Florist Brondesbury Privacy Policy for Customers
Introduction and Scope
At Florist Brondesbury, we are dedicated to safeguarding your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your data when you place an order with us. It also outlines your rights under the General Data Protection Regulation (GDPR). This policy applies to all customers placing Florist Brondesbury orders from Brondesbury and the surrounding districts.
What Data We Collect
To fulfil your flower order efficiently and to deliver a quality user experience, we may collect the following personal data:
- Contact Information: Name, address (delivery and billing), phone number, and email address.
- Order Details: Items ordered, recipient information (if different from customer), order notes, and delivery preferences.
- Payment Information: Partial payment card details (such as the last four digits), payment confirmation, and transactional details. We do not store full card details.
- Customer Communications: Emails, messages, or information provided when contacting us about your order, enquiries, feedback, or complaints.
- Website Data: Technical data such as IP address, device type, browser information, as well as data from cookies or similar technologies to enhance your online experience. This includes analytical and usage data.
How We Use Your Data and Lawful Basis
Your data is processed only for specified purposes, and every action we take is underpinned by a lawful basis as required by the GDPR:
- Order Fulfilment: We process personal and order details to accept, prepare, and deliver your order. Lawful basis: Performance of a contract.
- Customer Communication: We use your contact details to confirm orders, update you on delivery, and respond to enquiries or complaints. Lawful basis: Performance of a contract, and where appropriate, legitimate interests.
- Payment Processing: Transactional data is processed to take payments or issue refunds. Lawful basis: Performance of a contract, and legal obligation.
- Marketing: With your explicit consent, we may send you marketing communications. You can opt out at any time. Lawful basis: Consent.
- Service Improvement: Analytical and usage data helps improve our website, products, and services. Lawful basis: Legitimate interests.
- Legal Compliance: In some circumstances, we are required to process data to meet legal or regulatory obligations. Lawful basis: Legal obligation.
How Long We Keep Your Data (Retention)
Florist Brondesbury keeps personal data only as long as necessary for the relevant purposes:
- Order-related data is retained for up to 7 years to comply with accounting and taxation requirements.
- Customer service communications are held for up to 2 years after resolution.
- If you have given consent for marketing, your contact details will be retained until you withdraw consent or opt out.
- Website analytics data is kept in an anonymised form and not linked to identifiable users after 26 months.
Once your data is no longer required for these purposes, we ensure its secure deletion or anonymisation.
Third-party Processors and Data Sharing
To deliver our services, we may share your data with trusted third parties (processors) who perform services on our behalf, for example:
- Payment processing companies for handling transactions securely.
- Delivery and courier services for order fulfilment.
- IT and hosting service providers to maintain our website and customer records.
- Professional advisers such as accountants or legal consultants when required for compliance.
Each processor is vetted to ensure they comply with GDPR, and we require them to keep your data secure and not use it for their own purposes. We do not sell your data to any other party. Your data is not transferred outside the UK or EU, unless adequate data protection safeguards are in place.
Your Rights Under GDPR
You are entitled to the following rights regarding your personal data:
- Right of Access: You can request information about what personal data we hold about you and receive a copy of it.
- Right to Rectification: You can ask to correct or update any incorrect or incomplete data.
- Right to Erasure: In certain cases, you may request the deletion of your personal data, unless retention is required by law or for contractual reasons.
- Right to Restriction: You may request that we temporarily suspend processing of your data.
- Right to Data Portability: You can ask for a copy of your data in a commonly used, machine-readable format to transfer to another provider.
- Right to Object: You can object to processing based on our legitimate interests, or for marketing purposes, at any time.
- Right to Withdraw Consent: Where consent is relied upon, you may withdraw your consent at any point for future processing.
To exercise your rights, please contact us using the details on our website. Where required, we may ask for confirmation of your identity to protect your privacy. We aim to respond to all requests in accordance with GDPR timelines and requirements.
Security of Your Data
Florist Brondesbury takes data security seriously. Personal data is protected using appropriate technical and organisational measures, including secure storage, encryption, access controls, and regular review of our procedures. We train our staff on privacy and data protection requirements. In the unlikely event of a data breach affecting your personal information, we will contact you and the relevant authorities as required by the GDPR.
Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in our practices, services, or to comply with legal requirements. Whenever significant changes are made, we will provide a clear notification on our website.
Contact and Further Information
If you have any questions about how we use your personal data, or if you wish to exercise your rights, please refer to the contact details provided on our main website. We encourage you to review this policy regularly to stay informed of how we are protecting your data.