Florist St Paul's Cray Privacy Policy
Introduction
This Privacy Policy describes how Florist St Paul's Cray collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This Policy applies to all customers placing orders with Florist St Paul's Cray from St Paul's Cray and the surrounding districts. Please read this Policy carefully to understand how we handle your information, your rights as a data subject, and how you can exercise them.
The Data We Collect
We collect various types of personal data in order to provide you with our floral products and related services. The types of data we collect include:
- Identity Data: Such as your full name and, where relevant, the recipient’s name if you are ordering on behalf of someone else.
- Contact Data: Including your address, delivery address, and contact details (e.g., postal address).
- Order Information: Details about your orders, such as products selected, delivery preferences, special instructions, and purchase history.
- Payment Information: Information required for transaction processing, such as payment card details or alternative payment methods. (Please note: actual card numbers are processed directly by secure third-party payment providers; we do not store your card details.)
- Technical Data: When you visit our website or interact with us online, we may collect your IP address, browser type, and device identifiers via cookie technology for security and functional purposes.
- Correspondence: Information from any communication or feedback you send us, including queries, complaints, or compliments.
Lawful Basis for Processing
We only process your personal data where permitted by law. The main lawful bases we rely upon are:
- Contractual Necessity: We process your data to fulfill orders and provide the products and services you request, including processing payments, managing deliveries, and handling customer service matters.
- Legal Obligations: Certain data may be processed to comply with legal requirements such as tax or accounting regulations.
- Legitimate Interests: We may process your data to maintain and improve our services, manage business operations, prevent fraud, and ensure the security of our website and premises, provided your fundamental rights do not override these interests.
- Consent: In cases where you give specific consent, such as opting into marketing communications, we process your data on this basis. You have the right to withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing and delivering your floral orders, including updating you about your delivery status.
- Managing payments and preventing fraudulent transactions.
- Communicating with you regarding your order, answering your questions, and addressing any customer service issues.
- Improving our products and services by analyzing order patterns and customer feedback.
- Complying with applicable legal or regulatory requirements.
- With your consent, sending you information about our offers, products, or services.
Data Retention
We will only retain your personal information for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. The retention periods for different types of personal data are determined based on the following criteria:
- Order and Transaction Data: Typically retained for up to six years from the date of transaction to comply with tax and contractual obligations.
- Account Data: If you create an account, your data is kept as long as your account remains active, and will be deleted or anonymised after closure and the expiry of any statutory retention period.
- Marketing Preferences: Data kept until you withdraw your consent or unsubscribe.
- Correspondence: Retained for as long as necessary to resolve your enquiry and/or comply with legal requirements.
After the relevant retention period has expired, your data will be securely deleted or anonymized.
Processors and Sharing Your Data
We may share your personal data with trusted third parties who help us deliver our services, such as:
- Payment gateways and financial service providers for secure transaction processing.
- Delivery partners to ensure your floral order is delivered to the correct address in St Paul's Cray and surrounding districts.
- IT and website support providers who help maintain our systems and online presence.
- Professional advisors (including accountants and legal advisors) where required by law or business need.
All such third parties are required to respect the security of your personal data and to treat it in accordance with the law. We only permit them to process your data for specified purposes and in accordance with our instructions. We do not sell or rent your personal data to third parties for their marketing purposes.
How We Protect Your Information
We take the security of your personal data seriously. We implement appropriate technological and organizational measures to guard against unauthorized access, alteration, disclosure, or destruction of your personal information. These measures include secure servers, encryption protocols for payment processing, routine security assessments, and limited access to your data on a need-to-know basis.
Your Rights as a Data Subject
As a customer of Florist St Paul's Cray, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You may request corrections to any incomplete or inaccurate data.
- Right to Erasure: You can ask us to delete your data in certain circumstances.
- Right to Restrict Processing: You may request us to limit the use of your data in specific situations.
- Right to Data Portability: You can request your data to be transferred in a structured, commonly used, machine-readable format.
- Right to Object: You can object to our processing where we rely on legitimate interests or direct marketing purposes.
- Right to Withdraw Consent: Where we use your data with your consent, you can withdraw this consent at any time.
If you wish to exercise any of your rights, please contact us using the details provided through our official channels.
Changes to This Privacy Policy
We reserve the right to update or amend this Privacy Policy at any time to reflect changes in our practices or relevant laws. We encourage you to review this Policy regularly for updates.
Applicability and Contacting Us
This Privacy Policy applies to all individuals placing orders with Florist St Paul's Cray located in St Paul's Cray and surrounding districts. If you have any questions about this Policy or wish to exercise your rights, please reach out to us via our official communication channels as listed on our website or invoices. Your privacy is important to us, and we are committed to responding promptly to your enquiries.
