Stanmore Florist Privacy Policy – Your Rights Under GDPR
Introduction
This Privacy Policy is issued by Stanmore Florist and applies to all customers placing orders with us from Stanmore and surrounding districts. We are committed to protecting your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR) and relevant UK data protection legislation.
Personal Data We Collect
Stanmore Florist collects and processes a range of personal data from customers in connection with flower orders and related services. The types of personal data we may collect include:
- Contact Information: Your name, delivery address, billing address, and contact details such as telephone number.
- Order Details: Information about the products you order, delivery instructions, and relevant notes provided to customise your order.
- Payment Information: Payment card details and transaction information (note that card details are processed securely by our payment processor and not stored by us).
- Recipient Information: Name, address, and contact information for individuals receiving the flowers as part of your order.
- Correspondence: Records of communications, such as queries, order confirmations, or complaints.
- Usage Data: Technical data collected when you use our website, such as IP address, browser type, and browsing activity, through cookies or similar technologies.
Lawful Basis for Processing
Under GDPR, we must have a lawful basis for processing your data. Stanmore Florist relies on the following lawful bases:
- Contractual Necessity: The majority of the data we collect is processed to fulfil your orders, manage deliveries, and provide customer service. Without this information, we cannot process your purchase or fulfil our contract with you.
- Legal Obligations: We may process your information to comply with legal requirements, such as record-keeping for accounting or tax purposes.
- Legitimate Interests: We process personal data to improve our services, prevent fraud, or contact you about your orders. These activities do not override your rights and freedoms.
- Consent: For optional activities, such as sending marketing communications, we will only process your information if you have provided consent. You can withdraw consent at any time.
How We Use Your Data
The data we collect is used for the following purposes:
- Processing and delivering your orders.
- Communicating order confirmations, delivery updates, or customer service information.
- Handling payments and refunds.
- Maintaining our records as required by law.
- Improving our website and customer experience.
- Where consented, sending you marketing or promotional information about Stanmore Florist’s products and services.
Data Retention
Stanmore Florist retains your personal data only for as long as necessary for the purposes for which it was collected. Typical retention periods are:
- Order and Customer Data: Retained for up to six years from the date of transaction to comply with legal, accounting, and tax requirements.
- Marketing Data: Retained until you withdraw your consent or unsubscribe from marketing communications.
- Technical Data: Retained according to our cookie policy and as required to ensure the secure operation of our website.
Data Processors and Third Parties
To fulfil our contractual and legal obligations, we may share your personal data with trusted third parties and service providers, such as:
- Payment Service Providers: Securely process payment transactions on our behalf; we do not store your card details.
- Delivery Partners: Deliver your flowers and gifts to the designated recipients using the contact and address information you provide.
- IT and Support Providers: Assist in maintaining our website, system security, and email communications.
All third-party processors are required to process your personal data in accordance with our instructions and are bound by appropriate confidentiality and security obligations. We do not sell your data to any third parties.
Your Rights
You have a number of rights under GDPR regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: If you believe any data we hold is inaccurate or incomplete, you can ask us to correct it.
- Right to Erasure: You have the right to request deletion of your data in certain circumstances, for example where it is no longer needed or you have withdrawn consent.
- Right to Restriction: You can ask us to restrict or stop processing your data in specific situations.
- Right to Data Portability: Where applicable, you can request your data in a structured, commonly-used digital format.
- Right to Object: You can object to processing based on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time.
To exercise any of these rights, please contact us using the details provided on our website or in-store.
How We Protect Your Data
We implement appropriate technical and organisational security measures to protect your personal data. This includes limited access to your data, secure payment processing, regular review of our security practices, and staff training.
Updates to This Policy
This Privacy Policy may be updated periodically to reflect changes to our practices or for other operational, legal, or regulatory reasons. The latest version will always be available via our website and in-store.
Contact and Complaints
If you have any questions about this Privacy Policy, your personal data, or wish to make a complaint, please reach out to us using the contact details available on our website or visit us in-store. You also have the right to lodge a complaint with the UK Information Commissioner’s Office if you are dissatisfied with how we handle your data.