Privacy Policy for Earlsfield Flowers Customers
Introduction
This Privacy Policy outlines how Earlsfield Flowers collects, uses, protects, and manages your personal data in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Earlsfield Flowers from Earlsfield and the surrounding districts. We are committed to handling your data lawfully, transparently, and respectfully.
What Data We Collect
Earlsfield Flowers collects only the information necessary to process your order and provide you with the requested services. The types of data we collect may include:
- Personal Identification Data: Name, address, delivery address, postcode, and any instructions related to delivery.
- Contact Information: Telephone number, mobile number, and, if applicable, social media identifiers for communication.
- Order and Transaction Data: Details of your order, purchase history, payment method (not full card details), invoice information, and transaction status.
- Communication Data: Records of communications, including messages or notes about preferences, complaints, or special requests.
- Technical Data: Information provided by your device when accessing our website (such as IP address, device type, and browser type) but only where necessary for order processing or security.
We do not intentionally collect personal data from children under 16 years old, nor do we knowingly process sensitive data unless it is essential to the fulfillment of your order (e.g., allergy information for bespoke arrangements).
Lawful Basis for Processing Your Data
Earlsfield Flowers processes your personal data on specific lawful bases as defined under GDPR. These are:
- Contract: We process your data in order to fulfill the contract of sale — for instance, to deliver your orders and process your payments.
- Legal Obligation: In some cases, data processing is necessary for compliance with legal obligations, such as tax and accounting requirements.
- Legitimate Interests: We may process certain information for our legitimate business interests, such as improving our service, handling customer queries, and preventing fraud, so long as your rights and freedoms are not overridden.
- Consent: If you opt in to receive marketing communications, we will process your contact information based on your explicit consent. You may withdraw your consent at any time.
How We Use Your Data
Your data may be used for the following purposes:
- Processing and fulfilling your order(s).
- Communicating with you regarding your order, including confirmations and delivery updates.
- Managing customer queries, complaints, or requests for support.
- Administrative, accounting, and record-keeping purposes.
- Marketing, only where you have provided explicit consent.
- Improving our products and services by analyzing purchase trends and customer feedback.
Data Retention
Earlsfield Flowers retains your data only as long as is necessary to fulfill the purposes for which it was collected, or to comply with legal, tax, or accounting requirements. The retention periods we apply are as follows:
- Order Records: Typically retained for up to 7 years to comply with financial and tax regulations.
- Contact and Communication Data: Retained for up to 2 years after your last interaction unless you request deletion sooner.
- Marketing Data: If you have consented to marketing, we will retain your data until you unsubscribe or withdraw consent, after which your data will be removed from marketing lists within one month.
Once the applicable retention period has expired, your personal information will either be securely deleted, anonymised, or, if required, archived in a secure manner for legal reasons.
Processors and Third-Party Access
Earlsfield Flowers shares your personal data only with trusted third parties where necessary to process your order and provide our services. Typical processors may include:
- Payment Service Providers: To process your transaction securely.
- Delivery Partners or Couriers: To fulfill your deliveries efficiently within Earlsfield and surrounding districts.
- Accountants or Regulatory Authorities: Where necessary to comply with financial regulations and law enforcement requests.
- IT Providers or Hosting Services: For website functionality, order management, and cybersecurity.
All such third parties are required to handle your data securely and strictly as per our instructions. We do not sell, rent, or trade your personal information for any purpose unrelated to our service provision.
Your Rights Under GDPR
As a customer of Earlsfield Flowers, you have the following rights with regard to your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can request corrections to any inaccurate or incomplete information we hold about you.
- Right to Erasure: You may request deletion of your personal data, provided there are no legal requirements for its retention.
- Right to Restrict Processing: You may ask us to suspend processing in certain circumstances.
- Right to Data Portability: You may request that your data be provided to you or to a third party in a structured, commonly-used format.
- Right to Object: You can object to the processing of your data where processing is based on legitimate interests, or to direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Any requests regarding your rights will be handled promptly and in accordance with GDPR requirements. Proof of identity may be required before fulfilling certain requests.
Data Security
We implement reasonable technical and organisational measures to protect your data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. Only authorised staff and trusted processors with a legitimate need may access your data.
International Transfers
Your personal data is stored within the United Kingdom or European Economic Area (EEA) wherever possible. If data needs to be processed outside these areas, we ensure that appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in how we process your data, changes in law, or improvements in our procedures. All updates will be posted on this page and, where appropriate, notified to you directly.
Contact and Complaints
If you have any questions, concerns, or requests regarding this Privacy Policy or how your data is handled, please contact our customer service team or the manager at Earlsfield Flowers. If you are dissatisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner’s Office or your local data protection authority.