West Hampstead Florist Privacy Policy
About This Privacy Policy
This Privacy Policy explains how West Hampstead Florist collects, uses, processes, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). The policy applies to all customers who place orders with West Hampstead Florist from West Hampstead and surrounding districts, whether online, in-store, or by telephone. Please review this policy carefully to understand your rights and how your information is managed.
What Data We Collect
When you place an order or interact with West Hampstead Florist, we collect personal data necessary to provide our services and ensure a smooth customer experience. This data includes:
- Identity Data: Your full name and, when applicable, company name.
- Contact Data: Billing and delivery addresses, phone numbers, and, where required, email addresses.
- Order Information: Details of the products you purchase, order history, payment method choice (but not your card details, which are handled securely by our payment processor), and any delivery instructions.
- Recipient Data: Names, addresses, and any other information required for order delivery to a recipient other than yourself.
- Technical Data: IP address, browser type and version, time zone setting, and device information (when using our website and consenting to cookies).
- Correspondence: Records of communication, including messages, feedback, or complaints you send to us.
The Lawful Basis for Processing Your Data
We only collect and process your data where we have a lawful basis under GDPR. West Hampstead Florist relies on the following lawful grounds:
- Contractual Necessity: To process and deliver your orders, provide customer support, and fulfil our obligations as part of the service you have requested.
- Legitimate Interests: To improve our products and services, communicate promotions, prevent fraud, and maintain the security of our operations, provided these interests are not overridden by your rights and freedoms.
- Legal Obligation: To retain transactional records and comply with UK tax or accounting regulations.
- Consent: Where required, such as for certain marketing communications; you can withdraw consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- To process and fulfil your flower orders, including delivery to your chosen recipient.
- To contact you regarding your order or any queries you raise.
- To manage payments through secure third-party payment processors.
- To improve our customer service and product offerings.
- To keep proper business records, as required by law.
- To send direct marketing communications, where you have agreed to receive these.
Data Retention
We retain your personal data only for as long as is necessary to fulfil the purpose for which it was collected, including for satisfying legal, accounting, and reporting obligations. Typically, we retain order-related data for up to seven years to comply with UK legal requirements. Other correspondence or marketing preferences will be held only as long as you maintain a relationship with West Hampstead Florist or until you withdraw your consent. When data is no longer needed, it is securely deleted or anonymized.
Sharing and Processors
We treat your personal data with care. However, to deliver our services, we may share your information with:
- Payment Processors: Secure, GDPR-compliant third parties to handle your payment transactions. We do not store your card details on our systems.
- Delivery Partners: Couriers or delivery agents who require your data to fulfil orders. They are bound by confidentiality and may not use your data for other purposes.
- IT and System Support: Providers who offer technical support, data hosting, website functionality, and security services, acting strictly as data processors under our direct instructions.
- Legal or Regulatory Authorities: Where disclosure is required by law.
We never sell your data or share it with other third parties for their own purposes.
Keeping Your Data Safe
West Hampstead Florist is committed to protecting your data. We adopt appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect. Access to your data is limited to those employees, agents, and processors who need it to perform their duties.
Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
- Right to be Informed: To know how and why your data is being processed.
- Right of Access: To request a copy of the personal data we hold about you.
- Right to Rectification: To request correction of inaccurate or incomplete data.
- Right to Erasure: To request deletion of your data where there is no valid reason for its retention.
- Right to Restrict Processing: To limit how we use your data in certain circumstances.
- Right to Data Portability: To receive your data in a structured, commonly used format and transfer it to another provider.
- Right to Object: To object to processing based on legitimate interests or for direct marketing purposes.
- Rights Regarding Automated Decision-Making: To not be subject to decisions based solely on automated processing, where applicable.
If you wish to exercise any of these rights, contact us using the methods outlined in our standard communications.
Changes to This Policy
We may update this Privacy Policy from time to time. Any significant changes will be brought to your attention through our website or by direct communication where appropriate. Please review this Policy periodically to stay informed about how your data is protected.
Contact and Further Information
If you have any questions about this Privacy Policy or wish to exercise your rights, please get in touch with West Hampstead Florist through your usual means of communication with us. We are committed to addressing any concerns and ensuring your data is managed in accordance with your rights and the law.