Privacy Policy for Florist Blackwall Orders
Introduction
This Privacy Policy details how Florist Blackwall (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you place orders from Blackwall and the surrounding districts. We are dedicated to ensuring that your privacy is protected and that your data is handled in full compliance with the UK General Data Protection Regulation (GDPR). This policy is intended for all customers purchasing floral arrangements and related products from Florist Blackwall.
What Data We Collect
We collect the following categories of personal data from customers when orders are placed or enquiries are made:
- Contact Information: Your name, delivery address, billing address (if different), and contact details, such as telephone numbers (mobile and/or landline).
- Order Details: Product selections, delivery instructions, recipient’s information, occasion details (such as birthdays or anniversaries for custom arrangements).
- Payment Information: Card details or payment transaction identifiers (note: card details are not stored by us but processed securely by payment processors).
- Communication Records: Correspondence via messages, contact forms, or phone calls regarding your order or our services.
- Technical Data: Limited device, browser, IP, and visit data, for website functionality and analytics purposes.
Lawful Basis for Processing
We process your personal data only where there is a lawful basis under the GDPR. These include:
- Contractual Necessity: To process and fulfil your order and to provide customer service related to your purchase.
- Legitimate Interest: To manage and improve our business operations, including fraud detection, quality control, and direct marketing (where appropriate, and always with an opt-out option).
- Legal Obligation: To comply with applicable UK laws, tax regulations, and record-keeping requirements.
- Consent: In limited cases where you explicitly agree, such as to receive promotional communications beyond essential service notifications.
Retention of Your Data
Your personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The retention periods are as follows:
- Order and Transaction Records: Retained for up to 6 years in line with financial regulations and for handling complaints or disputes.
- Marketing Data: Retained until you withdraw consent or object to processing.
- Technical Data: Retained for a maximum of 24 months to improve website security and customer experience.
Upon expiry of these periods, your data is securely deleted or anonymised.
Third Party Processors
To deliver our services efficiently and securely, we may share your data with carefully selected third party service providers (processors), who act on our written instructions and are required to comply with strict data protection measures. These include:
- Payment Service Providers: To securely process your payments; card details are never stored on our systems.
- Delivery Partners: To ensure the successful delivery of your order to the correct recipient.
- IT and Website Support Providers: For website hosting, maintenance, and data security.
- Communication Tools: For managing communications, order confirmations, or customer feedback requests.
All processors are vetted for GDPR compliance and may only use your personal data for the purpose specified by us.
User Rights Under GDPR
You have several rights concerning your personal data under the GDPR. These rights include:
- Right to Access: You may request details of the personal information we hold about you.
- Right to Rectification: You have the right to have inaccurate or incomplete information corrected.
- Right to Erasure: You can request the deletion of your personal data under certain circumstances, for example, when data is no longer necessary for the purposes it was collected.
- Right to Restrict Processing: You may ask us to restrict or suppress your data processing under certain conditions.
- Right to Data Portability: You have the right to receive the personal data you provided to us in a commonly used, machine-readable format.
- Right to Object: You can object to the processing of your data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where consent is relied upon for processing, you may withdraw it at any time without affecting the lawfulness of processing carried out prior to withdrawal.
To exercise these rights, please contact us with proof of your identity so we can verify and process your request.
Data Security
We implement robust measures—both technical and organisational—to protect your data from accidental loss, misuse, active threat, or unauthorised access. These include access controls, training, encryption during data transit, and secure destruction once data is no longer required.
Policy Updates
We may update this Privacy Policy from time to time in response to legal, technical, or business changes. Any changes will be reflected in the most recent version, indicated by the revised date at the end of the policy. We encourage you to check this policy occasionally to ensure you remain informed about how we handle your data.
Jurisdiction and Scope
This policy applies to all customers who place orders with Florist Blackwall from Blackwall and the neighbouring areas. All data processing activities are governed by the relevant UK data protection laws and GDPR requirements.
Contacting Us
If you have questions regarding this Privacy Policy or wish to exercise any of your data rights, you may contact us through our website’s contact form or via written correspondence addressed to Florist Blackwall. We aim to respond to all requests promptly and in accordance with the legal requirements.
Last updated: June 2024