GDPR-Compliant Privacy Policy for New Eltham Florist
Introduction
At New Eltham Florist, we are dedicated to protecting the privacy and personal information of our customers. This privacy policy explains how we collect, use, store, and process your data in compliance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with New Eltham Florist, whether living in New Eltham or the surrounding districts. Please review this policy to understand your rights and how we respect your privacy.
What Personal Data We Collect
When you engage with New Eltham Florist, we may collect the following types of personal data:
- Identity Data: This includes your name and, if ordering on behalf of someone else, the recipient's name.
- Contact Data: Postal address, billing address, delivery address, and telephone number(s).
- Order Details: Information about flower arrangements or products ordered, delivery instructions, and any gift messages attached to orders.
- Payment Information: Limited payment details required to process your transaction. (Full payment card data is handled securely by our payment processor and is not stored by us.)
- Order History: Records of previous orders placed with us.
- Correspondence: Any communication between you and New Eltham Florist, such as queries or feedback made in person, by phone, or using our website forms.
- Technical Data: For those visiting our website, we may collect information such as browser type, device, IP address, and usage statistics via cookies for analytics purposes.
Lawful Basis for Processing Personal Data
Under the GDPR, we must have a legitimate legal basis to process your personal information. We rely on the following grounds:
- Contractual Necessity: Processing is necessary to fulfill your order or respond to requests related to our products and services.
- Legal Obligation: We are required by law to retain and use certain data for tax and accounting purposes.
- Legitimate Interests: For operational reasons, such as improving our service, communicating with you about your order, and record-keeping.
- Consent: For marketing communications, we will only send you promotional material if you have explicitly opted-in. You may withdraw consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing and fulfilling your flower orders, including delivery to the provided address.
- Managing payments and verifying transactions.
- Communicating with you regarding your order status, issues, or feedback.
- Providing customer support and resolving any disputes.
- Complying with legal obligations.
- Conducting analytics to enhance our services and website performance.
- Sending promotional materials, if you have consented to receive them.
Retention of Personal Data
We retain personal data only for as long as necessary to fulfill the purposes it was collected for, including any legal, accounting, or reporting requirements. Our general retention periods are as follows:
- Order details, contact data, and transaction records are retained for up to seven years to satisfy legal obligations.
- Marketing data (where consent is given) will be held until you withdraw your consent or opt out.
- Technical website data is typically retained for up to two years for analysis and performance purposes.
After these periods, your personal data will be securely erased or anonymised so that you can no longer be identified from it.
Sharing Your Personal Data and Use of Processors
We will never sell your personal data to third parties. However, we may share your data with carefully selected third-party service providers (processors) who assist us in delivering our services. These include:
- Payment processors: To securely process your payment information when you place an order.
- Delivery partners: For logistical support in delivering your flowers or gifts.
- IT and cloud service providers: Who provide data hosting, website, and email infrastructure.
- Professional advisers: Such as accountants or legal consultants, where required by law.
All our processors must adhere to data protection standards at least as stringent as our own, as detailed in written contracts. They are only permitted to use your data for purposes specified by us and must delete your data after fulfilling their obligations.
Your Rights under the GDPR
As a data subject under the GDPR, you have several rights regarding your personal data. These include:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Ask us to correct or update inaccurate or incomplete information.
- Right to Erasure: Request the deletion of your personal data where it is no longer necessary or you withdraw consent (this is subject to any legal retention requirements).
- Right to Restrict Processing: Ask for processing of your data to be restricted under certain circumstances.
- Right to Data Portability: Request a copy of your data in a portable format to reuse with other service providers.
- Right to Object: Object to certain processing activities, such as direct marketing.
- Right to Withdraw Consent: If we process your data based on consent, you can withdraw it at any time.
To exercise any of these rights, you may contact us by any of the means described in our contact section in store or on our website. We will respond to all requests in accordance with the GDPR and within legally mandated timeframes.
Data Security
We take the security of your personal data seriously and implement appropriate organisational and technical measures to protect against unauthorised access, accidental loss, alteration, or disclosure. These measures include encryption, regular staff training, and strict internal security protocols.
Updates and Changes to This Policy
We may occasionally update this privacy policy to reflect changes in our practices or legal requirements. The latest version will always be available in store and on our website. We encourage customers to review the policy regularly for any updates.
Contact and Complaints
If you have any concerns about how your personal data is handled by New Eltham Florist, or if you would like to exercise your GDPR rights, please get in touch with us using the details found in our shop or on our website. You are also entitled to contact the Information Commissioner's Office (ICO) if you are dissatisfied with our response to your request or with our data practices.