request a quotation, arrange a site visit, or communicate with us by email, telephone, or form.
- Transaction data: details relating to orders, purchases, invoices, payments, delivery, returns, warranties, and service records.
- Technical data: IP address, browser type and version, device identifiers, operating system, and website usage information.
- Usage data: information about how you use our website, pages viewed, form submissions, and interactions with our content.
- Marketing and preference data: your communication preferences, consent choices, and marketing opt-ins or opt-outs.
- Project-related data: information necessary to assess greenhouse requirements, site conditions, technical specifications, and related planning information.
We obtain personal data directly from you, from your organisation, from publicly available sources, from our business partners, and from service providers supporting our operations. Where permitted by law, we may also receive information from third parties such as payment processors, delivery providers, or professional advisers.
We do not intentionally collect special category data unless it is strictly necessary and permitted by applicable law. If such data is collected inadvertently, we will handle it with appropriate safeguards.
3. Purpose of Data Processing
We process personal data for the following purposes:
- responding to enquiries and providing quotations;
- managing customer relationships and supplier relationships;
- assessing project requirements for greenhouse products and services;
- processing orders, payments, deliveries, and invoicing;
- arranging site surveys, installations, maintenance, and support services;
- administering warranties, repairs, and after-sales support;
- operating, maintaining, and securing our website and systems;
- conducting business administration, accounting, audit, and record-keeping;
- complying with legal, regulatory, tax, and contractual obligations;
- detecting and preventing fraud, misuse, or security incidents;
- sending service communications and, where permitted, marketing communications;
- improving our products, services, website, and customer experience.
Where we rely on your consent, we will only use your personal data for the specific purpose for which consent was obtained.
4. Legal Basis for Processing
We process personal data only where we have a valid legal basis under applicable data protection law. Depending on the circumstances, this may include:
- Performance of a contract: where processing is necessary to enter into or perform a contract with you, including quotations, orders, deliveries, installations, and support.
- Compliance with a legal obligation: where processing is required to meet legal, tax, accounting, safety, or regulatory obligations.
- Legitimate interests: where processing is necessary for our legitimate business interests, provided that those interests are not overridden by your rights and freedoms. Examples include business administration, service improvement, security, fraud prevention, and customer communications.
- Consent: where you have given clear consent, for example for certain marketing communications or optional cookies and similar technologies, where applicable.
- Vital interests: in rare cases where processing is necessary to protect someone’s vital interests.
- Public task or official authority: where applicable, if processing is necessary for a task carried out in the public interest or under official authority.
Where we rely on legitimate interests, we consider the nature of the processing, the impact on you, and your reasonable expectations.
5. Data Sharing and Third Parties
We may share personal data with third parties where necessary and lawful for the purposes described in this Privacy Policy. These third parties may include:
- IT and hosting providers;
- website analytics and security providers;
- accountants, auditors, legal advisers, and other professional advisers;
- payment service providers and banking partners;
- delivery, logistics, and installation partners;
- subcontractors and specialist service providers involved in project delivery, maintenance, or support;
- regulatory authorities, law enforcement, courts, or other public bodies where required by law;
- customer relationship management, communication, and email service providers;
- insurers and claims handlers where necessary for risk management or dispute resolution.
We require third parties to handle personal data in a secure and lawful manner and, where appropriate, under contractual obligations regarding confidentiality and data protection.
We do not sell personal data.
6. Data Transfer to Third Countries
Some of our service providers or business partners may be located outside the United Kingdom or may process data in countries outside the United Kingdom. Where personal data is transferred internationally, we will take appropriate steps to ensure that the transfer complies with applicable legal requirements and that your data remains protected.
Such safeguards may include adequacy regulations, standard contractual clauses, international data transfer agreements, or other legally recognised mechanisms. Where required, we will implement supplementary technical and organisational measures to enhance protection.
7. Storage Duration
We retain personal data only for as long as necessary for the purposes for which it was collected, including to satisfy legal, accounting, tax, contractual, and regulatory requirements.
The retention period depends on the type of data and the context of processing. In general:
- enquiry and customer correspondence data is retained for as long as needed to manage the relationship and for a reasonable period afterwards;
- contract, invoice, and financial records are retained in accordance with legal and accounting obligations;
- project and service records are retained for the period necessary to manage warranties, support, and disputes;
- marketing data is retained until you opt out, withdraw consent, or otherwise ask us to stop;
- technical website data is retained for operational, analytical, and security purposes for a limited period.
When personal data is no longer required, we will securely delete it or anonymise it where appropriate.
8. User Rights
Subject to applicable law, you may have the following rights in relation to your personal data:
- Right of access: to request confirmation of whether we process your data and to obtain a copy of it.
- Right to rectification: to request correction of inaccurate or incomplete data.
- Right to erasure: to request deletion of your data in certain circumstances.
- Right to restriction: to request that we limit the processing of your data in certain situations.
- Right to data portability: to receive certain data in a structured, commonly used, machine-readable format and, where feasible, to transmit it to another controller.
- Right to object: to object to processing based on legitimate interests or to direct marketing at any time.
You may also have rights relating to automated decision-making, although we do not currently use personal data for decisions based solely on automated processing that produce legal or similarly significant effects.
To exercise any of these rights, please contact us using the details set out in this Privacy Policy. We may need to verify your identity before responding. We will respond within the time limits required by applicable law.
9. Withdrawal of Consent
Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. Withdrawal of consent will not affect the lawfulness of processing carried out before the withdrawal.
If you withdraw consent, we may no longer be able to provide certain communications or services that depend on that consent. You can withdraw consent by contacting us at [email protected] or by using any unsubscribe or preference management option provided in our communications.
10. Right to Complain
If you have concerns about how we handle your personal data, we encourage you to contact us first so that we can try to resolve the matter promptly and fairly.
You also have the right to lodge a complaint with the relevant data protection supervisory authority in the United Kingdom, which is the Information Commissioner’s Office (ICO), or with another competent authority if applicable under local law.
We would appreciate the opportunity to address your concerns before you contact a supervisory authority, but this does not affect your legal rights.
11. Data Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, accidental loss, destruction, alteration, disclosure, or misuse. These measures may include:
- access controls and role-based permissions;
- password protection and secure authentication practices;
- encryption or other safeguards where appropriate;
- regular system monitoring and security updates;
- staff confidentiality obligations and data protection training;
- backup and recovery procedures;
- physical security measures at our premises and records storage locations;
- vendor assessment and contractual controls for service providers.
While we take reasonable steps to protect your data, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security, but we work continuously to reduce risks.
12. Contact Information
If you have any questions about this Privacy Policy, our data protection practices, or if you wish to exercise your rights, please contact:
Evergreen Glasshouse Solutions Ltd
Unit 4, River Bridge Business Park, 5 Sturton Road, Lincoln, LN2 4JX, United Kingdom
Email: [email protected]
Phone: +44 1522 694 783
13. Changes to Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, operational needs, or technical developments. Any revised version will be posted on our website with an updated effective date where appropriate.
We encourage you to review this Privacy Policy periodically to stay informed about how Evergreen Glasshouse Solutions Ltd processes personal data. Continued use of our services or website after updates take effect will constitute acknowledgment of the revised policy to the extent permitted by law.