Florist Haggerston Privacy Policy
Introduction
At Florist Haggerston, we are committed to maintaining the trust and confidence of our customers. We understand the importance of your privacy and work diligently to ensure that your personal data is handled responsibly and transparently. This Privacy Policy outlines how we collect, use, store, and protect your information in accordance with the General Data Protection Regulation (GDPR).
This policy applies to all customers placing orders with Florist Haggerston, whether you are ordering from Haggerston itself or the surrounding districts. By placing an order with us, you acknowledge and accept the practices described in this Privacy Policy.
Information We Collect
In providing our floral products and associated services, we collect and process various types of data:
- Personal Identification Data: Such as your full name, billing, and delivery addresses.
- Contact Information: Including your phone number and, if provided, email address for order confirmation and communication about your purchase.
- Order Details: Information about the items purchased, any personal messages for recipients, and delivery instructions.
- Payment Information: Payment method data (such as the last four digits of your card or transaction IDs); note that full payment information is handled securely by our payment processors and is not fully accessed or stored by Florist Haggerston.
- Technical Data: If you order online, this may include your IP address, browser type, operating system, and device identifiers for security, analytics, and optimization of our website.
Lawful Bases for Processing
Under GDPR, we are required to have valid lawful bases for collecting and using your personal information. We rely on the following:
- Contractual Necessity: Processing data to fulfill your order, communicate with you about your purchase, and deliver products or services you have requested.
- Legal Obligation: Retaining necessary transaction records for tax, accounting, and regulatory compliance.
- Legitimate Interests: Enhancing and optimizing your customer experience, preventing fraud, ensuring security, and improving our products and services.
- Consent: Where required, such as for certain direct marketing communications, we will seek your explicit consent. You are free to withdraw consent at any time.
How We Use Your Data
We use your data for the following purposes:
- Processing and fulfilling your floral orders, including delivery to specified recipients.
- Communicating with you regarding your order.
- Managing your payment and maintaining transaction records in line with legal obligations.
- Improving our website, products, and services by analyzing non-identifiable technical usage data.
- Where you have provided consent, sending you updates, promotions, or information that may interest you.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Policy. The specific retention periods depend on the nature of the data and our legal obligations. For example:
- Order and transaction data is generally retained for six years to comply with accounting regulations.
- Contact details and delivery instructions are stored securely and erased or anonymized once no longer necessary unless otherwise required by law.
- If you have provided consent for marketing communications, your contact information will be retained until you opt-out or withdraw consent.
Data Processors and Third Parties
To facilitate our services, we may use trusted third-party service providers (“processors”) who process data on our behalf and only under our instructions. Examples include:
- Payment service providers to process your orders securely.
- IT and hosting partners to operate our website and maintain databases.
- Delivery partners to ensure your flowers reach the correct address.
- Analytics services for website optimization (using anonymized or aggregated data where possible).
All third-party processors are required to adhere to contractual obligations to ensure your data remains secure and is only used in accordance with our instructions and applicable laws.
We do not sell or rent your personal data to any third parties for commercial purposes.
How We Protect Your Data
We implement appropriate technical and organizational security measures to protect your personal data from unauthorized access, accidental loss, disclosure, or destruction. These measures include data encryption, regularly updated cybersecurity protocols, restricted access to sensitive data, and staff training on data protection.
Your Data Protection Rights
Under the GDPR, you have the following rights regarding your personal information:
- Access: You can request a copy of the personal data we hold about you.
- Rectification: You may ask us to correct or update your personal information if it is inaccurate or incomplete.
- Erasure: You have the right to request deletion of your data when it is no longer necessary for the purposes it was collected, except where we have a legal obligation to retain it.
- Restriction: You can request the restriction of processing your personal data under certain circumstances.
- Objection: You may object to processing based on legitimate interests or for direct marketing purposes.
- Data Portability: You have the right to request the transfer of your personal data to another service provider, where applicable.
- Withdraw Consent: If we process your data on the basis of consent, you may withdraw this at any time without affecting the lawfulness of processing before withdrawal.
To exercise these rights, please contact our team directly. We may need to verify your identity to respond to your request to protect your privacy and security.
Policy Changes
We review and may update this Privacy Policy periodically to reflect changes to our data handling practices or for legal reasons. If any significant changes are made, we will notify you appropriately so you remain informed about how we protect your privacy.
Contacting Us
If you have any questions or concerns regarding this Privacy Policy, the ways in which your personal information is processed, or if you wish to exercise your rights as a data subject, please contact our team. We are committed to handling any privacy concerns promptly and transparency is at the heart of our approach to data protection.