Holland Park Florist GDPR Privacy Policy
Privacy Policy for Holland Park Florist Customers
This Privacy Policy explains how Holland Park Florist ('we', 'us', or 'our') collects, uses, and safeguards your personal information when you place an order with us. The policy applies to all customers placing orders from Holland Park and its surrounding districts. We are committed to ensuring your privacy and complying with applicable data protection laws, including the UK General Data Protection Regulation (GDPR).
What Data We Collect
We collect information necessary to process and fulfil your order, maintain our business operations, and improve our services. The categories of data we typically collect include:
- Identity Data: Your name, title, and contact details.
- Contact Data: Delivery address, billing address, postcode, telephone number, and email address.
- Order Information: Details of the products you purchase, order notes (such as card messages or delivery instructions), and transaction identifiers.
- Payment Data: Limited payment details required to process your order, though full payment card information is not stored by us but is processed securely by our third-party payment processor.
- Communications: Records of communications you have with us (for example, regarding your order or queries about our service).
- Technical Data: IP address, browser type, and access times when you use our digital platforms, for analytics and security purposes.
Lawful Basis for Data Processing
We collect and use your personal data under one or more of the lawful bases set out in GDPR, specifically:
- Contractual Necessity: Processing your data is required to fulfil your order and provide you with our products and services.
- Legal Obligation: We are required by law to retain certain transaction details for taxation and record-keeping purposes.
- Legitimate Interests: For the efficient running of our business, customer service, service improvement, and the prevention of fraud or misuse of our services.
- Consent: Where applicable, such as for direct marketing communications, we may ask for your explicit consent, which you may withdraw at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing and delivering your order, including communicating with you about your order status and delivery arrangements.
- Managing payments and refunds.
- Responding to your enquiries and providing customer support.
- Complying with our legal and regulatory obligations.
- Improving our products, services, and overall customer experience.
- Analyzing usage of our service for business analysis and operational purposes.
Retention of Your Information
Your personal data will be stored only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Typically, we retain:
- Order and transaction details for up to seven years to comply with statutory accounting and tax obligations.
- Customer communications for up to two years after your last interaction with us, unless we are required to retain it for longer due to legal reasons or ongoing disputes.
- Data used for marketing purposes until you withdraw your consent or opt out.
After the relevant retention period, your personal data will be securely deleted or anonymised.
Data Processors and Sharing Information
To offer our products and services, we may share your data with trusted third-party service providers ('processors') who assist with payment processing, order delivery, IT support, website hosting, and customer communications. All processors are contractually bound to safeguard your data and may not use it for their own purposes. Processors may include:
- Payment gateway providers for secure processing of card and digital wallet payments.
- Delivery and courier companies to fulfil delivery of your floral orders.
- IT and software providers who maintain our systems and infrastructure.
- Professional advisors, if required.
- Regulatory authorities or law enforcement, where required by law.
We do not sell or trade your personal data. Your information is not transferred outside the United Kingdom or European Economic Area unless adequate safeguards are in place.
Your Rights Under GDPR
Under the GDPR, you have the following rights in relation to your personal data:
- Right to Access: You may request access to, or copies of, your personal data.
- Right to Rectification: You may have incorrect or incomplete data corrected.
- Right to Erasure: In certain cases, you may request deletion of your personal data ('right to be forgotten').
- Right to Restrict Processing: You may restrict processing of your data in specific circumstances.
- Right to Data Portability: You may request to receive your data in a structured, commonly used, machine-readable format.
- Right to Object: You may object to certain types of processing, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw this at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data has been handled improperly.
To exercise any of these rights, please contact us using the details provided on our website or in your order confirmation documents. We will respond to your request in accordance with GDPR timeframes and requirements.
Policy Updates
We reserve the right to update this Privacy Policy from time to time. Any significant changes will be notified to you by appropriate means. The date of the latest update will always be indicated at the end of this document. We encourage you to review this policy periodically.
Contacting Us
If you have any questions, concerns, or requests regarding your personal data or this Privacy Policy, please contact us through the communication channels listed on our website. We are committed to protecting your privacy and addressing all concerns promptly.
Last updated: June 2024