Florist Finchley Privacy Policy Summary
Introduction
This Privacy Policy describes how Florist Finchley ('we', 'us', or 'our') processes and protects the personal data of all customers placing orders from Finchley and surrounding districts. Safeguarding your privacy is central to our values and operations. We comply fully with the General Data Protection Regulation (EU) 2016/679 ('GDPR') and all relevant UK and EU data protection legislation. Please review this policy carefully to understand your rights and our practices concerning your data.
What Data We Collect
To provide our services efficiently and securely, we collect the following types of data:
- Identity Data: Your full name, and occasionally, titles or honorifics.
- Contact Data: Delivery address, billing address, and, if provided, your telephone number.
- Order Information: Details of the bouquet or product ordered, messages to accompany flowers, and any specific delivery instructions.
- Transaction Data: Payment method, order date, order value, and payment status. We do not store or process your full card details directly; these are managed by secure payment processors.
- Correspondence: Copies of communications sent to or from Florist Finchley related to your order, customer queries, or feedback.
- Technical Data: IP address, browser type, time zone settings, and cookies collected through our website for functionality and analytics, if and when applicable.
Lawful Bases for Processing Your Data
We only process your personal information when we are satisfied that our legal basis for doing so is fair and lawful. The principal lawful bases we rely upon under Article 6 of the GDPR include:
- Performance of Contract: We collect, use, and share your data to process your order, arrange delivery, accept payment, and provide customer care as needed.
- Legal Obligation: We are mandated to retain some data to comply with legal requirements including tax, fraud prevention, and record-keeping regulations.
- Legitimate Interests: Where appropriate, we may use your data to improve our services, prevent fraud, secure our website, or contact you post-sale regarding your order (such as delivery follow-ups or product recalls).
- Consent: Where you have expressly agreed (for example, for marketing communications), we will rely on your consent. You retain the right to withdraw this consent at any time.
How We Use Your Data
Your data is used exclusively for fulfilling orders, processing payments, arranging deliveries, responding to your queries, safeguarding business operations, and (where consented) providing marketing updates. We never sell your data to third parties.
Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes outlined in this policy:
- Order and Transaction Data: Retained for up to six years to meet accountancy, tax, and legal requirements.
- Customer Correspondence: Typically retained for 2 years from the date of your last communication with us.
- Marketing Data: Held until you withdraw consent or request deletion.
- Technical Data: Stored according to industry practices, usually no more than 24 months for analytics and security.
At the end of these retention periods, your data is securely deleted or anonymised.
Data Processors & Third Parties
To fulfil your order and operate effectively, we work with carefully selected data processors. These include:
- Payment Services: Secure third-party payment gateways process your payments without exposing your full card details to us.
- Delivery Partners: Reputable local carriers and couriers may receive recipient contact and address for order fulfilment.
- IT Service Providers: Providers who host our website, support customer management systems, or assist with secure data storage.
All processors act only on our documented instructions and are compliant with applicable data protection law. They implement strict security standards and must not use your data for their own purposes.
Security Measures
Your privacy is protected by multiple technical and organisational safeguards. We maintain robust access controls, regular security reviews, and encryption measures for sensitive data. Only authorised personnel have access to your information.
Your Rights Under GDPR
You have a range of rights under GDPR concerning the personal information we hold about you:
- Right of Access: Request a copy of the data we hold about you.
- Right to Rectification: Request corrections of incomplete or inaccurate information.
- Right to Erasure: Request deletion of your data under certain conditions.
- Right to Restrict Processing: Ask us to limit the way we use your data.
- Right to Data Portability: Receive your data in a commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or consent, including marketing.
- Right to Withdraw Consent: Withdraw previously given consent at any time.
- Right to Lodge a Complaint: Lodge a complaint with the UK’s Information Commissioner’s Office (ICO) if you believe your data is mishandled.
To exercise any of these rights, please contact us using the methods provided on our website or written correspondence address. All requests will be responded to within one month as required by law.
Policy Applicability and Updates
This Privacy Policy applies to all individuals who order from Florist Finchley from within Finchley and surrounding districts. We may update this policy from time to time to reflect changes in our practices or legal obligations. The most current version is always available on our website, with changes effective upon posting.
Contact and Additional Information
If you have any questions about this policy, your privacy, or how we handle personal data, please consult our website for further details or contact us using the communication channels provided there. We are committed to working constructively to resolve any concerns regarding your information and privacy.