Earls Court Florist Privacy Policy
Introduction
At Earls Court Florist, we are committed to safeguarding your privacy and ensuring that your personal data is handled responsibly and transparently. This Privacy Policy outlines how we collect, use, store, and protect the personal data of our customers placing flower orders in Earls Court and the surrounding districts. We adhere strictly to the requirements of the UK General Data Protection Regulation (GDPR). By placing an order or interacting with our services, you agree to the practices described in this policy.
Scope of this Policy
This policy applies to all individuals who order products or services from Earls Court Florist either directly, by telephone, or through our online ordering platform, provided they are located in Earls Court and its neighbouring areas.
What Data We Collect
To process your orders efficiently and provide the best customer service, we may collect and process the following types of personal data:
- Contact Information: Your full name, delivery address, billing address, phone number, and email address.
- Order Details: Details of your flower order, including recipient information, card or message details, and any instructions for delivery.
- Payment Information: Payment transaction details (note: payment card details are handled via secure third-party payment processors and not stored by us).
- Communication Records: Records of communications with you, including any correspondence, enquiries, or feedback regarding our services.
- Technical Information: Limited technical data when you use our website, such as IP address, browser type, and cookies, necessary for site functionality and analytics.
Lawful Basis for Collecting Data
We are required under GDPR to have a lawful basis for processing your personal data. We collect and process your data for the following reasons:
- Contractual Necessity: To process, confirm, and deliver your flower orders as per your request.
- Legal Obligations: To fulfil our legal and regulatory requirements, including tax record-keeping and fraud prevention.
- Legitimate Interests: To improve our products and services, maintain security, and respond to your communications and feedback; where our interests do not override your fundamental rights and freedoms.
- Consent: Where we use your data for direct marketing and have obtained your explicit consent, for example, to send you promotional offers (you may withdraw consent at any time).
How We Use Your Data
Your personal data is used in the following ways:
- To process and fulfil your flower orders and deliver to you or the named recipient.
- To communicate with you about your order status, payment confirmation, and delivery details.
- To respond to your enquiries, feedback, or concerns efficiently.
- To comply with regulatory and accounting requirements.
- To enhance and personalise your experience with our services, where appropriate.
Data Retention
We retain your personal data only as long as necessary for the purposes stated in this policy. In general:
- Order and transactional records are retained for up to seven years to comply with tax, legal and business requirements.
- Contact information used for marketing is retained until you unsubscribe or withdraw consent.
- If you make an enquiry but do not complete an order, your details are stored for no longer than one year unless ongoing communication indicates continued interest.
Data Processors and Third Parties
To deliver our services, we may share your data with carefully selected third parties who act as data processors on our behalf. These include:
- Payment Processors: Securely handle payment transactions. We do not store your payment card details ourselves.
- Delivery Partners: Couriers or delivery drivers requiring recipient contact or address details for successful delivery.
- IT and Hosting Providers: To host our website and store data securely.
All processors must comply with strict data protection obligations and are not permitted to use your data for any purpose other than providing contracted services to Earls Court Florist.
Your Rights as a Data Subject
According to GDPR, you have the following rights in relation to your personal data:
- Right of Access: You have the right to request access to the personal data we hold about you.
- Right to Rectification: You can request that inaccurate or incomplete data be corrected or updated.
- Right to Erasure: You may ask us to delete your personal data, subject to legal or contractual obligations that require retention.
- Right to Restrict Processing: You can request that we limit the way we use your data in certain circumstances.
- Right to Data Portability: You have the right to request your data be provided to you or another controller in a commonly used, machine-readable format.
- Right to Object: You can object to certain processing, such as receiving direct marketing communications. We will honour your request unless we are required to retain such data for lawful reasons.
- Right to Withdraw Consent: Where you have provided consent (for example, to receive marketing emails), you may withdraw it at any time.
Children’s Privacy
Our services are not intended for children under the age of 16. We do not knowingly collect data relating to children, and if we become aware that such data has been provided, we will delete it without delay.
Data Security
We implement robust technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse. These measures include secure servers, encryption, regular data protection reviews, and restricted access to those staff or processors who require it to deliver our services.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Any significant updates will be made available via our website, and where appropriate, we will inform you directly.
Contact and Complaints
If you have questions about this Privacy Policy or wish to exercise your data protection rights, you may contact us using the available contact methods on our website. Should you feel your data protection rights have been infringed, you also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).
Review Date
This Privacy Policy is effective as of June 2024 and will be reviewed regularly to ensure continued compliance with data protection law.