Florist Bromley Privacy Policy: Our Commitment to Your Data Protection
Introduction
This privacy policy explains how Florist Bromley collects, uses, retains, and protects your personal data in accordance with the requirements of the General Data Protection Regulation (GDPR). It applies to all individuals who place orders with Florist Bromley from Bromley and the surrounding districts. Respecting your privacy and ensuring your data protection is a key priority in all our activities.
What Data We Collect
Florist Bromley collects certain personal data from customers to fulfil orders and provide our services efficiently. The data we collect may include:
- Identity Information: Your name and, if relevant, the recipient's name.
- Contact Details: Delivery address, billing address, and phone number where required for order fulfilment.
- Order Details: Product selections, order amounts, messages for recipients, and delivery preferences.
- Payment Information: Type of payment method and necessary transaction details (such as the last four digits of your card number or payment confirmation number); we do not store complete card numbers or CVV codes.
- Communication Records: Any correspondence made with our team regarding your order or service queries.
This data is collected directly from you when you place an order, contact us for support, or make an enquiry about our services.
Lawful Basis for Data Processing
Florist Bromley processes your personal data based on several lawful grounds under GDPR, including:
- Contractual Necessity: Most of the data we collect is required to perform our contract with you. For example, delivery and contact information is necessary for completing and delivering your order.
- Legal Obligation: We are required to retain information relating to payments and transactions in order to comply with tax and accounting laws.
- Legitimate Interest: We may process your data when it is in our legitimate business interest, such as to improve our services, prevent fraud, or respond to customer queries. We ensure that any processing on this basis does not override your rights or interests.
- Consent: On occasion, where required by law (for example, for certain marketing communications), we will seek your explicit consent before processing your data for that specific purpose.
Purpose of Data Collection and Use
Your personal data is collected and processed for the following purposes:
- To manage and fulfil your orders, including processing payments and arranging deliveries.
- To communicate with you regarding your purchase, delivery status, and customer support queries.
- To maintain business records for accounting and legal compliance.
- To enhance and personalise your customer experience.
- To monitor and improve our products, services, and website security.
- To notify you about updates or changes to our services (where you have agreed).
Data Retention Policy
Florist Bromley will only retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements:
- Order and transaction data may be kept for up to seven years to comply with tax and financial record-keeping laws.
- Customer correspondence is retained for up to two years after your last interaction with us, to enable effective customer service and resolve any queries.
- Where data is on the basis of consent (such as marketing preferences), data will be kept only as long as you provide consent. You can withdraw your consent at any time.
At the end of the retention period, we securely delete or anonymise your personal information so that it can no longer be associated with you.
Processors and Data Sharing
Florist Bromley only shares your personal data with third parties ("processors") when it is strictly necessary to provide our services. These processors include:
- Payment Service Providers: To securely process your payment transactions, we use trusted third-party payment gateways accredited for security and compliance.
- Delivery Partners: Relevant recipient and delivery information is shared with couriers and delivery personnel to successfully deliver your order.
- IT and Cloud Service Providers: Your data may be stored or processed using secure and GDPR-compliant IT infrastructure partners who support our website and customer management systems.
We require all processors to comply with data protection law and take appropriate security measures to safeguard your information. We do not sell your data to third parties for marketing or any other purposes.
Your Rights Under GDPR
As a data subject within the UK and EU, you have several rights regarding your personal data, including:
- Right to Access: You have the right to obtain confirmation as to whether or not we are processing personal data about you, and, where that is the case, access to the personal data.
- Right to Rectification: If your data is inaccurate or incomplete, you have the right to have it corrected.
- Right to Erasure ("Right to be Forgotten"): In certain circumstances, you may request that your personal data be deleted.
- Right to Restrict Processing: You have the right to request the restriction or suppression of your personal data in specific situations.
- Right to Data Portability: You can request that your data be transferred to another organisation or directly to you.
- Right to Object: You can object to the processing of your personal data at any time under certain conditions.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw this at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, or if you have concerns about how your data is handled, please contact us via the details provided on our website. We aim to respond to all requests within one month and will always treat your enquiries confidentially.
Security Measures
Florist Bromley takes your data security seriously. We have put in place appropriate technical and organisational measures to protect your personal data from accidental loss, unauthorised access, alteration, or disclosure. These measures include data minimisation, regular security assessments, encryption where appropriate, and staff training in data protection requirements.
Updates to This Privacy Policy
This privacy policy may be updated from time to time to reflect changes in our data processing practices or legal requirements. When this happens, we will adjust the "Last updated" date at the top of the policy. We encourage you to periodically review this page to stay informed of how we are protecting your personal data.
Contact Information
If you have any questions or requests relating to this privacy policy or the exercise of your data protection rights, please refer to the contact details available on our website. Florist Bromley is committed to resolving any concerns you may have regarding your personal data swiftly and transparently.