Florist West Harrow Privacy Policy
About This Privacy Policy
This privacy policy outlines how Florist West Harrow processes and protects the personal data of its customers who place orders in West Harrow and the surrounding districts. We are committed to handling your personal data responsibly and in accordance with the UK General Data Protection Regulation (GDPR), Data Protection Act 2018, and other relevant privacy laws. Please read this policy carefully to understand how we use, store, share, and protect your information.
What Data We Collect
Florist West Harrow may collect and process the following categories of personal data, depending on your interactions with us and the services requested:
- Identity Data: Name, surname, and title.
- Contact Data: Delivery and billing addresses, phone numbers, and other necessary delivery details.
- Order and Transaction Data: Details of your orders, purchased products, prices, payment status, and order notes.
- Payment Data: Payment status and transaction method (note: payment card details are processed by secure third-party payment processors and not stored by us).
- Recipient Data: Names and addresses of recipients if you place an order for delivery to someone other than yourself.
- Communication Data: Any correspondence between you and Florist West Harrow, such as order confirmations, delivery notifications, complaints, and customer support queries.
- Technical Data: Where applicable, limited information such as IP address, browser type, device type, and access times (for customers using our website or online ordering system).
Lawful Bases for Processing
Under the GDPR, we are only permitted to process your personal data where a lawful basis applies. Florist West Harrow relies on the following lawful bases for processing your information:
- Contractual Necessity: Processing is necessary to fulfil your order, deliver products, process payments, or provide customer service.
- Legal Obligation: We may process personal data when required to comply with legal or regulatory obligations, such as record keeping or responding to law enforcement.
- Legitimate Interests: In certain situations, processing is necessary for our legitimate business interests, provided these are not overridden by your rights or interests. Examples include fraud prevention, improving our services, or defending our legal rights.
- Consent: Where we require your consent for specific data uses (for example, where you opt-in to marketing communications), we will collect it separately at the point of data collection. You may withdraw your consent at any time.
How We Use Your Personal Data
Florist West Harrow uses personal data for the following purposes:
- Processing and fulfilling your orders, including delivery and notification to recipients.
- Communicating order updates, confirmations, or changes.
- Responding to enquiries, complaints, or support requests.
- Processing payment transactions and fraud prevention.
- Maintaining business records for accounting and regulatory purposes.
- Improving our services and customer experience.
- Where appropriate, sending you service communications or marketing material (if you have opted in).
How Long We Retain Your Data
We will retain your personal data only for as long as is necessary to fulfil the purposes for which it was collected, including for legal, accounting, or reporting requirements. Typically:
- Order and transaction records are retained for up to 6 years to comply with legal and tax obligations.
- Contact and communication data used for customer service purposes are held for no longer than 2 years after the last correspondence unless a longer period is required by law.
- If you have provided consent for marketing, your consent will be considered valid until withdrawn or after a specified period of inactivity, whichever occurs first.
- Technical data for security and analytics are retained in line with our system logs, typically for up to 12 months.
When the relevant retention period expires, your information will be securely deleted or anonymised.
Processors and Data Sharing
Florist West Harrow only shares your personal data where necessary to achieve the purposes outlined in this policy and in accordance with applicable laws. We may share your data with:
- Service Providers (Processors): We engage professional service providers such as payment processors, IT and system administration providers, couriers and delivery staff, and customer management systems. These partners are contractually bound to only process your data on Florist West Harrow's instructions, maintain its confidentiality, and implement appropriate security measures as required by law.
- Legal and Regulatory Authorities: Where required to do so by law, we may share data with government agencies or law enforcement for compliance.
We do not sell or rent your personal data to third parties. Your data will not be transferred outside the UK or European Economic Area without adequate safeguards and your knowledge.
Your GDPR Rights
Under the GDPR, you have a number of important rights in relation to your personal data. These include:
- Right of Access: You can request information about the personal data we hold about you and how we process it.
- Right to Rectification: You can request that we correct any inaccurate or incomplete personal data.
- Right to Erasure (Right to be Forgotten): You can ask us to delete your personal data under certain circumstances, for example, where it is no longer necessary for the purposes for which it was collected.
- Right to Restrict Processing: You can request that we restrict our processing of your personal data in specific situations.
- Right to Data Portability: You can request that we provide your personal data to you or another controller in a structured, commonly used electronic format.
- Right to Object: You can object to our processing of your personal data where we rely on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where we process your data based on consent, you have the right to withdraw that consent at any time.
If you wish to exercise any of these rights or have questions regarding your data, you can contact Florist West Harrow by post or in person at our business address. We may need to verify your identity before responding to your request. If you are unsatisfied with our response, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Updates to This Policy
We may update this privacy policy from time to time to reflect operational changes, legal requirements, or improvements to our privacy practices. When we make changes, we will note the date of the latest update. We encourage you to review this policy regularly to stay informed on how your data is protected.
Scope of Policy
This policy applies to all customers placing orders with Florist West Harrow from West Harrow and the surrounding districts, whether you order in person, by phone, or through our website or other online systems. By placing an order with us, you acknowledge and accept the data practices outlined in this privacy policy.