Privacy Policy for Gidea Park Florist
Introduction
This Privacy Policy governs the collection and processing of personal data by Gidea Park Florist for all customers placing orders from Gidea Park and surrounding districts. Protecting your privacy and personal data is a top priority, and we adhere strictly to the requirements of the General Data Protection Regulation (GDPR). This policy outlines the types of data we collect, the lawful basis for processing, how long we retain your data, the use of data processors, and your rights as a data subject.
Scope of this Policy
This Privacy Policy applies to all individuals who place orders with Gidea Park Florist, whether through our website, over the phone, or in person, for deliveries within Gidea Park and its neighboring areas. It covers data collected during the order process, subsequent communications, and customer interactions related to our services.
What Data We Collect
We collect personal data necessary to process and fulfill your floral order. The categories of data we may collect include:
- Full name
- Contact information (such as phone number and delivery address)
- Email address (if provided)
- Billing and payment information (such as card details, if payment is made by card)
- Order details (such as flower selection, messages, and special instructions)
- Recipient information (such as name, delivery address, and phone number, when ordering for others)
- Communication history (records of correspondence related to your order)
- Technical data (such as IP address and browser type, if ordering via our website)
Lawful Basis for Processing
Under GDPR, we must have a lawful basis for each type of personal data we process. The data collected by Gidea Park Florist is processed on the following bases:
- Contractual necessity: Most personal data is collected and processed because it is necessary for the performance of a contract to which you are party—such as fulfilling your floral order and delivering products as specified.
- Legal obligation: Certain records (such as invoices and payment details) may be retained to fulfill our legal obligations relating to accounting or taxation.
- Legitimate interests: We may process some data for business purposes, such as communicating with you about your order, improving our services, or managing and administering our business, provided our interests are not overridden by your rights.
- Consent: Where explicit consent is required—such as for marketing communications—we will seek your prior permission, and you are free to withdraw this consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- To process and deliver your order efficiently and accurately
- To communicate with you about your order, including confirmations, updates, and queries
- For invoicing and payment processing
- To address customer service issues or complaints
- If consented, to send marketing communications or updates regarding our services
- To comply with applicable legal obligations
- For internal record-keeping, business administration, and analysis
Data Retention
Personal data is retained for only as long as is necessary to fulfill the purposes outlined in this Privacy Policy. The retention periods are as follows:
- Order and recipient information: Kept for up to 6 years to meet accounting, tax, and record-keeping requirements.
- Payment data: Retained securely and only as needed for processing payment and complying with financial regulations. Card details are not stored after the transaction is completed.
- Marketing communications: Retained until you withdraw consent or opt out.
- Technical data: Retained for up to 1 year for security and statistical purposes.
After the appropriate retention period, securely delete or anonymize all personal data.
Data Processors and Sharing
We may share your personal data with third parties engaged as data processors, but only to the extent necessary for providing our services. Such processors may include:
- Payment processing providers, for the purpose of managing card or electronic payments
- Delivery service partners, for fulfilling and delivering orders
- IT service providers, for website hosting, database management, and communications
All processors acting on our behalf are contractually obligated to handle your information securely and in accordance with data protection laws. We do not share your personal data with any third parties for unrelated purposes.
International Transfers
Your data is processed within the United Kingdom and European Union. Should it become necessary to transfer your personal data outside these jurisdictions, we ensure measures are in place to protect your rights and compliance with GDPR requirements.
Your Rights as a Data Subject
Under GDPR, you have the following rights regarding your personal data:
- Right to access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct or update inaccurate or incomplete personal data.
- Right to erasure: You may ask us to delete your personal data, subject to applicable legal or contractual retention obligations.
- Right to restrict processing: You may request that we restrict the processing of your personal data in certain circumstances.
- Right to data portability: Where applicable, you may request a copy of your data in a standard, machine-readable format.
- Right to object: You may object to the processing of your data in certain circumstances, especially where processing is based on legitimate interests or for direct marketing.
- Right to withdraw consent: Where we process data based on your consent, you have the right to withdraw that consent at any time.
- Right to lodge a complaint: If you believe your data is not being handled in accordance with this policy or the law, you may lodge a complaint with the relevant supervisory authority.
Data Security
We implement appropriate technical and organisational measures to safeguard your personal data against unauthorized access, accidental loss, destruction, or disclosure. Only authorized personnel and approved data processors have access to your information.
Changes to this Policy
We may amend this Privacy Policy from time to time to reflect changes to our data processing practices or legal requirements. Updates will be made available through our official communications and in-store notices where appropriate. The date of the latest revision will always be indicated at the start of the policy.
How to Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please reach out using the contact details provided in your order confirmation or on our official order forms.