Florist Harringay Privacy Policy
Introduction
Florist Harringay is committed to protecting the privacy and personal data of our customers. This Privacy Policy explains how we collect, use, store, and protect your personal information in accordance with the General Data Protection Regulation (GDPR). It applies to all customers placing orders with Florist Harringay from Harringay and the surrounding districts.
What Data We Collect
When you place an order with Florist Harringay, we collect personal data necessary to process and deliver your order. This data may include:
- Contact details: Full name, billing address, delivery address, and telephone number.
- Order details: Details of products or services ordered, special delivery instructions, and messages to recipients.
- Payment information: Payment card details (which are processed securely via accredited payment processors and are not stored by us), and transaction records.
- Communication data: Records of your correspondence with us (e.g., entered via website forms).
- Technical information: IP address, device type, browser type, and cookies for website functionality and security.
Lawful Basis for Processing Personal Data
Under GDPR, we are required to have a lawful basis to process your personal data. The lawful bases applicable to Florist Harringay are as follows:
- Contractual necessity: Processing required to fulfill your order, deliver products, and manage payments.
- Legal obligation: Retaining certain financial and transactional records as required by taxation and accounting laws.
- Legitimate interests: Processing your data to provide and improve our services, respond to inquiries, and ensure website security, provided such interests are not overridden by your rights.
- Consent: When you opt in to marketing communications or consent to non-essential cookies, processing will be based on your explicit consent. You may withdraw consent at any time.
How We Use Your Data
Your personal data is used to:
- Process and fulfill flower and gift orders, including payment processing and delivery.
- Communicate order status, respond to queries, and provide customer support.
- Comply with applicable laws and regulations.
- Improve our services and website experience.
- Where you have given consent, to send you marketing communications about our products and promotions.
Data Retention
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Our retention periods are as follows:
- Order and transaction data: Kept for up to seven years, in compliance with commercial and tax regulations.
- Marketing data: Retained until you withdraw your consent or request to unsubscribe from communications, whichever occurs first.
- Correspondence and inquiry data: Retained for up to one year after resolution of the inquiry or complaint.
After these periods, your data will be securely deleted or anonymised.
Data Processors and Sharing
To deliver our services efficiently, we use trusted third-party processors who may process your personal data on our behalf. These include:
- Payment processors: For secure payment handling and fraud prevention.
- Delivery partners: To ensure timely flower and gift deliveries to your specified address.
- IT and website service providers: For secure hosting, maintenance, and technological support.
All processors are required to comply with GDPR, ensuring data security and confidentiality. Personal data is not sold, rented, or disclosed to third parties for unrelated marketing purposes. We only share information necessary to perform our business functions and fulfil your orders.
International Data Transfers
Florist Harringay aims to ensure your data remains within the United Kingdom or the European Economic Area (EEA) wherever possible. If it is necessary to transfer your data outside of these regions, we will ensure that adequate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or the UK Information Commissioner’s Office.
Your Rights Under GDPR
You have a number of rights concerning your personal data under GDPR:
- Right to access: You may request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct any inaccurate or incomplete information.
- Right to erasure: You can request deletion of your personal data, subject to legal obligations to retain certain records.
- Right to restrict processing: In certain circumstances, you can request that we restrict the processing of your data.
- Right to data portability: You may ask us to provide your information in a machine-readable format or transfer it to another organisation.
- Right to object: You can object to the processing of your data for direct marketing or on grounds relating to your particular situation.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
If you wish to exercise any of these rights, please contact us with your request. We will respond to your request in accordance with GDPR timeframes.
Data Security
Florist Harringay employs appropriate organisational and technical measures to safeguard your personal data against loss, unauthorised disclosure, alteration, or access. We regularly review our procedures and upgrade our systems to maintain data security at all times.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in regulations or our practices. The latest version will always be available on our website. We encourage you to review this policy periodically.
Contact and Complaints
If you have questions, concerns, or complaints regarding this Privacy Policy or how your information is handled, please contact us directly. If you remain dissatisfied, you have the right to lodge a complaint with the UK Information Commissioner’s Office or your local data protection authority.