Privacy Policy – Your Personal Data at Kingston upon Thames Florist
Introduction
This Privacy Policy explains how Kingston upon Thames Florist (‘we’, ‘us’, ‘our’) collects, uses, stores, and protects your personal data. This policy is aligned with the General Data Protection Regulation (GDPR) and applies to all individuals who place orders with Kingston upon Thames Florist within Kingston upon Thames and its surrounding districts.
We are dedicated to safeguarding your privacy and ensuring transparency regarding your personal data. Please review this policy carefully to understand your rights and how we process your information.
What Personal Data We Collect
We collect a range of personal data depending on your interaction with us. This includes:
- Identity Data: Name, title, and, if supplied, occasion details (e.g., birthday or anniversary).
- Contact Data: Delivery address, billing address, phone number, and order recipient details.
- Transaction Data: Details about products you have ordered, date and time of order, and purchase history.
- Payment Data: Payment method and transaction details. (Payment card information is processed securely by our payment providers; we do not store full card details.)
- Technical Data: IP address, browser type, and device information (collected via cookies for website security and improvement purposes).
- Correspondence Data: Records of your communications with us, including queries, feedback, or complaints.
Lawful Basis for Processing Your Data
In accordance with GDPR, we process your personal data under the following lawful bases:
- Contractual Necessity: Processing your order and delivering your products require the collection and use of your personal data.
- Legal Obligation: Retaining information for accounting, tax, and regulatory purposes as mandated by law.
- Legitimate Interests: For business management, responding to your queries, and improving our services, provided such interests do not override your rights and interests.
- Consent: In limited circumstances, such as for marketing communications, we will request your explicit consent. You have the right to withdraw consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing your flower order and delivering it accurately and efficiently.
- Managing payments and preventing fraudulent transactions.
- Communicating order updates, confirmations, and responding to your enquiries.
- Complying with legal requirements.
- Analysing usage data to improve our website and services.
Data Retention
We will retain your personal data only as long as necessary to fulfil the purposes for which it was collected, including any legal, accounting, or reporting requirements.
- Order and Transaction Data: Retained for up to 7 years to comply with UK tax and business record-keeping obligations.
- General Correspondence: Retained up to 2 years after resolution, unless required longer for legal purposes.
- Marketing Preferences: Until you opt out or request deletion.
Your data will be securely deleted or anonymised once it is no longer needed for these purposes.
Data Processors and Sharing of Information
Your data is only shared with trusted third-party service providers (‘processors’) necessary to deliver our services and comply with legal obligations. Typical processors include:
- Payment processing providers to facilitate secure transactions.
- Delivery partners to ensure accurate and timely dispatch of your orders.
- IT service providers supporting our website and order processing systems.
- Accountants and auditors for statutory and compliance purposes.
Where our processors operate outside of the United Kingdom or European Economic Area, we ensure appropriate safeguards are in place to protect your information in accordance with GDPR requirements.
We do not sell, rent, or otherwise share your personal data with third parties for their marketing purposes.
Data Security
We apply robust security measures to protect your personal data from accidental loss, unauthorised access, or misuse. These measures include restricted access to your data, encrypted storage and transmission, regular review of our data collection practices, and security training for our staff.
Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure (‘Right to be forgotten’): Request deletion of your personal data, subject to legal retention obligations.
- Right to Restrict Processing: Request to limit the processing of your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used format and transmit it to another controller, where technically feasible.
- Right to Object: Object to certain types of processing, including for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw this at any time.
To exercise any of these rights, please contact us using the contact details found on our website or in-store. Please note that we may request proof of identity before responding to data-related requests, and that certain legal exceptions may apply.
Policy Scope and Updates
This Privacy Policy applies to all customers who place orders with Kingston upon Thames Florist for delivery within Kingston upon Thames and surrounding districts. We may update this policy periodically to reflect changes in our practices or relevant legislation. Significant changes will be notified via our website.
Contact and Complaints
If you have questions about this Privacy Policy or how your data is processed by Kingston upon Thames Florist, please get in touch through the contact information provided on our website. If you believe your data protection rights have been breached, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) or your local supervisory authority.
We value your trust and are committed to ensuring that your personal data is handled responsibly and transparently.