Privacy Policy – Florist Hampstead Garden Suburb
Introduction
This Privacy Policy sets out how Florist Hampstead Garden Suburb handles your personal data in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. This policy is relevant to all customers who place orders with Florist Hampstead Garden Suburb from Hampstead Garden Suburb and its surrounding districts. Our privacy practices are designed to protect your personal information, uphold your rights, and ensure that data is processed lawfully and transparently.
What Data We Collect
When you place an order with Florist Hampstead Garden Suburb, we may collect and process the following information:
- Identity Data: Name, surname, and title.
- Contact Data: Delivery and billing addresses, telephone numbers, and contact preferences.
- Order Data: Details of products ordered, delivery instructions, order history, and transaction records.
- Payment Data: Limited payment information required for order processing (such as payment method and transaction ID). Payment card details are not stored by us but are processed securely by our payment provider.
- Technical Data: IP addresses, browser type, device identifiers, and access times, when using our website.
- Correspondence: Any communications sent to us, whether by phone, post, through our website, or via social media.
We do not intentionally collect special category data (such as health, ethnicity, or religious beliefs) unless you choose to provide such information, which will be treated with additional care and only processed where strictly necessary for your order.
Lawful Basis for Processing Your Data
We process your personal data only where we have a lawful basis to do so, as required by GDPR. The principal legal grounds for our data processing are as follows:
- Contractual Necessity: Processing your order, fulfilling delivery, communicating with you regarding your purchase, and providing customer service.
- Legal Compliance: Retaining records to comply with UK tax or legal obligations.
- Legitimate Interests: Improving our services, ensuring fraud prevention, processing analytics data to enhance user experience, and marketing communications (only where permitted and relevant).
- Consent: Where you have explicitly agreed to receive marketing communications or to participate in customer surveys. You can withdraw your consent at any time.
How We Use Your Data
Your personal data will only be used in order to:
- Process and deliver your floral orders, including managing payments and arranging delivery.
- Respond to your queries, requests, or complaints.
- Improve and ensure security on our website.
- Send updates about your order and, with your consent, provide news and special offers.
- Meet legal, regulatory, or tax requirements.
Data Retention Periods
We retain your personal data only as long as is necessary for the purposes set out in this policy and to comply with legal obligations:
- Order and Transaction Data: Retained for up to 7 years, as required for accounting and taxation.
- Marketing Data: Retained until you withdraw your consent or object to receiving further communications.
- Technical Data: Retained for a period appropriate to security and analytics, generally not exceeding 24 months.
- General Contact or Correspondence: Retained as long as necessary to resolve your enquiry or support needs, usually no more than 12 months after your last contact.
Once data is no longer required, it will be securely deleted or anonymised.
Data Processors and Third Parties
To fulfil your order and operate our business, we may share your information with trusted third-party service providers, known as data processors. These may include:
- Delivery partners to ensure the safe and prompt delivery of your order.
- Payment processing providers who securely handle your payment details.
- IT support and hosting providers who assist us in maintaining our systems and website.
- Professional advisors or accountants for compliance with legal obligations.
All third-party processors are required to comply with GDPR, act only on our instructions, and maintain security of your information. We will never sell or rent your information to third parties for marketing purposes.
Your Rights as a Data Subject
Under GDPR, you have a number of important rights regarding your personal data. These include:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request corrections to data that is inaccurate or incomplete.
- Right to Erasure: Request deletion of your personal data where there is no compelling reason for its continued processing (subject to tax and regulatory obligations).
- Right to Restrict Processing: Request restriction on processing if you contest its accuracy or where processing is unlawful.
- Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format, and have the right to transmit it to another data controller.
- Right to Object: Object to certain types of processing, such as direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.
- Right to Lodge a Complaint: If you are unhappy with how we handle your data, you may contact the data protection supervisory authority.
Data Security Measures
We adopt appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure or destruction. This includes secure servers, data encryption where appropriate, limited access to data, and staff training on data protection responsibilities.
International Data Transfers
Your information may be transferred and processed outside the UK or EEA where necessary for services such as IT hosting or payment processing. In such cases, we ensure that adequate safeguards (such as contractual clauses) are in place to maintain the security and legality of your data transfer in accordance with GDPR requirements.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in law, our business practices, or the services we offer. Material changes will be notified to you before they take effect where required.
Contact Us
If you have any questions or concerns regarding this Privacy Policy, or wish to exercise your rights, please get in touch with us using our website's contact form or by writing to our business address. We endeavour to respond to all requests within one month as required by GDPR.
Effective Date: 1 June 2024