Florist Enfield GDPR Privacy Policy
Introduction
This Privacy Policy outlines how Florist Enfield collects, uses, stores, and protects your personal information. The policy applies to all customers placing orders with Florist Enfield in Enfield and surrounding districts. We are committed to operating in accordance with the UK General Data Protection Regulation (GDPR) and ensuring your privacy is safeguarded.
What Data We Collect
When you place an order or interact with Florist Enfield, we may collect the following types of personal data:
- Identity Data: First and last name, title.
- Contact Data: Billing and delivery addresses, telephone number, and (if provided) a contact email.
- Order Data: Transaction details such as selected products, cost, delivery instructions, personalized note messages, and order history.
- Payment Data: Payment status, method, and reference (please note, we do not store full card details).
- Technical Data: Device identifiers, IP address, browser type, and cookies related to your visit.
- Correspondence: Records of communications with our team regarding your order or queries.
We do not knowingly collect or process special categories of personal data (such as information about health, race, religion, or biometrics).
Lawful Basis for Processing Your Data
Florist Enfield processes your personal data only when we have a valid legal reason to do so. The primary lawful bases we rely on are:
- Performance of a Contract: To process and deliver your order, your data is necessary for fulfilling our contractual obligations.
- Legitimate Interests: To improve our products and services, respond to your queries, and communicate order updates, we may use your data where it does not override your rights and interests.
- Legal Obligation: To comply with laws and regulations (such as tax and accounting requirements), we may process and retain some personal data.
- Consent: If you sign up for direct marketing or optional updates, this will be based on your explicit opt-in consent, which you can withdraw at any time.
How We Use Your Data
We use your personal data to:
- Process and fulfill your orders, including confirming and tracking deliveries.
- Contact you regarding your purchase, requested changes, or delivery queries.
- Respond to customer service requests and feedback.
- Improve our site, services, and user experience through aggregated analytics.
- Comply with legal and regulatory requirements.
- Send you marketing communications (only where permitted by law or your consent).
Data Retention
We retain personal data only for as long as is necessary for the purposes stated above, or as legally required. In general:
- Order and transaction records: Retained for up to seven years for tax and accounting purposes.
- Marketing data: Retained until you withdraw your consent or unsubscribe.
- Website usage data: Retained for up to two years for analytics unless you clear your browser cookies or exercise your right to object.
- Correspondence: Retained as long as needed to resolve your enquiry and, where applicable, support further orders.
On expiry of the relevant retention period, your personal data will be securely deleted or rendered anonymous.
Data Sharing and Processors
Florist Enfield may share your personal data with trusted third parties only for the purposes described in this policy. These include:
- Payment processors: To handle secure payment and refunds. We do not store payment card details ourselves.
- IT and web service providers: To manage our website, email, and order systems.
- Delivery partners: To ensure your order is delivered to the correct address.
- Professional advisors: Such as accountants or legal services, where necessary.
- Regulators or legal authorities: If required by law or court order.
All third-party processors are vetted for GDPR compliance and act only on our instructions. They are prohibited from using your data for their own purposes.
Data Storage and Security
Your personal data is stored securely using technical and organisational measures to protect it against unauthorised access, alteration, disclosure, or destruction. Digital data is encrypted where possible, and physical access to our offices and records is restricted. Our staff are trained in data protection and privacy standards.
Your Rights Under GDPR
You have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct incomplete or inaccurate information.
- Erasure (right to be forgotten): Request deletion of your data where there is no lawful basis for us to retain it.
- Restriction: Request we restrict processing where you contest its accuracy or lawfulness.
- Objection: Object to processing for direct marketing or where processing is based on our legitimate interests.
- Data Portability: Ask for your data to be transferred to another provider or given to you in a digital format.
- Withdraw Consent: Where processing is based on consent, you have the right to withdraw it at any time.
- Complain: You have the right to contact the Information Commissioner’s Office if you have concerns about our data practices.
We will respond to your requests as quickly as possible in accordance with applicable law.
Policy Changes
We may update this Privacy Policy from time to time to reflect new legal or regulatory requirements or our data practices. The latest version will always be available to customers placing orders with Florist Enfield.
Contacting Us
If you have any questions, concerns, or requests relating to your personal data or this Privacy Policy, you may contact us through our website or at our physical store.