Privacy Policy - Florist Yiewsley
Introduction
This Privacy Policy describes how Florist Yiewsley collects, uses, and protects the personal data of customers placing orders in Yiewsley and the surrounding districts. We are committed to ensuring compliance with the UK General Data Protection Regulation (GDPR) and safeguarding your personal information.
Scope of this Privacy Policy
This policy applies to all customers who place orders with Florist Yiewsley, whether via our website, telephone, or in person, and is relevant for residents and recipients located in Yiewsley and its neighbouring districts.
Personal Data We Collect
We collect the following types of personal data as necessary to process orders, provide services, and meet our legal obligations:
- Identity Data: Name (of sender and recipient)
- Contact Data: Address, postcode, phone number (optional), delivery instructions
- Order Data: Product selections, delivery preferences, order notes, and purchase history
- Payment Data: Limited payment details processed via our payment processors (we do not store full card details ourselves)
- Technical Data: IP address, browser type, and access times if you interact via our website
We do not intentionally collect special category data (such as health or religious information).
Lawful Basis for Processing Your Personal Data
Under GDPR, we must have a lawful basis for processing your personal information. Florist Yiewsley processes data based on the following grounds:
- Contractual Necessity: To process and deliver your floristry orders as requested
- Legal Obligation: To comply with legal and regulatory requirements (such as record-keeping and tax)
- Legitimate Interests: To improve our services, manage queries or complaints, and for limited direct marketing of similar services (unless you opt out)
- Consent: Where required, we seek your consent, e.g., for certain types of marketing communication
How We Use Your Data
Your information is used only for purposes directly related to your order and experience with Florist Yiewsley. These include:
- Taking and fulfilling floral orders
- Communicating order confirmations and status updates
- Handling customer service queries or complaints
- Improving our services and website experience
- Complying with legal, accounting, or taxation obligations
Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected. Our general retention periods are:
- Order records: Retained for up to seven years to meet tax and legal requirements
- Marketing consent: Retained until you withdraw consent or unsubscribe
- General enquiries: Data from non-order enquiries is usually deleted within two years
After the expiration of these periods, your data will be securely deleted or anonymized.
Third-Party Processors
We may disclose personal data to third-party processors to help deliver our services. Such processors include:
- Certain payment processing providers (for handling payments securely)
- Delivery partners or couriers (for delivering your order to the recipient)
- IT service providers (such as website hosting platforms or email providers)
We ensure that all third-party processors operate in compliance with GDPR and have agreements in place that require your data is protected to the same standard as if we processed it ourselves. We do not sell customer data to third parties.
Data Security
We implement appropriate security measures to protect personal data against accidental loss, unauthorised access, disclosure, alteration, or destruction. These measures include restricted access, secure storage, and regular review of our policies and procedures.
Your GDPR Rights
As a data subject under the GDPR, you may exercise the following rights with respect to your personal data:
- Right of Access: Request a copy of the information we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data under certain circumstances.
- Right to Restrict Processing: Request restricted use of your data in specific situations.
- Right to Data Portability: Request transfer of your data to another provider.
- Right to Object: Object to use of your data for direct marketing or where processing is based on our legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw this at any time.
If you wish to exercise any of your data rights or have concerns about our use of your data, please contact us in writing. We will respond within one month as required by GDPR.
International Data Transfers
Florist Yiewsley stores and processes your personal data within the United Kingdom or the European Economic Area (EEA) wherever possible. Where data is processed outside these locations, we ensure that adequate safeguards are in place in line with GDPR requirements.
Policy Updates
This Privacy Policy may be updated from time to time to reflect changes in our practices or changes in data protection law. We encourage you to review it periodically. The most recent version will always be available to you prior to placing an order.
Contacting Us
If you have any queries about this Privacy Policy, your personal data rights, or how we process your data, please contact us in writing. We are committed to resolving any concerns you may have regarding your privacy and personal information.
