Stamford Hill Florist Privacy Policy
Privacy Policy for Stamford Hill Florist
This Privacy Policy describes how Stamford Hill Florist collects, stores, uses, and safeguards your personal data. The policy applies to all customers placing orders with Stamford Hill Florist for delivery or pickup in Stamford Hill and surrounding districts. Our practices adhere to the General Data Protection Regulation (GDPR) and all relevant UK data protection laws.
Who We Are
Stamford Hill Florist is a local business providing floral arrangements and related services to customers in Stamford Hill and nearby areas. We are the data controller of any personal data you provide to us. This means we are responsible for deciding how we hold and use personal information about you.
What Personal Data We Collect
When you place an order or interact with Stamford Hill Florist, we collect the following types of information:
- Identity Data: Name, order recipient’s name (if different).
- Contact Data: Address, postcode, delivery address, telephone number, and, where provided, other contact details.
- Order Details: Purchase history, floral preferences, delivery instructions, messages included with orders.
- Payment Data: Payment confirmations and transaction amounts, but not full card details as these are handled securely by our payment processors.
- Communication Data: Any correspondence, feedback, or complaints you send to us regarding your order or our services.
- Technical Data: Device and browser type, IP address, time zone setting, and website usage information if you interact via our website.
How We Use Your Personal Data
We process your personal data for various purposes, such as:
- To process and deliver your floral orders, including contacting you or recipients about deliveries.
- To manage payments and order transactions.
- To communicate with you about your order, delivery updates, or customer support.
- To respond to your enquiries, feedback, or complaints.
- For record-keeping and to comply with legal and regulatory obligations.
- To improve our products, services, and customer experience.
- If you consent, to send marketing information about our products and offers (you can withdraw consent at any time).
Lawful Basis for Processing
The GDPR requires us to have a valid lawful basis for each use of your personal data. Which basis applies depends on the specific purpose:
- Contract: Processing is necessary for fulfilling orders you have placed and providing services you request.
- Legal Obligation: We may need to retain certain transaction data to comply with tax and accounting laws.
- Legitimate Interests: To improve our service, ensure the security of our operations, and maintain business records—where these interests do not override your rights.
- Consent: We rely on your explicit consent for optional activities like delivering marketing communications. You may withdraw your consent at any time.
How Long We Retain Personal Data
Your personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements. In general:
- Order and delivery details are kept for up to 7 years in line with our accounting and financial record-keeping obligations.
- Marketing data is held until you opt out or withdraw consent.
- If you contact us to request deletion or exercise your rights, we will review, limit, or erase your data in accordance with the law.
Data Processors and Sharing Personal Data
We share your personal data only where necessary and with trusted third parties who process data on our behalf (“data processors”). These include services for payment processing, order management, website hosting, and delivery logistics. All third parties are required to comply with relevant data protection laws and to safeguard your information.
We do not sell your personal information. Your data is not transferred outside the UK or European Economic Area unless adequate protections are in place.
Your Data Protection Rights
You have the following rights with respect to your personal data under the GDPR:
- Access: The right to request a copy of the personal data we hold about you.
- Rectification: The right to request correction of any inaccurate or incomplete data.
- Erasure: The right to request deletion of your personal data, subject to certain legal limitations.
- Restriction: The right to request restriction of processing of your data in certain circumstances.
- Objection: The right to object to processing based on our legitimate interests or for direct marketing purposes.
- Portability: The right to receive your data in a structured, commonly used format and have it transferred to another controller.
- Withdraw Consent: Where we process data based on your consent, you may withdraw it at any time.
To exercise your rights, please contact Stamford Hill Florist using your preferred method of communication.
Data Security Measures
We take security seriously and have implemented appropriate technical and organisational measures to protect your data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. Examples include secured servers, encryption protocols for payment processing, and limited access by authorised personnel only.
Policy Applicability and Updates
This Privacy Policy applies to all Stamford Hill Florist customers placing orders for Stamford Hill and surrounding districts. We may update this policy occasionally to reflect changes in the law, guidance, or our practices. We encourage you to review this notice regularly to stay informed about how we protect your information.
Contacting Stamford Hill Florist
If you have questions or concerns about how we protect your personal data or wish to exercise your data rights under this Privacy Policy, please get in touch with Stamford Hill Florist using your preferred communication method.
This Policy is effective as of 1 June 2024.