Florist West Kensington Privacy Policy
Introduction
This Privacy Policy describes how Florist West Kensington ('we', 'us', 'our') collects, processes, and protects personal data from customers placing orders in West Kensington and surrounding districts. We are committed to safeguarding the privacy of all our customers in compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. By placing an order with Florist West Kensington, you acknowledge and agree to the practices described in this policy.
Scope of This Policy
This policy applies to all individuals ('you', 'your') who place orders with Florist West Kensington for flower delivery or related services within West Kensington and its surrounding districts. It outlines how we handle personal data during the ordering process and while delivering our services.
What Data We Collect
We collect and process the following categories of personal data to provide and improve our services:
- Contact Information: Name, delivery address, billing address, and contact details of both the sender and recipient of an order, including phone numbers.
- Order Details: Purchase history, products ordered, selected delivery options and instructions, order value, and payment method (note: we do not store card details; payments are processed securely via our payment partners).
- Communication Data: Queries, feedback, and correspondence you have with us (such as by phone, message, or written form) regarding your order or our services.
- Device and Usage Information: IP address, browser type, device identifiers, and website usage information collected via cookies or similar technologies where applicable (refer to our cookie notice for details).
Purposes and Lawful Basis for Processing
We collect and process your personal data only where a lawful basis exists under GDPR. These include:
- Contractual Necessity: To process and fulfill your orders, arrange deliveries, communicate about your order’s status, and provide customer support (GDPR Article 6(1)(b)).
- Legal Obligation: To comply with applicable legal and tax requirements, including record-keeping and invoicing (GDPR Article 6(1)(c)).
- Legitimate Interests: To improve our services, handle customer enquiries and feedback, and protect our business interests. We ensure such processing is balanced with your rights (GDPR Article 6(1)(f)).
- Consent: When required, such as for sending email marketing, we will only do so where you have given your explicit consent, which you may withdraw at any time (GDPR Article 6(1)(a)).
How We Use Your Data
Your personal data is used solely for the following purposes:
- Processing, confirming, and delivering your order
- Managing payment and invoicing through our secure payment partners
- Communicating with you about your order and handling any queries or feedback
- Complying with legal and regulatory obligations
- Improving our services and user experience
- Marketing communications, only if you have given consent
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including:
- Order and Transaction Records: Typically retained for up to seven years to comply with legal, accounting, and tax requirements.
- Communication Data: Retained for up to three years after the last correspondence to ensure quality of service and resolve any potential disputes.
- Marketing Data: Retained until you withdraw consent or opt-out of communications.
Upon expiry of retention periods, personal data will be securely deleted or anonymized in accordance with our data retention policy.
Processors and Third Parties
To perform our services, we may sometimes share your data with trusted third parties acting as data processors on our behalf. These include:
- Payment Processors: To securely process payments, we share necessary information only with trusted payment service providers.
- Delivery Partners: Where necessary, your contact details and delivery instructions may be shared with staff or third-party couriers responsible for fulfilling your delivery.
- Service Providers: Companies that help us operate and maintain our website, manage communications, or support our business functions. Each processor is contractually bound to protect your data and process it only as instructed by us.
- Legal Authorities: Where required by law, we may disclose your data to relevant authorities.
We do not sell, rent, or trade your personal information to third parties for marketing or for any other purposes.
Your Rights Under GDPR
You have a range of rights in respect of your personal data, including:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You can request deletion of your data where there is no legitimate reason for us to retain it.
- Right to Restrict Processing: You may request that we temporarily stop processing your data in certain circumstances.
- Right to Data Portability: You have the right to receive your data in a structured, commonly used, and machine-readable format for transmission to another provider.
- Right to Object: You may object to certain types of processing, such as direct marketing.
- Right to Withdraw Consent: Where you have given consent, you may withdraw it at any time. This will not affect the lawfulness of any processing carried out before withdrawal.
To exercise any of these rights, or to request further information about our data handling practices, you may contact us using the methods outlined on our website. We will respond as required by GDPR and aim to address any concerns promptly and transparently.
Data Security
We employ a range of organizational and technical measures to protect your personal information against unauthorized access, accidental loss, use, disclosure, or destruction. These include secure server environments, encryption, access controls, and staff training. While we take all reasonable steps to protect your data, please be aware that no security system is entirely infallible.
Changes to This Privacy Policy
We may occasionally update this Privacy Policy to reflect changes to our practices or legal requirements. All updates will be posted on our website with an updated revision date. We encourage you to review this policy regularly to stay informed about how we protect your information.
Contact and Complaints
If you have questions, concerns, or requests concerning your personal data, please refer to the contact details provided on our website. If you are dissatisfied with how we handle your data, you have the right to raise a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
This Privacy Policy was last updated in June 2024. We thank you for trusting Florist West Kensington with your personal information.