Worcester Park Florist Privacy Policy

Introduction

This Privacy Policy explains how Worcester Park Florist (“we”, “our”, “us”) collects, uses, discloses, and safeguards your personal data when you place an order with us from Worcester Park or surrounding districts. We are dedicated to processing your personal information in accordance with the UK General Data Protection Regulation (GDPR) and other applicable laws. This policy applies to all customers placing Worcester Park Florist orders, whether online, by phone, or in-store, from these areas.

What Data We Collect

We collect personal data provided directly by you to fulfill your orders and provide our services. The types of personal data we may collect include:

  • Identity Data: Your first name, last name, and title.
  • Contact Data: Addresses, phone numbers, and, when necessary, an email address.
  • Recipient Data: Name, delivery address, and contact number for the recipient of any order you place.
  • Order Data: Details of your purchase, messages to be attached to your flowers, and payment status (we do not store card details).
  • Technical Data: IP address, browser type, and similar technical data when you order online.

We do not knowingly collect special categories of data (such as health, ethnicity, or religious beliefs) except where you voluntarily provide allergy or accessibility information for deliveries.

Lawful Basis for Collecting and Using Data

Under GDPR, we must have a lawful basis to process your personal data. The bases we rely upon are:

  • Contract: Processing is necessary to fulfil your order, process payment, deliver flowers, and communicate with you about your purchase.
  • Legal Obligation: Where necessary to comply with applicable laws, tax, and accounting regulations.
  • Legitimate Interests: To improve our services, respond to customer queries, and maintain records for business management purposes, provided those interests are not overridden by your rights and interests.
  • Consent: If required (for example, for direct marketing via email), we will request your explicit consent. You can withdraw your consent at any time.

How We Use Your Data

We use your data for various purposes, including:

  • Processing and fulfilling orders, including communicating with you and the order recipient as necessary.
  • Delivering flowers and related goods.
  • Personalising card messages and ensuring delivery accuracy.
  • Managing payments and refunds (note: payment information such as card details is managed securely by our payment processor and never stored by us).
  • Handling customer enquiries, feedback, and complaints.
  • Improving our services and understanding customer needs.
  • Complying with applicable legal and regulatory obligations.

Who Processes Your Data (Third-Party Processors)

Your personal data may be shared with trusted third-party processors for the purposes explained above. These may include:

  • Payment Service Providers: To securely process transactions.
  • Delivery Partners (Couriers): For delivering your flowers or related goods to the correct address.
  • IT and Hosting Providers: For the secure operation of our website, order management, and secure communication between our team and customers.
  • Professional Advisors: Such as accountants, where required for audit and tax purposes.

We require all third-party processors to respect the security of your personal data and to treat it in accordance with the law. We do not allow third parties to use your data for their own purposes and only permit them to process your data for specified purposes and in accordance with our instructions.

Data Retention Periods

We retain your personal data only for as long as necessary to fulfill the purposes for which we collected it, including for the purposes of satisfying any legal, accounting, or reporting requirements.

  • Order and Delivery Data: Kept for six years from the date of transaction; this aligns with accounting and legal record-keeping obligations.
  • Marketing Data: If you have consented to marketing, we will retain your contact data until you withdraw your consent or after three years of inactivity.
  • Website Technical Data: Retained for no more than twelve months.

After these periods, your personal data will be securely deleted or anonymised.

Your Rights as a Data Subject

Under data protection laws, you have important rights regarding your personal data. These include:

  • The right to access your personal data and ask for a copy.
  • The right to rectification if your data is incomplete or inaccurate.
  • The right to erasure (“the right to be forgotten”), in certain circumstances.
  • The right to restrict processing of your data in certain cases.
  • The right to data portability where applicable.
  • The right to object to processing where our legal basis is legitimate interests or direct marketing.
  • The right to withdraw consent at any time where processing is based on consent.

If you wish to exercise any of these rights, please contact us using our usual communication channels.

How We Keep Your Data Secure

We are committed to ensuring your information is secure. We implement technical and organisational measures to safeguard your data, such as password-protected systems, secure servers, and staff training in data protection. Only authorised employees or third-party processors with a legitimate need to access your data will do so, and all processing is monitored for compliance with GDPR.

Policy Scope and Updates

This Privacy Policy applies to all Worcester Park Florist customers placing orders from Worcester Park and its surrounding districts, for services provided via our shop, phone, and website. We reserve the right to update this policy. Any changes will be posted on our website and made available in-store, with the date of last update indicated at the end of the policy.

Contact and Complaints

If you have concerns regarding your data, or are not satisfied with our response, you may contact the relevant supervisory authority for data protection in the UK. For any data protection queries or to exercise your rights, please get in touch using our standard communication channels or by visiting us in person.

Last updated: June 2024