Privacy Policy
Compliant with UK GDPR and the Data Protection Act 2018
Last updated: March 2026
IMPORTANT
We operate a lead generation marketplace. When you submit an enquiry on this website, your personal data will be shared with vetted tree surgery businesses for the purpose of providing you with quotes. By submitting an enquiry, you explicitly consent to this sharing. Please read this policy carefully before submitting your details.
Key Details
Website
www.treesurgeon.org.uk
Data Controller
UK Tree Surgeons Ltd
Data Protection Contact
privacy@treesurgeon.org.uk
ICO Registration
[To be inserted]
1. Who We Are
UK Tree Surgeons Ltd operates this website and the associated supplier marketplace platform. We are a lead generation business that connects members of the public requiring tree surgery services across the United Kingdom with vetted, professional tree surgery businesses ("suppliers") across all regions.
We are registered as a Data Controller with the Information Commissioner's Office (ICO) under the Data Protection Act 2018. Our supplier businesses who receive personal data via this platform act as independent Data Controllers in their own right once they receive that information.
2. What Personal Data We Collect
2.1 Consumer Data
Collected when an enquiry form is submitted:
- Full name, phone number, email address
- Postcode, service type, job description
- Date and time of submission
- IP address and device/browser information
- Following job completion: reported invoice value, job confirmation, star rating and review, responses to follow-up messages
2.2 Supplier Data
Collected at registration:
- Business name, contact name, phone, email
- Company registration number, registered address
- Public liability insurance documentation
- NPTC certification
- Service areas and services offered
- Stripe Connect bank details (processed by Stripe directly)
- Login credentials (encrypted)
- Job outcome reports, invoice values, account activity and communication logs
2.3 Automatically Collected Data
- IP address, browser type and version, operating system
- Referring URL, pages visited, time on page
- Clickstream data, cookie identifiers
3. How We Use Your Data
Consumer Data Lawful Basis
| Purpose | Lawful Basis | Details |
|---|---|---|
| Matching enquiry with local tree surgeons | Consent (Article 6(1)(a)) | Explicit consent given at point of form submission |
| Sharing contact details with up to 3 matched suppliers | Consent (Article 6(1)(a)) | Clearly disclosed at point of data collection |
| Follow-up messages to verify job outcome and invoice value | Legitimate Interests (Article 6(1)(f)) | Necessary to verify commission and prevent fraud |
| Requesting a rating and review of your supplier | Legitimate Interests (Article 6(1)(f)) | Maintains platform quality and protects future consumers |
| Responding to enquiries or complaints | Legitimate Interests (Article 6(1)(f)) | Necessary for communication related to your request |
| Complying with legal obligations | Legal Obligation (Article 6(1)(c)) | Financial records, regulatory compliance |
Supplier Data Lawful Basis
| Purpose | Lawful Basis | Details |
|---|---|---|
| Account creation and identity verification | Contract (Article 6(1)(b)) | Necessary to enter into our supplier agreement |
| Delivering matched leads to supplier accounts | Contract (Article 6(1)(b)) | Core platform service delivery |
| Collecting commission via Stripe | Contract (Article 6(1)(b)) | Fulfilment of the revenue share agreement |
| Sending SMS and email notifications about new leads | Contract (Article 6(1)(b)) | Essential to the platform service |
| Maintaining Verified Partner profiles | Contract (Article 6(1)(b)) | Agreed as part of Verified Partner subscription |
| Monitoring trust scores and flagging fraud | Legitimate Interests (Article 6(1)(f)) | Protecting platform integrity and consumer interests |
| Marketing communications | Consent (Article 6(1)(a)) | Only where supplier has opted in |
| Tax and legal compliance | Legal Obligation (Article 6(1)(c)) | HMRC and Companies Act obligations |
5. Automated Processing
Our matching algorithm is automated and considers postcode, service type, supplier coverage areas, and account tier. This does not produce legal effects on consumers.
Supplier trust scores are calculated automatically. Suppliers may request human review of any automated decision affecting their account by emailing privacy@londontreesurgeons.co.uk.
