Privacy Policy for Florist Chingford Customers

Introduction

This Privacy Policy outlines how Florist Chingford collects, uses, stores, and protects the personal data of customers placing orders from Chingford and its surrounding districts. We are dedicated to safeguarding your privacy and ensuring compliance with the General Data Protection Regulation (GDPR). By using our services, you agree to the practices described in this policy.

Scope of Policy

This Privacy Policy applies to all customers who order products or services from Florist Chingford, whether through our website, by telephone, or in person, where the order is placed for delivery or collection in Chingford and the neighbouring districts.

Personal Data We Collect

We collect and process only data necessary for delivering our products and services efficiently and lawfully. The categories of personal data we may collect include:

  • Identity data: Name of the person placing the order; recipient’s name.
  • Contact data: Delivery address, billing address, telephone number, and delivery instructions.
  • Order details: Date and time of order, items purchased, message for the recipient, and preferred delivery date.
  • Payment data: Details required for processing payment, such as payment card information (processed via secured third-party payment processors; we do not store complete card numbers).
  • Communication data: Records of your correspondence with us, such as messages, order instructions, and feedback.

Lawful Basis for Processing

We process your personal data in accordance with the GDPR under the following lawful bases:

  • Contract: Processing is necessary for the performance of the contract with you. For example, to fulfil your order and deliver flowers to your specified address.
  • Legitimate interests: Where processing is necessary for our legitimate interests, such as improving our services, protecting our business, or responding to your inquiries, except where overridden by your interests or fundamental rights and freedoms.
  • Legal obligation: To comply with legal requirements, including financial regulations and record-keeping obligations.
  • Consent: In certain cases, such as direct marketing activities, we will only use your data with your explicit consent. You may withdraw consent at any time.

How We Use Your Data

Your personal data may be used for the following purposes:

  • Processing and delivering your flower order, including handling payment and logistics.
  • Contacting you regarding your order and responding to your queries or feedback.
  • Sending important service communications, such as order confirmation or delivery updates.
  • Improving our website, products, and services based on customer feedback.
  • Complying with accounting, tax, and regulatory obligations.

Data Retention

We retain your personal data for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting requirements. Typically, the data related to your orders will be retained for up to six years, to comply with UK tax and business regulations. We will review retention periods regularly and securely delete or anonymise data when it is no longer required.

Data Processors and Third Parties

We use trusted third-party service providers (data processors) to deliver our services efficiently and securely. These may include:

  • Payment processors: For secure processing of card payments. We do not store full payment card details on our systems.
  • IT and cloud service providers: For hosting our website, managing data securely, and back-up services.
  • Delivery partners: For the delivery of your order to the recipient as instructed.

All third-party providers are GDPR-compliant and are only permitted to use your personal data in accordance with our instructions for agreed purposes. Any transfer of data outside the UK or EEA is protected by appropriate safeguards.

Your Rights Under GDPR

You have several rights under the GDPR regarding your personal data:

  • Right to access: You can request a copy of the personal data we hold about you.
  • Right to rectification: You can request correction of any inaccurate or incomplete data.
  • Right to erasure: You can request the deletion of your data where there is no lawful reason for us to continue holding it.
  • Right to restrict processing: You can request we limit how we use your data.
  • Right to object: You can object to processing based on legitimate interests or direct marketing.
  • Right to data portability: You can request transfer of your data to another service provider in a structured, commonly used format.

To exercise any of your rights, you may contact us using our contact page or in writing at our shop address. We may require proof of your identity before fulfilling your request. We aim to respond to all legitimate requests within one month.

Security of Your Data

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. This includes secure servers, encryption, robust access controls, and regular data protection reviews.

Children’s Privacy

Our products and services are not intended for children under the age of 16. We do not knowingly collect or process data relating to children. Where it is necessary to process such data (for example, orders placed on behalf of children), this must be provided by a parent or legal guardian.

Changes to This Policy

This Privacy Policy is reviewed and updated from time to time to ensure it remains accurate and compliant with applicable law. Material changes will be communicated on our website with the updated date. We encourage you to review this policy regularly.

Contact and Complaints

If you have any questions, concerns, or want to exercise your data rights regarding this Privacy Policy, please use the contact details provided on our website or visit our premises. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK.