Canning Town Florist Privacy Policy
Introduction
This Privacy Policy describes how Canning Town Florist ('we', 'us', 'our') collects, uses, stores, and safeguards your personal data in compliance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers who place orders with Canning Town Florist from Canning Town and the surrounding districts.
What Data We Collect
We collect various categories of personal data directly from you during the process of placing an order, creating an account, or making an enquiry. Depending on your interaction with us, we may collect the following information:
- Identity Data: Name, title, and sometimes a company name when relevant to the order.
- Contact Data: Billing address, delivery address, phone number, and postal code.
- Order Information: Details about the requested floral products, card messages, and recipient information (if the order is a gift).
- Payment Data: Payment method, partial payment card information (never full), transaction identifiers, and billing details. We do not store your complete payment card information; secure payment processors handle this data directly.
- Technical Data: IP address, browser type and version, device information, and cookies (if you use our website), which help us improve the ordering experience.
- Communication Data: Records of communication, including messages and any preferences expressed regarding marketing or contact methods.
Lawful Basis for Processing Your Data
Under the GDPR, we must have a lawful basis for processing your personal data. We process your information under the following grounds:
- Contractual Necessity: Most data we collect is necessary for fulfilling your order, including delivery and payment processing. Without this information, we would be unable to provide our floral services.
- Legal Obligation: We may need to process information for compliance with legal and regulatory requirements, such as tax and accounting laws.
- Legitimate Interests: We may process data to improve our services, enhance security, or protect against fraud, where such interests are not overridden by your rights and interests.
- Consent: Where you agree to receive marketing communications, we rely on your explicit consent, which can be withdrawn at any time.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying legal, accounting, or reporting requirements. Typical retention periods are as follows:
- Order-Related Data: Retained for up to 7 years in line with tax and accounting obligations.
- Marketing Preferences: Consent records and contact preferences are kept until you withdraw your consent or unsubscribe.
- Website Data: Technical information and cookies are retained for up to 2 years, depending on their nature and purpose.
When your data is no longer required, we securely delete or anonymise it.
Processors and Third Parties
We may share your personal data with trusted third parties known as 'processors' who perform services on our behalf. These include:
- Payment Service Providers: For processing payments securely and efficiently.
- IT and Web Hosting Providers: Suppliers who host our website, manage databases, and provide email services.
- Delivery Partners: Couriers or delivery agents for order fulfilment.
- Professional Advisors: Accountants, legal advisors, and auditors who may require limited access as part of their professional services.
All processors are contractually bound to protect the security and confidentiality of your information and must not use it for their own purposes. We do not share your data with third parties for any other reason without your prior consent, except where required by law.
Your Rights
Under the GDPR and UK data protection law, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You may request corrections to any incomplete or inaccurate data.
- Right to Erasure: In certain cases, you may ask us to delete your personal data where there is no legal reason for us to keep it.
- Right to Restrict Processing: You can request that we limit how we use your data in specific circumstances.
- Right to Data Portability: Have your data provided to you, or a third party, in a structured, commonly used format.
- Right to Object: You have the right to object to certain processing, such as direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw this at any time.
- Right to Lodge a Complaint: You have the right to complain with the Information Commissioner’s Office if you believe we have not handled your data properly.
To exercise any of these rights, please contact us using the methods provided on our website or in-store. We may need to verify your identity before fulfilling your request to protect your privacy.
Security of Your Data
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, or disclosure. These measures include data encryption, restricted access controls, and regular staff training.
International Data Transfers
We do not routinely transfer your personal data outside the UK/European Economic Area. If such transfers are ever necessary, we will ensure that adequate safeguards are in place to protect your data, in accordance with legal requirements.
Policy Updates
We may update this Privacy Policy from time to time. Any changes will be posted on our website and will take effect immediately upon posting. We encourage customers to review this policy periodically to stay informed of how we are protecting your data.
Contacting Us
If you have questions about this policy or wish to exercise your rights, please visit our website or speak to our team in-store. We take your privacy seriously and are committed to addressing any concerns you might have.