Florist Clerkenwell Privacy Policy
Introduction
This Privacy Policy explains how Florist Clerkenwell ('we', 'us', 'our') collects, uses, processes, and protects your personal data in compliance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Florist Clerkenwell from Clerkenwell and the surrounding districts. We are committed to handling your information responsibly and transparently.
What Data We Collect
To process your orders and provide our floral services, we collect various categories of personal data. The types of information we may collect include:
- Identity Data: Your full name, delivery recipient’s name, and company name if provided.
- Contact Data: Billing and delivery address, telephone numbers, and other contact details you supply to facilitate your order delivery and communication.
- Transactional Data: Details of the products you have ordered from us, purchase dates, order value, and payment methods (note: we do not store your card numbers, only payment reference details).
- Communication Data: Records of correspondence when you contact us about your order or send a query, including any notes made on our systems in relation to customer service.
- Technical Data: Your IP address, browser type, device information, and information about how you use our website. This information is collected via cookies and similar technologies to enhance your experience on our website.
No special category data (such as data relating to health, religion, or ethnicity) is intentionally collected in the course of processing regular orders.
Lawful Basis for Processing
We process your personal data under the following lawful bases as set out in Article 6 of the GDPR:
- Performance of a Contract: To process and deliver your order as requested, manage payments, and fulfil our service obligations.
- Legal Obligation: To comply with applicable UK laws and tax regulations that require us to retain information regarding financial transactions and customer orders.
- Legitimate Interests: To communicate with you regarding your order, handle any complaints, improve our products and services, and enhance your customer experience. We only rely on this basis where such interests are not overridden by your fundamental rights and freedoms.
- Consent: In certain cases, such as sending you promotional material or marketing newsletters where you have specifically opted in. You may withdraw your consent at any time.
How We Use Your Information
Your information is used solely for the purposes set out above, which include processing your order, arranging delivery, communicating with you regarding your purchase, and maintaining our business records. We do not sell or lease your data to third parties.
Data Retention
We retain your personal data only as long as is reasonably necessary for the purposes described in this policy or to comply with legal and regulatory requirements. Typically, we will retain:
- Order and transactional data for a minimum of 6 years to comply with UK accounting and tax laws.
- Correspondence and communication records for as long as required to manage your customer service needs and in line with our internal retention policies.
- Technical data (such as cookie data) is retained in line with our cookie policy and the settings you select when visiting our website.
Once data is no longer required, it will be securely deleted or anonymised so that it can no longer be associated with you.
Processors and Third Parties
We may share your personal data with carefully selected third-party processors who assist us in delivering our services, subject to GDPR-compliant data processing agreements. These include:
- Payment Processors: To process payments securely for your orders. Payment information is handled by approved third-party providers and is not retained on our own systems.
- Delivery Partners: To fulfil delivery of your orders, using only the information necessary to complete the delivery.
- IT Service Providers: Who help host and maintain our website, databases, and business systems.
All data processors act only on our instructions and are required to comply with GDPR data protection standards. We do not allow our third-party providers to use your personal data for their own purposes.
User Rights Under GDPR
You have several important rights under the UK GDPR regarding your personal data, including:
- The right to access: You can request information about the personal data we hold about you and how it is processed.
- The right to rectification: You can ask us to correct any inaccurate or incomplete data we hold about you.
- The right to erasure: You can ask us to delete your personal data under certain circumstances, except where legally required to retain it.
- The right to restrict processing: You can request that we suspend the processing of your data in certain situations.
- The right to object: You can object to the processing of your data if you feel it impacts your rights and freedoms.
- The right to data portability: Where applicable, you can request a digital copy of your data to transfer to another provider.
- The right to withdraw consent: Where we rely on your consent, you can withdraw it at any time.
If you wish to exercise any of your rights under GDPR, please contact us via our customer service channels as outlined at the end of this policy. We may ask for identification to confirm your request and respond within one month as required by law.
Data Security
We take appropriate technical and organisational measures to secure your personal data against unauthorised access, loss, destruction, or disclosure. Our website is regularly maintained and uses secure encrypted connections. Access to your information is limited to staff and data processors who need it to perform their role.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our privacy practices. The revised version will be posted on our website with the date of the most recent update. We recommend that you check this page from time to time to ensure you are familiar with the current version.
How to Contact Us
If you have any questions about this Privacy Policy, your data protection rights, or wish to make a request or complaint, please contact Florist Clerkenwell via the contact options displayed on our website or available in your customer documentation. We will acknowledge and respond to requests or complaints in line with our obligations under data protection law.