Florist Crouch End Privacy Policy
Overview of This Privacy Policy
This Privacy Policy outlines how Florist Crouch End processes, stores, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). This policy is applicable to all customers placing orders with Florist Crouch End from the Crouch End area and its surrounding districts. We are committed to ensuring transparency regarding your data and respecting your privacy at every stage of our service delivery.
Personal Data We Collect
When you interact with Florist Crouch End—such as placing an order, making an enquiry, or browsing our services—we may collect the following categories of personal data:
- Contact Information: Full name, delivery address, billing address, and contact information such as phone number.
- Order Details: Details about your purchase, recipient information if different, and your order history.
- Payment Details: Information required to process payments. Please note that payment information is processed securely by our authorised payment processors and not stored by Florist Crouch End directly.
- Communication History: Any correspondence you have with us via our website, over the phone, or through other support channels.
- Technical Data: Data collected automatically from your device, such as IP address, browser type, and access times, primarily for website analytics and security.
Lawful Basis for Processing Your Data
Florist Crouch End processes personal data under the following lawful bases as defined by Article 6 of the GDPR:
- Performance of a Contract: We process your data to fulfill orders, complete transactions, and provide customer service related to your purchases with us.
- Legitimate Interests: To improve our website, monitor service quality, prevent fraud, and keep customers informed of any changes relevant to their orders.
- Legal Obligations: We may retain data or disclose certain information to comply with legal, tax, and regulatory duties.
- Consent: In situations where we process data that is not strictly necessary for performance of a contract or legal obligation (such as marketing emails), we will always seek your explicit consent in advance. You have the right to withdraw consent at any time.
How We Use Your Personal Data
The data we collect is used for the following purposes:
- Processing, confirming, and delivering your orders.
- Communicating with you about your orders and responding to queries or requests for support.
- Improving our services and website experience through analytics and feedback.
- Complying with accounting, tax, and legal requirements.
- Sending relevant updates or offers if you have consented to marketing communications.
Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes described in this privacy policy, including for satisfying any legal, accounting, or reporting requirements. Typically:
- Order and transaction records are retained for up to 7 years as required by law.
- Customer account details may be retained as long as your account remains active, or until you request deletion where applicable.
- Communication records are kept as needed for service quality, dispute resolution, or as legally required.
Sharing Your Data: Processors and Third Parties
Florist Crouch End may share your data with selected third-party processors as necessary to provide our services, including:
- Payment processors for secure handling of online transactions.
- Delivery partners or couriers to ensure timely delivery of your orders.
- IT and hosting providers to maintain our website and support our operations.
All third-party processors are subject to strict contractual obligations to safeguard your data and process it in accordance with GDPR standards. We do not sell or lease your personal information to any external parties.
Data Security
We implement a variety of security measures designed to ensure your personal data is protected against loss, misuse, unauthorised access, disclosure, alteration, or destruction. This includes secure hosting environments and continuous monitoring of our systems. Where possible, we pseudonymise or anonymise personal data to further reduce risk.
Your Rights Under GDPR
You have a range of rights regarding your personal data. These include:
- Right to Access: You can request details about the personal data we hold about you.
- Right to Rectification: You may request that we correct incomplete or inaccurate information.
- Right to Erasure: In certain circumstances, you can ask us to delete your data.
- Right to Restrict Processing: You can request limits to how your data is used under specific conditions.
- Right to Data Portability: You may request your data in a structured, commonly used format for transfer to another provider.
- Right to Object: Where we use legitimate interests as a basis, you have the right to object at any time.
To exercise these rights, you may contact us using our usual communication channels at any time. Requests will be responded to within one month, in accordance with GDPR requirements. In some cases, we may need to verify your identity before fulfilling your request for security purposes.
International Data Transfers
Your data is stored within the United Kingdom or European Economic Area wherever possible. In cases where data processing may involve a country outside of this area, we ensure appropriate safeguards are in place as required under GDPR.
Policy Updates
This Privacy Policy may be updated to reflect changes in our practices or changes in applicable laws and regulations. The most current version of the policy will always be available on our website, with the revision date clearly indicated.
Contact and Further Information
If you have any questions about this Privacy Policy, our data handling practices, or your rights under GDPR, please contact us through our regular communication channels. We value your privacy and are always keen to assist with any queries relating to your personal information.