Upminster Florist Privacy Policy 2024
Introduction
This Privacy Policy sets out how Upminster Florist collects, uses, stores, and secures your personal information when you order flowers or related products in Upminster and the surrounding districts. Our commitment is to protect your data and respect your privacy in accordance with the UK General Data Protection Regulation (GDPR).
Scope of This Policy
This privacy policy applies to all individuals who place orders with Upminster Florist, whether in person, via phone, or online, and who reside in or send orders within Upminster and its neighbouring areas. By engaging with our services, you acknowledge the practices described herein.
What Data We Collect
When you interact with Upminster Florist, we may collect the following categories of personal data:
- Identity Data: Full name, recipient's full name, and, where applicable, additional contact details of sender and recipient.
- Contact Data: Delivery address, billing address, telephone number (if provided).
- Order Data: Product and service details, delivery instructions, messages for recipients, date and time of orders.
- Payment Data: Transaction details (note: payment information is processed by third-party processors; we do not store or process complete card details).
- Communication Data: Records of correspondence, feedback, or queries you make to us regarding orders or our services.
- Technical Data (for online orders): IP address, browser type, device type, and cookies (where applicable to enhance browsing experience and security).
Lawful Basis for Processing Your Data
We process your personal information based on lawful bases as defined by the GDPR:
- Contractual Necessity: Most of the data we collect is necessary to fulfil your orders and provide our services to you or your chosen recipient.
- Legitimate Interests: We may use your data for legitimate business interests, such as improving our services, responding to queries, and preventing fraud, provided these interests are not overridden by your rights and interests.
- Legal Obligation: In some cases, we may process or retain data to comply with legal requirements, such as record-keeping for tax or regulatory authorities.
- Consent: Where we rely on consent for certain types of data collection (for example, direct marketing), you have the right to withdraw your consent at any time.
How We Use Your Personal Data
Your data is used to:
- Process and deliver your orders efficiently.
- Communicate with you about orders, delivery, or service queries.
- Ensure the quality and accuracy of deliveries.
- Process payments securely (via our payment processors).
- Respond to your enquiries, feedback, or complaints.
- Comply with legal obligations and applicable laws.
- Where consent is given, update you about our offers, news, or surveys.
Retention of Your Personal Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the satisfaction of any legal, accounting, or reporting requirements. Usually, order records and related communications are kept for a maximum of seven years to comply with legal and tax obligations. Anonymised or aggregated data may be retained for analytical purposes with no risk of identifying individuals. Once your data is no longer necessary, we will securely delete or anonymise it.
Data Processors and Third Parties
To deliver our services effectively, we may engage third-party service providers (data processors) who process data on our behalf and under contractual obligations. These may include:
- Payment Processors: To securely handle transactions (e.g., card payments).
- IT and Hosting Providers: To manage our ordering systems, website, and secure data storage.
- Delivery/Courier Services: For fulfilment of orders and tracking.
- Regulatory Authorities: If required by law for reporting obligations.
Each processor is selected based on their compliance with data protection standards and their contractual agreement to safeguard personal data. We do not sell or rent your data to any third parties.
Your Rights Under GDPR
As a data subject, you have the following rights in relation to your personal data processed by Upminster Florist:
- The right to access: Request a copy of the personal data we hold about you.
- The right to rectification: Correct any inaccuracies or incomplete data.
- The right to erasure: Request deletion of your data where no longer required or if processed unlawfully.
- The right to restrict processing: Put limitations on how your data is used under certain circumstances.
- The right to object: Object to data processing where we rely on legitimate interests or direct marketing.
- The right to portability: Request your data in a structured machine-readable format for your use or to transfer to another service provider.
- The right to withdraw consent: Where you have given consent, you may withdraw it at any time without affecting prior processing based on consent.
- The right to lodge a complaint: Raise concerns with a relevant data protection authority if you believe your rights have been infringed.
Protecting Your Data
We implement appropriate technical and organisational measures to ensure your personal data is secure. This includes restricted access, encrypted storage where applicable, and regular review of our data protection policies. We train our staff on confidentiality and data protection obligations and monitor our systems for potential vulnerabilities.
Policy Updates
We may update this Privacy Policy occasionally to reflect changes in legal requirements or our business practices. The latest version will always apply to your orders with Upminster Florist.
Contact Us
If you have any questions about this privacy policy or wish to exercise your data protection rights, please contact us through the contact methods detailed on our website or in store. We are committed to responding promptly to any privacy concerns or queries you may have.