Florist Acton Privacy Policy - Your Data and GDPR Rights
Introduction
This Privacy Policy describes how Florist Acton collects, uses, and protects your personal data whenever you place an order with us, either directly or through our website. The policy applies to all customers ordering from Florist Acton in Acton and the surrounding districts. We are committed to complying with the General Data Protection Regulation (GDPR) and ensuring the privacy and security of your information.
What Data We Collect
When you interact with Florist Acton, we may collect the following categories of information:
- Contact Information: Name, delivery address, billing address, and phone number for both customer and recipient, if applicable.
- Order Details: Products ordered, card messages, delivery instructions, and order history.
- Payment Information: Payment method selected (but not bank card details, as payments are processed by secure third-party providers).
- Technical Data: IP address, browser type, and information about your use of our website (e.g., cookies and analytics data).
- Correspondence: Any communications sent to us, such as enquiries or complaints.
Lawful Basis for Processing
Florist Acton only processes your personal data where there is a lawful basis under the GDPR. The primary grounds upon which we rely include:
- Contractual Necessity: We require certain information from you to fulfil and deliver your order. If you do not provide this data, we may be unable to process your order.
- Legitimate Interests: We may process data where it is necessary for our legitimate business interests, such as improving our services, maintaining order histories, or ensuring safe and secure transactions, provided these do not override your fundamental rights and freedoms.
- Legal Obligations: In some cases, we may process data to comply with regulatory or legal requirements, such as tax and accounting rules.
- Consent: Where required, for example for direct marketing, we will ensure we have your clear and informed consent before using your data for such purposes. You may withdraw consent at any time.
How We Use Your Data
Your personal information is used for the following purposes:
- To process, prepare, and deliver your floral orders.
- To communicate with you about your order, including order status and delivery notifications.
- To address your requests, questions, or concerns.
- To improve our products, services, website content, and customer experience.
- To fulfil legal and accounting obligations.
- To send you marketing communications (only if you have opted in to receive them).
Data Retention
Florist Acton will only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements. In general, we retain order and contact data for up to 6 years to comply with tax and accounting laws and to help address any ongoing or repeat customer needs. After this period, data is securely erased or anonymised so that individuals can no longer be identified.
Processors and Data Sharing
We do not sell your personal data. However, we may share your information with carefully-selected third-party processors and service providers in accordance with GDPR, including:
- Payment Processors: To securely handle card and online payments. Payment details are handled by third-party providers and are not stored by Florist Acton.
- Delivery Partners: To ensure timely and accurate delivery of your orders within Acton and surrounding areas.
- IT and Web Hosting Providers: To maintain our website, manage our databases, and ensure IT security.
- Professional Advisors: Such as accountants or legal consultants, only to the extent required for compliance with our obligations.
All processors are engaged under contracts that require them to treat your data securely and in accordance with data protection law. Data is only shared outside the UK or EEA with adequate safeguards in place.
User Rights under GDPR
You have several rights relating to your personal data under GDPR, including:
- Right to Access: You can request a copy of the personal information we hold about you.
- Right to Rectification: You may ask us to correct or complete any incorrect or incomplete data.
- Right to Erasure: In certain circumstances, you may request that we delete your personal data.
- Right to Restrict Processing: You may ask us to stop processing your data in specific situations, for example, while a request for correction is pending.
- Right to Data Portability: Where applicable, you can request that we transfer your data to another service provider.
- Right to Object: You can object to the processing of your data in certain circumstances, such as for marketing purposes.
- Right to Withdraw Consent: Where we rely on your consent, you are free to withdraw it at any time. Withdrawal of consent does not affect lawfulness of processing prior to withdrawal.
- Right to Complain: If you have concerns about how your data is handled, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
How We Protect Your Information
We implement appropriate technical and organisational measures to protect your data against unauthorised access, loss, misuse, or disclosure. These include secure servers, controlled access, and staff training. All access to order information is restricted to authorised personnel only.
Policy Updates
This Privacy Policy is regularly reviewed and may change from time to time to reflect changes in our services, legal requirements, or best practices. We encourage you to revisit this policy periodically to stay informed about how your data is used and protected.
Contacting Us
If you have any questions regarding this Privacy Policy, your rights, or wish to exercise any rights regarding your personal data, please contact us through the contact options provided on our website or in your order confirmation. We will respond to all requests as soon as reasonably practicable and in accordance with applicable laws.