Florist East Dulwich Data Protection Policy
  Privacy Policy Overview
At Florist East Dulwich, your privacy is at the heart of our relationship with you. This Privacy Policy applies to all customers who place orders with Florist East Dulwich from East Dulwich and the surrounding districts. This document explains how we collect, use, store, share, and protect your personal data in accordance with the UK General Data Protection Regulation (GDPR). Please read this policy carefully to understand your rights and choices regarding your data.
What Data We Collect
When you place an order or interact with our services, we may collect and process different types of personal information, including:
- Identity Data: Your full name and, where applicable, the recipient's name.
- Contact Data: Delivery address, telephone number, and occasionally billing address.
- Order Details: Purchase history, product choices, card messages, and delivery instructions.
- Payment Data: Information required to process your payment, including payment method and transaction details. (We do not store bank card details; processing is handled securely by payment processors.)
- Communication Data: Correspondence you send to us, including feedback, inquiries, or special requests.
- Technical Data: Device identifiers, IP address, browser type, and usage data when you use our website, for analytic and security purposes.
Lawful Basis for Data Processing
We only collect and process personal data where we have a legal basis to do so. The lawful bases under which we use your information include:
- Contractual Necessity: Processing your order, arranging payment, and fulfilling deliveries. Without this data, we cannot fulfil our contract with you.
- Legal Obligation: Compliance with applicable tax, accounting, and regulatory requirements.
- Legitimate Interests: For running our business efficiently, preventing fraud, improving our services and customer experience, and communicating relevant information to you. We ensure our legitimate interests do not override your rights.
- Consent: If we use your data for marketing purposes beyond what is necessary to fulfil your order, we will seek your clear and explicit consent. You can withdraw this consent at any time.
How We Use Your Data
Your personal information is used for purposes including, but not limited to:
- Processing, confirming, and delivering your order.
- Communicating order updates, delivery confirmations, and addressing any issues.
- Responding to your requests and queries.
- Improving our products, services, and customer experience.
- Complying with our legal and regulatory obligations.
- Sending, if you have consented, occasional promotional information relevant to our products and services.
How Long We Keep Your Data (Data Retention)
We only retain your personal data for as long as needed for the purposes for which it was collected and to fulfil any legal, accounting, or reporting requirements. The criteria used to determine appropriate retention periods include:
- The duration of our business relationship (e.g., while you maintain an account or actively place orders).
- Applicable legal obligations (e.g., keeping order records for tax law compliance, typically up to 6 years).
- Any queries, claims, or disputes that may arise relating to your purchases.
Once the retention period concludes, your data is securely deleted or anonymised.
Processors and Data Sharing
We may share your personal data with trusted third-party processors who help us to deliver our services, but only as necessary. Examples of processors include:
- Payment Processors: To process card payments securely.
- IT and Cloud Service Providers: For website hosting, email communications, and secure data storage.
- Professional Advisors: Accountants, legal advisors, or insurers to comply with legal obligations.
All third-party service providers we use are required to respect the confidentiality and security of your data, to use it only as instructed, and to comply with GDPR requirements. We do not sell or rent your data to any third parties for marketing purposes.
Your Data Protection Rights
Under the UK GDPR, you have a range of rights regarding your personal information. These include:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure: Ask us to delete your personal data where there is no good reason for us to continue processing it.
- Right to Restrict Processing: Request suspension of processing under certain circumstances.
- Right to Data Portability: Request transfer of your data to you or a third party in a structured, commonly used format.
- Right to Object: Object to processing of your data where our lawful basis is legitimate interest, or for marketing purposes.
- Right to Withdraw Consent: If you have given consent for certain uses, you may withdraw this at any time.
To exercise any of these rights, please contact us using the details on our website. We will respond to your request in accordance with GDPR.
Security Measures
We use a range of technical and organisational measures to safeguard your personal information and protect it from unauthorised access, loss, misuse, or alteration. These include encrypting sensitive data, regular security reviews, access controls, and staff training in data protection. While we strive to ensure absolute security, no online system is entirely risk-free and we recommend that you take your own precautions to protect your data online.
Policy Scope and Updates
This Privacy Policy applies to all customers of Florist East Dulwich placing orders within East Dulwich and the surrounding districts. We may occasionally update this policy to comply with changes in law or our business practices. Where relevant, we will notify you of significant updates. The current version will always be available on our website and will supersede any previous versions.
Contact and Concerns
If you have questions about this policy, your rights under the GDPR, or concerns about the way Florist East Dulwich processes your data, please refer to our website for contact details. You also have the right to lodge a complaint with the UK Information Commissioner's Office if you believe your data has been handled unlawfully.