West Drayton Florist Privacy Policy
Introduction
This Privacy Policy describes how West Drayton Florist collects, uses, stores, and safeguards your personal data. It applies to all customers placing orders with West Drayton Florist, whether you are based in West Drayton or surrounding districts. As a responsible florist, we are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and related data protection laws.
What Data We Collect
We collect personal data only as necessary to provide a seamless ordering and delivery experience for our customers. The categories of information we may collect include:
- Personal Identification Information: Name, email address, postal address, and phone number.
- Order Information: Details of flower arrangements, recipient details, delivery addresses, and order history.
- Payment Information: Payment confirmation and transaction details (note: debit/credit card data is securely processed by third-party payment providers and not retained by us).
- Correspondence: Records of any communication between you and West Drayton Florist (including order notes and inquiries).
We do not collect or process special category data such as racial or ethnic origin, religious beliefs, health information, or children’s data.
Lawful Basis for Processing Personal Data
The primary lawful basis under the GDPR for West Drayton Florist to process your personal data is:
- Contractual Necessity: To process and fulfill flower orders at your request, and to communicate regarding your order.
- Legal Obligations: For record-keeping, accounting, and complying with regulatory or legal requirements.
- Legitimate Interests: To improve our products and services, respond to inquiries, and maintain operational efficiency (without overriding your fundamental rights and freedoms).
- Consent: With your explicit consent, we may occasionally send promotional communications. Consent can be withdrawn at any time.
How We Use Your Data
Your personal data is used exclusively for legitimate and necessary business purposes, including:
- Processing your flower orders and facilitating delivery to requested addresses.
- Communicating with you about your order status, updates, and any customer service requests.
- Fulfilling legal, accounting, and tax obligations.
- Improving our offerings based on order data and customer preferences.
- Sending information about relevant offers or events, only when you have opted in to receive such updates.
Data Retention
West Drayton Florist will retain your personal data only for as long as necessary to achieve the purposes outlined above, or as required by applicable law (such as tax records retention). Generally, order and transaction information is retained for up to seven years to meet legal and accounting requirements. Any marketing or consent-based data is retained until you withdraw your consent or opt out of such communications.
Once your data is no longer needed, it will be securely deleted or anonymised.
Third-Party Data Processors
To fulfill our services, West Drayton Florist may engage with trusted third-party service providers ("data processors") such as:
- Payment processors: To securely handle your payment transactions.
- Delivery partners: To deliver floral arrangements to your requested locations.
- IT and website hosting partners: To maintain our online ordering platform, data backup, and security systems.
All such processors are vetted to ensure GDPR compliance and are contractually obliged to protect your data, to act only on our instructions, and never use your data for their own purposes.
Data Security and Storage
Your data is stored within secure systems that employ industry-standard technical and organizational measures to protect against unauthorized access, loss, misuse, or alteration. Access to personal data is strictly limited to staff and processors who require it to perform their duties.
International Data Transfers
West Drayton Florist stores and processes your data within the United Kingdom and the European Economic Area (EEA). Should data be transferred outside these regions, we ensure appropriate safeguards and data protection measures are in place as required by law.
Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right to Access: Obtain a copy of your personal data held by us.
- Right to Rectification: Request corrections to inaccurate or incomplete data.
- Right to Erasure: Ask for your data to be deleted, subject to legal or contractual obligations.
- Right to Restrict Processing: Limit the use of your personal data under certain circumstances.
- Right to Data Portability: Receive your data in a commonly used, machine-readable format and transmit it to another controller.
- Right to Object: Object to processing where we rely on legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time when processing is based on consent.
Requests regarding your rights can be made in writing or by contacting us via the contact details provided on our website or in your order confirmation. We will respond to valid requests within one month, but may require additional information to verify your identity.
Policy Updates
This Privacy Policy may be updated from time to time to reflect changes in phone, legal requirements, or business practices. The latest version will always be available in our store or on our website. We encourage you to review our policy regularly.
Contacting Us
If you have questions or concerns about how your personal data is handled by West Drayton Florist, please use the contact options provided on our website or within your order documents. We are committed to addressing your privacy concerns promptly and transparently.
