Florist Downe Customer Privacy Overview
Introduction
At Florist Downe, we are committed to safeguarding the privacy and personal data of all our customers. This Privacy Policy explains how we collect, use, store, and protect your information in accordance with the General Data Protection Regulation (GDPR). This policy applies to anyone placing orders with Florist Downe in Downe and the surrounding districts.
What Data We Collect
When you place an order or interact with Florist Downe, we may collect the following categories of personal data:
- Identity Data: Your name and title
- Contact Data: Your billing address, delivery address, and contact preferences
- Order Information: Details of the products or services you purchase or enquire about
- Payment Data: Transaction details (note: payment card details may be securely processed by our payment service providers and are not stored by us)
- Correspondence: Details of communications with us, including any feedback or enquiries
We do not intentionally collect special categories of personal data (such as health or biometric data) except where you choose to provide such information for floral arrangements (for example, allergy information included in delivery instructions).
Lawful Basis for Processing Your Data
Florist Downe processes your personal data based on the following lawful grounds as defined under the GDPR:
- Contract: To process your orders, deliver products, manage payments, and provide customer support, we must collect and use your data as part of our contract with you.
- Legitimate Interests: We may process data to improve our products and services, ensure the security of our website and business, and for administrative purposes that do not override your privacy rights.
- Legal Obligations: We may be required to process your data to comply with relevant laws, such as tax, accounting, and record-keeping.
- Consent: Where you provide explicit consent (such as for receiving marketing communications), we will process your data accordingly. You can withdraw your consent at any time.
How We Use Your Information
Your personal data is used for the following purposes:
- Processing and fulfilling your orders
- Communicating order updates and delivery notifications
- Managing payments and refunds
- Responding to enquiries and providing customer service
- Account administration (where applicable)
- Complying with legal and regulatory requirements
- Improving our products, services, and customer experience
- Where permitted, sending you marketing communications (which you can opt-out of at any time)
Data Retention
We retain your personal data only as long as necessary for the purposes it was collected, including to satisfy legal, accounting, and reporting requirements. The retention periods will depend on the nature of the data and our legal obligations. Typically,:
- Order and transaction records: Retained for up to 7 years to comply with accounting and tax rules
- Customer correspondence: Retained for up to 3 years after your last contact with us
- Marketing preferences: Retained until you withdraw your consent or unsubscribe
After the relevant retention period, your data will be securely deleted or anonymised.
Data Processors and Third Parties
In order to fulfil our contract with you and operate our business efficiently, we may share your personal data with trusted third parties, including:
- Payment processing companies: For handling secure payments
- Delivery partners: For fulfilling and delivering your orders
- IT and website service providers: To host and support our website and systems
- Professional advisers: For accounting, legal, or audit requirements
All processors and third parties we engage are required to adhere to strict data protection standards and act only on our instructions. Your data is not sold or shared for third-party marketing purposes.
Data Security
Florist Downe implements appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, disclosure, or alteration. These include secure systems, restricted access, and data encryption where appropriate.
Your Rights Under the GDPR
You have a number of rights regarding your personal data under the GDPR, including:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct any inaccurate or incomplete data.
- Right to Erasure: You can request that your personal data be erased where there is no lawful basis for its continued processing.
- Right to Restriction of Processing: You can ask us to restrict how we use your data in certain circumstances.
- Right to Data Portability: Where applicable, you may request a copy of your data in a commonly used format for transfer to another provider.
- Right to Object: You can object to the processing of your data on grounds relating to your specific situation or object to direct marketing at any time.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
Should you wish to exercise any of these rights, please contact us using the information provided on our website or ordering forms. We may need to verify your identity before fulfilling your request.
Applicability of This Policy
This privacy policy covers all interactions with Florist Downe, including orders placed online, by phone, or in-person, by customers in Downe and the surrounding districts. By using our services, you are acknowledging and agreeing to the terms described in this policy.
Changes to Our Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices or legal requirements. The current version will always be available at the point of sale and on our official website.
Contact and Complaints
If you have any questions or concerns regarding your personal data or this policy, you are encouraged to contact us through the channels provided on our website. If you remain dissatisfied, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).