Florist Holland Park Privacy Policy
Introduction
This Privacy Policy explains how Florist Holland Park (‘we’, ‘us’, ‘our’) collects, uses, and safeguards your personal data when you place orders for our products or services as a customer in Holland Park and surrounding districts. We are committed to protecting your rights, transparency, and compliance with data protection legislation, specifically the General Data Protection Regulation (GDPR).
Scope of this Policy
This Privacy Policy applies to all individuals placing orders with Florist Holland Park, whether directly or through our website, phone ordering service, or in-person, when ordering for delivery or collection in Holland Park and the surrounding districts. By using our services, you acknowledge the collection and processing of your personal data in accordance with this policy.
What Data We Collect
When you place an order or interact with Florist Holland Park, we may collect the following categories of personal data:
- Contact Information: Name, address, delivery address, phone number, and (where applicable) any correspondence preferences.
- Order Information: Details about your order (type of products purchased, recipient’s name and address, order notes, delivery instructions), and transaction details, such as purchase amount, frequency of order, and payment method (note: payment data is processed securely via third party payment processors and is not retained by us directly).
- Account Information: If you create a customer account, we may retain your username and password (securely encrypted).
- Communications: Records of correspondence with us, including queries, feedback, or complaints.
- Technical Data: Information about how you interact with our website (such as IP address, browser type, pages visited), collected through cookies and similar technologies (refer to our separate Cookie Policy for further details).
Our Lawful Basis for Processing Your Data
Under GDPR, we must have a lawful basis to collect and use your personal data. Depending on the nature of your interaction with us, we rely on the following bases:
- Performance of a Contract: When you place an order, we process your data to fulfill our contract with you (e.g., processing and delivering your order, communicating order status).
- Legal Obligation: We may be required to retain certain information to comply with applicable laws (such as tax or accounting requirements).
- Legitimate Interests: We may process your data for legitimate business purposes, such as improving our service, handling customer queries, protecting our business from fraud or misuse, and ensuring IT security – provided this does not unduly impact your rights.
- Consent: In limited cases, such as marketing emails or promotions, we will seek your explicit consent before using your data, and you may withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- To process, fulfill, and deliver your flower order, including communications regarding delivery status, delays, or issues;
- To contact you in connection with your order or in response to your queries or feedback;
- To maintain accurate records in compliance with legal requirements (such as proof of purchase, receipts);
- To improve our services, website performance, and customer experience;
- If you have provided consent, to send you marketing communications, special offers, or seasonal messages.
How Long We Retain Your Data
We store personal data only as long as necessary to fulfill the purposes we collected it for, including for compliance with legal, accounting, and reporting obligations. Data retention periods are as follows:
- Orders: Order and contact information is retained for up to 7 years for accounting and legal purposes.
- Accounts: If you have an online account, account-related data is retained until you request closure of the account, after which it is deleted within 30 days unless retention is required for legal reasons.
- Marketing Data: If you receive marketing emails and subsequently unsubscribe, we keep a minimal record of your request to exclude you from future campaigns.
- Technical/Cookie Data: As set out in our Cookie Policy, retention varies by cookie type and purpose.
Our Data Processors
We use selected third-party service providers (‘processors’) to support the operation of our business and delivery of services. These may include:
- Payment processors for secure handling of payment transactions;
- IT and cloud service providers for secure data storage and website operations;
- Delivery partners for logistics and tracking deliveries;
- Email and customer communication service providers;
- Accountants and auditors for compliance purposes.
All service providers are required to process your information in strict accordance with our instructions and GDPR requirements. We ensure that appropriate data protection agreements are in place and select processors who can evidence adequate security measures.
Your Rights as a Data Subject
You have a number of important rights under GDPR relating to your personal data. These include:
- Right to Access: You can request a copy of your personal data that we hold.
- Right to Rectification: If any data we hold about you is inaccurate or incomplete, you have the right to have it corrected.
- Right to Erasure (‘Right to Be Forgotten’): You can, in some instances, ask us to delete the information we hold about you. Please note, some data may need to be retained for legal compliance.
- Right to Restrict Processing: You can request restrictions on the processing of your personal data.
- Right to Data Portability: You may request a copy of your data in a commonly used machine-readable format.
- Right to Object: You can object to our use of your data for direct marketing or certain other purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw this at any time.
If you wish to exercise any of these rights, please contact us using the contact methods provided on our website or at our business premises.
Data Security
We are committed to ensuring the security of your personal data. We implement a range of physical, technical, and organizational security measures to protect your data against loss, misuse, unauthorized access, alteration, or disclosure. All payment information is processed through secure gateways and not stored by Florist Holland Park directly.
Changes to This Privacy Policy
We may revise this Privacy Policy from time to time to reflect changes in the law, our data practices, or our services. The most up-to-date version will always be available on our website. Where appropriate, we will notify customers of significant changes.
Contact Us
If you have any questions about this policy, how we process your personal data, or wish to exercise your data rights, please get in touch with us through the contact details available on our website or by visiting our premises in Holland Park.