Privacy Policy for Florist Kentish Town Customers
Introduction
This Privacy Policy explains how Florist Kentish Town ("we", "our", or "us") collects, uses, and protects the personal data of customers who place florist orders from Kentish Town and the surrounding districts. We are committed to complying with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and ensuring the confidentiality and security of your personal information.
Scope of this Policy
This Privacy Policy applies to all individuals who purchase products or services from Florist Kentish Town in Kentish Town and neighbouring areas, whether ordering in person, by telephone, or through our online service channels.
What Data We Collect
We collect only the personal data necessary to fulfil your order and provide the requested services. Depending on how you interact with us, we may collect the following categories of data:
- Identity Information: Such as your name and, if you are purchasing as a business, company details.
- Contact Information: Including delivery address, billing address, phone number, and payment details.
- Order Information: Details of the products and services you have ordered, preferred delivery date, and recipient data if sending flowers to someone else (including their name and delivery address).
- Communication Information: Records of communications with us, such as customer service queries, feedback, and customer support requests.
- Technical Data: Details about your use of our website, such as IP address, browser type, and reference sources (if applicable).
We do not intentionally collect special category data (such as health, religious, or biometric information), nor do we use your data for automated decision-making or profiling.
Lawful Basis for Processing Your Data
Under the GDPR, we must have a lawful basis to process your personal data. For the activities described in this Policy, we rely on the following bases:
- Contract: We process your personal data to take steps at your request before entering a contract, and to fulfil our contractual obligations (for example, to deliver the flowers you ordered).
- Legal Obligation: Certain information may be retained or processed to comply with our legal and accounting requirements (such as tax or anti-fraud obligations).
- Legitimate Interests: We may use certain data for our legitimate business interests, such as improving our products and services, managing customer relationships, gaining feedback, and ensuring the security of our website. When relying on legitimate interests, we always balance our interests against your rights and freedoms.
- Consent: Where required by law, for example for marketing communications, we will request your explicit consent.
How We Use Your Data
Your personal data is used only for legitimate business purposes, including:
- Processing and fulfilling your floristry orders
- Arranging delivery and managing payments
- Communicating with you about your order or requested services
- Responding to queries, complaints, or requests related to our services
- Improving our products and customer service offerings
- Fulfilling our statutory and legal obligations
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. Factors considered when determining appropriate retention periods include:
- The nature and sensitivity of the data
- The purposes for which the data was collected and whether those purposes have been fulfilled
- Any applicable legal or regulatory obligations requiring us to retain information for specific periods (such as accounting or tax laws)
- Our legitimate interests in retaining records (for example, to respond to claims or complaints)
Typically, we will retain order-related data for up to seven years in accordance with UK tax and accounting regulations. Data used solely for marketing or communications is retained until you withdraw your consent or unsubscribe.
Processors and Data Sharing
We take steps to keep your data secure and only share it when strictly necessary. In certain cases, we may share your personal information with trusted third-party service providers ("processors") who perform services on our behalf, including:
- Payment processing companies (to complete transactions)
- Delivery partners (for transporting or delivering your orders)
- IT and system support providers (who help maintain our website and internal systems)
- Professional advisers, such as accountants or legal consultants (where required by law)
All processors are contractually obligated to handle your data securely and in accordance with the GDPR. We do not sell or rent your data to third parties. In the unlikely event that we need to transfer your data outside the United Kingdom or European Economic Area, we will ensure that appropriate safeguards are in place to protect your information.
Security of Your Personal Data
We implement technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse. These measures include encrypted payment processing, secure storage of records, and limiting access to your information only to those who need it to perform their job functions.
Your Rights under GDPR
As a data subject, you have the following rights in relation to your personal data:
- The right to access – You can request details about the personal data we hold about you and how we use it.
- The right to rectification – You can ask us to correct inaccurate or incomplete data.
- The right to erase ("the right to be forgotten") – You may request deletion of your data where there is no valid reason for its continued retention.
- The right to restrict processing – You may ask us to temporarily stop processing your data in certain circumstances.
- The right to data portability – Where lawful, you may request a copy of your data in a commonly used format.
- The right to object – You can object to the use of your data for direct marketing or where we rely on our legitimate interests as the lawful basis for processing.
- The right to withdraw consent – You can withdraw your consent at any time where processing is based on consent (such as for marketing communications).
To exercise your rights, or if you have any questions or concerns about our handling of your personal data, please contact us using the communication methods available on our website.
Changes to this Policy
We reserve the right to update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We encourage you to review this notice periodically. Where significant changes are made, we will take reasonable steps to notify customers as appropriate.
Contact and Complaints
If you have any questions about this Privacy Policy, or if you wish to make a complaint about our handling of your data, please get in touch using the contact methods provided on our website. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.