Carshalton Florist Privacy Policy
Introduction
This Privacy Policy sets out how Carshalton Florist collects, uses, stores, and protects your personal data when you place orders with us in Carshalton and the surrounding districts. As part of our commitment to protecting your privacy and complying with the UK General Data Protection Regulation (GDPR), this policy outlines your rights and our responsibilities when handling your data.
Scope of this Policy
This policy applies to all individuals who place flower orders, make inquiries, or interact with Carshalton Florist as customers in Carshalton and nearby areas. By accessing our services, you acknowledge and accept the practices described in this policy.
Personal Data We Collect
Depending on your interaction with Carshalton Florist, we may collect:
- Identity Data: Name, surname, and title.
- Contact Data: Postal address, delivery address, phone number, and (if provided) email address.
- Order Information: Details of orders placed, including recipient names, delivery instructions, card messages, product selections, and transaction history.
- Payment Information: Necessary card or bank details to process your order. Payment transactions are securely managed by our payment processors (see below); we do not store full payment card details.
- Communication Data: Records of communications and customer service inquiries.
- Technical Data: Where applicable, IP address and information collected via cookies or similar technology from our website, helping us improve our service and website performance.
Lawful Basis for Processing Your Data
Your data will only be processed where a lawful basis applies. Carshalton Florist relies on the following lawful bases:
- Contractual Necessity: Processing your data is required to fulfill our contract with you, such as completing orders and deliveries.
- Legitimate Interests: For certain uses, such as improving our services, preventing fraud, and handling customer service inquiries, we process data in pursuit of our legitimate business interests. We balance these interests against your rights and freedoms.
- Legal Compliance: Where necessary, we may process your data to comply with legal obligations (for example, for tax and accounting requirements).
- Consent: Where required by law, such as for certain marketing communications, we will ask for your explicit consent and always respect your right to withdraw it at any time.
How We Use Your Personal Data
Carshalton Florist uses your data for the following purposes:
- Processing and fulfilling your orders, including delivery arrangements.
- Providing customer service and responding to your queries or complaints.
- Communicating order updates or essential service information.
- Managing payments and preventing fraudulent transactions.
- Maintaining account and purchase histories for service improvement and record-keeping.
- Sending marketing communications if you have consented (you can unsubscribe at any time).
- Complying with legal and regulatory obligations.
Data Retention
We only retain your personal data for as long as necessary to fulfill the purposes we collected it for, including for legal, accounting, or reporting requirements. Typically, we retain:
- Order-related and transaction data for up to seven years, to comply with financial record-keeping obligations.
- Customer service correspondence for up to three years from our last interaction.
- Marketing consent data until you withdraw your consent or request deletion.
- Technical data for a limited period as defined by our cookie policy and business needs.
When personal data is no longer needed, it is securely deleted or anonymised.
Data Processors and Third Parties
Carshalton Florist may share your data with trusted third parties who act as data processors on our behalf. These include:
- Payment Service Providers: To process secure card transactions.
- Delivery Partners: For local delivery of your flower orders.
- IT, Website, and Email Service Providers: For secure hosting, order management, and communications.
- Professional Advisers: Such as accountants or legal consultants, only where legally required.
All processors comply with GDPR requirements and only process data following our instructions. We do not sell your data to third parties.
International Data Transfers
Your data is normally processed within the UK or European Economic Area (EEA). If it is necessary to transfer data outside the EEA, we ensure appropriate safeguards are in place to protect your privacy and data rights as required by GDPR.
How We Protect Your Personal Data
We implement appropriate technical and organizational security measures to prevent unauthorized access, loss, destruction, or disclosure of your personal data. Regular staff training, data encryption, secure payment processing, and strict access controls are part of our commitment to data security.
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: Request details of the personal data we hold about you.
- Right to Rectification: Request correction of incorrect or incomplete data.
- Right to Erasure: Ask us to delete your data where legally permissible.
- Right to Restrict Processing: Request restriction of processing in certain situations.
- Right to Data Portability: Receive the personal data you provided in a structured, commonly used format.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: If we rely on your consent, you can withdraw it at any time (without affecting the lawfulness of processing prior to withdrawal).
- Right to Lodge a Complaint: If you are unhappy with how we handle your data, you have the right to contact the UK Information Commissioner's Office (ICO).
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law or our practices. Please review this policy periodically to stay informed about your rights and how we process your data.
Contact Us
If you have any questions, requests, or concerns relating to your personal data or this Privacy Policy, please contact us using the details provided on our website or through the usual customer service channels.