6. Consent and Withdrawal
6.1 Consumer Consent
Consumer consent is given at form submission. To withdraw after submission, contact privacy@londontreesurgeons.co.uk. We cannot recall data already delivered to suppliers but will cease further sharing immediately.
6.2 Supplier Consent
Suppliers can withdraw marketing consent via the unsubscribe link in emails, via dashboard settings, or by emailing us. Transactional messages (lead alerts, commission receipts) are not affected.
7. Data Retention
| Data Category | Purpose | Retention Period |
|---|---|---|
| Consumer enquiry data | Lead matching and delivery | 3 years from date of enquiry |
| Consumer job outcome data | Commission verification and fraud prevention | 6 years (statutory limitation period) |
| Consumer ratings and reviews | Supplier quality assurance | Duration of supplier account + 1 year |
| Supplier account data | Account administration | Duration of account + 6 years |
| Supplier financial data | Financial records and tax compliance | 6 years from financial year end |
| Supplier trust score and flag history | Fraud prevention | Duration of account + 2 years |
| SMS and email communication logs | Audit trail | 2 years |
| Website usage data and analytics | Platform performance | 26 months |
| Cookie consent records | Demonstrating compliance | 3 years |
8. Security
Technical Measures
- TLS encryption
- Bcrypt password hashing
- Restricted database access
- ISO 27001-certified infrastructure
- Role-based access controls
- Supabase Row Level Security
- Rate-limited API endpoints
Organisational Measures
- Staff data protection training
- Data processing agreements with all processors
- Regular reviews
In the event of a breach likely to risk individual rights, the ICO will be notified within 72 hours and affected individuals notified without undue delay where risk is high.
9. International Transfers
All data is stored within the UK or EEA where possible. International transfers rely on Standard Contractual Clauses.
Stripe, Twilio, and Resend may transfer data to the US under SCCs. Contact privacy@londontreesurgeons.co.uk for details of specific safeguards.
10. Your Rights
| Your Right | What It Means | Legal Basis |
|---|---|---|
| Right of Access | Request a copy of all personal data we hold | Article 15 UK GDPR |
| Right to Rectification | Ask us to correct inaccurate data | Article 16 UK GDPR |
| Right to Erasure | Request deletion where there is no compelling reason to retain | Article 17 UK GDPR |
| Right to Restrict Processing | Ask us to pause processing in certain circumstances | Article 18 UK GDPR |
| Right to Data Portability | Receive your data in a structured machine-readable format | Article 20 UK GDPR |
| Right to Object | Object to processing based on legitimate interests or direct marketing | Article 21 UK GDPR |
| Right to Withdraw Consent | Withdraw at any time where consent is the lawful basis | Article 7 UK GDPR |
| Right to Complain | Lodge a complaint with the ICO at ico.org.uk | Section 165 DPA 2018 |
We respond to all valid requests within one calendar month. To exercise your rights, email privacy@londontreesurgeons.co.uk with the subject line "Data Subject Request".
12. Children
Services are for individuals 18 and over. We do not knowingly collect data from children. Contact privacy@londontreesurgeons.co.uk if you believe a child's data has been collected.
13. Supplier-Specific Provisions
Suppliers become independent Data Controllers when they receive consumer data and are responsible for:
- Lawful processing
- Restricting use to the original enquiry purpose
- Not retaining beyond 12 months
- Not adding consumer data to marketing lists without separate consent
- Not selling or transferring consumer data to third parties
Breach constitutes a material breach of the Supplier Agreement.
14. Legitimate Interests Assessment
Post-job Follow-up Messages
Our interest is commission verification and fraud prevention. Consumer impact is minimal — a small number of relevant messages directly related to their transaction. Consumers can opt out by replying STOP.
Supplier Trust Score Monitoring
Our interest is consumer protection and platform integrity. Scores are not public. Suppliers are informed at registration and can appeal any flag.
15. Changes to This Policy
Material changes will be noted with an updated date, a homepage notice for 30 days, and fresh consent where required.
16. Contact and Complaints
Response Time
5 working days
ICO Complaints
ico.org.uk | 0303 123 1113
Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF