Florist Upminster Privacy Policy
Introduction
At Florist Upminster, we take your privacy seriously. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and other relevant data protection legislation. This policy applies to all customers who place orders with Florist Upminster from Upminster and the surrounding districts.
Data We Collect
We collect and process various types of personal data to provide you with our services. The data we collect may include:
- Contact Details: Such as your full name, delivery address, billing address, phone number, and any other contact information you provide when placing an order.
- Order Information: Details about the products or services you order, transaction amounts, and delivery instructions.
- Recipient Details: When you provide details of someone else (e.g., the intended recipient of flowers), this may include their name, address, and telephone number.
- Payment Information: We use third-party payment processors for processing your payments securely. We may receive confirmation of payment and partial payment details but do not store your full payment card information.
- Communication Records: Copies of your correspondence with us, such as emails, feedback, or customer service requests.
- Technical Data: Including your IP address, browser type, and browsing activity on our website where relevant.
Lawful Basis for Data Processing
Florist Upminster processes your personal data only where we have a lawful basis to do so. These include:
- Contractual Necessity: Processing your data is necessary for us to fulfil your order, deliver flowers and products, and provide any related customer service.
- Legitimate Interests: We have a legitimate business interest to improve our services, prevent fraud, and protect our operations, provided this does not override your rights and freedoms.
- Legal Compliance: We may process your data where required to comply with our legal obligations, such as tax and accounting requirements.
- Consent: In limited circumstances, such as marketing communications, we may seek your specific consent for processing your data, which you may withdraw at any time.
How We Use Your Data
We use the information we collect for various purposes, including:
- Processing and fulfilling your orders
- Delivering floral arrangements and related products
- Communicating with you regarding your orders or enquiries
- Responding to customer service requests
- Improving and personalising our products and services
- Maintaining accurate business and transaction records
- Complying with applicable laws and regulations
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. Typically, this means:
- Order Records: Retained for 7 years for tax and legal compliance.
- Account Information: Retained for as long as you have an active relationship with us.
- Marketing Preferences: Retained until you unsubscribe or ask us to remove your data from such use.
- Correspondence: Retained for up to 2 years to resolve issues or support inquiries, unless required longer for legal purposes.
Data Processors and Third Parties
To operate efficiently and provide our services, Florist Upminster may share your personal data with trusted third parties, including:
- Payment Processors: Securely process payment transactions. We do not store payment card details ourselves.
- Delivery Partners: Enable us to deliver your order to the recipient.
- IT Service Providers: Host, maintain, and support our IT infrastructure and website.
- Professional Advisors: Such as accountants or legal advisors, where required by business operations or legal obligations.
All third-party service providers are required to respect the security of your personal data and to treat it in accordance with the law. They are not allowed to use your data for their own purposes and are only permitted to process your personal data as instructed by us.
Your Rights
Under the GDPR, you have a number of important rights regarding your personal data. These include:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure: In certain circumstances, you may request the deletion of your personal data.
- Right to Restrict Processing: You may ask us to temporarily stop processing your data in certain situations.
- Right to Object: You have the right to object to our processing of your personal data where we rely on legitimate interests.
- Right to Data Portability: You are entitled to receive your personal data in a structured, commonly used format and have the right to transmit that data to another provider.
- Right to Withdraw Consent: Where we rely on your consent to process your data, you can withdraw your consent at any time.
To exercise any of these rights, please contact us by using the contact information provided when ordering or on our website. We may require verification of your identity before completing your request, in line with our legal obligations to protect your data.
Data Security
Florist Upminster takes appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, destruction, or disclosure. Access to your data is limited to employees and service providers who have a business need to know and are bound by confidentiality obligations.
Policy Changes
We may update this Privacy Policy to reflect changes in our practices or legal requirements. Any significant changes will be communicated to our customers by an appropriate method. Please check our website for the latest version of this policy.
Contact and Complaints
If you have questions about this Privacy Policy or how we handle your data, please contact us via the communication options provided on our website or order pages. If you are dissatisfied with how we process your personal data, you have the right to lodge a complaint with the data protection authority.