Florist Chadwell Heath Privacy Policy
Introduction
This Privacy Policy explains how Florist Chadwell Heath collects, uses, stores, and safeguards your personal data when you place an order with us. The policy applies to all customers placing orders from Chadwell Heath and surrounding districts. We are committed to protecting your privacy and ensuring we handle your personal information in accordance with the General Data Protection Regulation (GDPR) and relevant UK data protection legislation.
What Data We Collect
When you place an order with Florist Chadwell Heath, we may collect and process the following categories of personal data:
- Identity Data: Your full name and, when relevant, the recipient’s name if you are sending flowers to someone else.
- Contact Data: Delivery address, billing address, and contact telephone number.
- Order Details: Information about the products you purchase, delivery preferences, and order notes (e.g., card messages).
- Payment Data: Limited payment information required to process your order. Full card details are processed securely by our payment provider and are not stored by us.
- Technical Data: IP address, browser type, the device used, and information about how you interact with our website when placing an order.
Lawful Basis for Processing Your Data
The lawful basis upon which we process your personal data includes:
- Contractual Necessity: Processing your data is necessary for us to fulfill your floral order, deliver products, and facilitate payment.
- Legal Obligation: We may process your data to comply with legal requirements, such as fiscal and tax obligations regarding sales transactions.
- Legitimate Interests: We may use your data to improve our services, ensure the security and integrity of our orders and website, or respond to queries and feedback.
- Consent: For optional activities, such as sending marketing communications, we will only process your data with your explicit consent, which can be withdrawn at any time.
How We Use Your Data
Your data is used to:
- Process and deliver your order to the intended recipient.
- Communicate with you regarding your order, including confirmation, delivery updates, and customer service.
- Ensure payment is processed securely and accurately.
- Improve our website and customer experience using technical and analytical data (aggregated and anonymised wherever possible).
- Fulfill any legal or statutory obligations that apply to our business.
- Where you have given explicit consent, send occasional updates or marketing communications. You can opt out at any time.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy and as required to comply with legal or regulatory obligations. In typical circumstances:
- Order and contact details are retained for up to 7 years for accounting and tax purposes.
- Payment data processed by secure third-party providers is not stored by us.
- Marketing preferences are retained until you withdraw consent.
- Technical and analytics data may be retained in aggregate and anonymised form for service improvement.
Once your data is no longer needed, it will be securely deleted or anonymised.
Data Processors and Third Parties
We may share your personal data with trusted third-party processors to fulfill our services, including:
- Payment Service Providers: To securely process transactions.
- Delivery/Courier Partners: To ensure successful delivery of your order.
- Website and IT Maintenance Providers: For secure hosting, technical support, and improvement of our systems.
- Legal and Regulatory Authorities: When required by law, for compliance with legal processes and government requests.
All third-party processors comply with GDPR and only process personal data as instructed by us, adopting appropriate technical and organisational measures to safeguard your information. Your data is not transferred outside the UK or European Economic Area (EEA) unless to a country offering an adequate level of data protection or with sufficient safeguards as per GDPR requirements.
Your Rights as a Data Subject
Under GDPR, you have several rights relating to your personal data. These include:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right of Rectification: You can ask us to correct any inaccurate or incomplete data.
- Right of Erasure: You may request deletion of your personal data where there’s no compelling reason for us to continue processing it.
- Right to Restrict Processing: You have the right to limit the ways we use your data in certain circumstances.
- Right to Data Portability: You can request that we provide your personal data in a machine-readable format, or transfer it directly to another provider if feasible.
- Right to Object: You may object to our processing of your personal data for direct marketing or on bases relating to your specific situation.
- Right to Withdraw Consent: Where processing is based on consent (such as marketing), you can withdraw consent at any time.
If you wish to exercise any of these rights, please contact us through your usual communication method with Florist Chadwell Heath. While we aim to address all requests promptly, there may be situations where we must retain data for legitimate or legal reasons.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legislation, our procedures, or the range of services offered. Customers will be notified of significant changes where appropriate, and the most current version will always be available to review alongside our ordering processes.
Contact and Queries
For any questions or concerns regarding this Privacy Policy, or if you wish to exercise your GDPR data rights, please contact us using your standard communication channels with Florist Chadwell Heath. We are committed to ensuring your data is handled respectfully, fairly, and transparently at all times.