Erith Florist Privacy Policy
Introduction
This Privacy Policy outlines how Erith Florist collects, uses, stores, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). It applies to all customers placing orders with Erith Florist from Erith and the surrounding districts. Our commitment is to transparency, fairness, and respect for your privacy rights.
What Data We Collect
When you place an order with Erith Florist, either via our website, telephone, or in person, we may collect the following types of data:
- Personal Identification Data: Your name, and in some cases, the name of the recipient of floral arrangements.
- Contact Details: Address (for delivery or invoicing), phone number, and, if provided, email address.
- Order Information: Details of the floral products purchased, delivery instructions, personalised card messages, and relevant transaction history.
- Payment Details: Card or payment details (processed securely via our payment processors and not stored by Erith Florist directly).
- Correspondence: Records of communication with you regarding your orders, enquiries, or complaints.
- Technical Data: When using our website, we may collect device type, operating system, browser type, and usage analytics through cookies for operational and statistical purposes.
Lawful Basis for Processing Your Data
The GDPR requires us to identify our lawful basis for collecting and processing your personal data. We rely on the following bases:
- Contractual Necessity: Processing your data is necessary for fulfilling our agreement with you (e.g., delivering your order, processing payments).
- Legitimate Interests: We may use your information to improve our services, manage our business efficiently, and handle any enquiries or complaints, so long as these interests do not override your privacy rights.
- Legal Obligations: Where the law requires us to, we may process your data to comply with fiscal, tax, or other statutory requirements.
- Consent: Where you provide explicit permission (e.g., marketing communications), we rely on your consent, which you may withdraw at any time.
How We Use Your Data
Your data is used for purposes including:
- Processing and delivering your orders for floral products.
- Managing payments, refunds, and order status notifications.
- Responding to your queries, feedback, and complaints.
- Providing customer support and after-sales service.
- Enhancing our website, products, and services based on aggregated analytics data.
- Fulfilling our legal obligations, such as maintaining sales records for tax purposes.
- Sending direct marketing communications, only where we have your consent.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Typically, this means:
- Order and Delivery Data: Retained for up to 7 years to comply with tax and business regulations.
- Marketing Data: Retained until you withdraw consent or unsubscribe from communications.
- Enquiry Data: Retained for 2 years from the date of last contact, unless part of an ongoing service or complaint process.
When data is no longer required, it is securely deleted or anonymised.
Data Processors and Third Parties
To provide our services, we may share your necessary data with trusted third-party processors, such as:
- Payment processing companies for transaction management.
- IT and website hosting providers for digital service delivery.
- Courier and delivery services to ensure timely floral deliveries.
- Professional advisors, such as accountants or legal consultants, where required by law.
All third-party processors are contractually obliged to handle your data in accordance with GDPR and to implement security measures to protect your information. We do not sell your data to third parties for their marketing or commercial purposes.
International Data Transfers
Some of our service providers may transfer, process, or store your data outside the United Kingdom and the European Economic Area (EEA). Where this occurs, we ensure that adequate safeguards are in place to protect your data, such as data protection agreements or certification under approved schemes.
Your Rights
Under GDPR, you have the following rights regarding your personal information:
- Right to Access: Request a copy of any data we hold about you.
- Right to Rectification: Ask us to update or correct inaccurate data.
- Right to Erasure: Request the deletion of your data when it is no longer needed.
- Right to Restrict Processing: Temporarily limit how we use your data under certain circumstances.
- Right to Data Portability: Request that we transfer your data to another provider in a structured, commonly used format.
- Right to Object: Object to our processing of your data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw your consent at any time where processing is based on consent.
- Right to Lodge a Complaint: Make a complaint to the relevant supervisory authority if you believe your data protection rights have been breached.
To exercise any of these rights, please contact us using the communication methods detailed on our website or in store.
Security of Your Data
We implement appropriate technical and organisational measures to safeguard your personal information. These include secure servers, encrypted payment processing, access controls, and regular staff training on data protection.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services or legal requirements. The latest version will always be available at our website or upon request in-store. We encourage you to review it regularly.
Contacting Us
If you have any questions or concerns about how your data is handled by Erith Florist, or you wish to exercise your rights under this policy, please use the contact information provided on our website or visit our store. We are committed to responding promptly to any privacy-related enquiries.