Seven Sisters Florist GDPR Privacy Policy
Introduction
This Privacy Policy outlines how Seven Sisters Florist ("we," "us," "our") collects, uses, stores, and protects your personal data in compliance with the UK General Data Protection Regulation (UK GDPR). This policy applies to all customers placing orders from Seven Sisters and any surrounding districts. Seven Sisters Florist is dedicated to handling your personal information with great care, accountability, and transparency.
What Data We Collect
When you place an order with Seven Sisters Florist, we may collect, process, and store the following categories of personal data:
- Identification Data: Your full name and, if relevant, your title.
- Contact Data: Postal address, delivery address, billing address, and phone number.
- Order Data: Details of the products you order, order notes, messages for recipients, and transaction information.
- Payment Data: Payment method, and information required to process payments and prevent fraud (note: payment card details are processed securely by our payment processors and not stored by us).
- Communication Data: Data from correspondence, customer support, or feedback you provide.
- Technical Data: IP addresses, browser type, page interaction information, and other technical data collected through our website to optimize user experience.
Purposes and Lawful Basis for Processing Personal Data
Under the GDPR, we must have a lawful basis for processing your personal information. Seven Sisters Florist may process your data for the following purposes and bases:
- Contractual Necessity: For processing and fulfilling your orders, managing payments, deliveries, and customer service. Your personal data is required to enter into a contract with us for products and services.
- Legal Obligation: To comply with statutory and regulatory requirements (such as bookkeeping and tax regulations).
- Legitimate Interests: For reviewing and improving our products and services, ensuring website security, fraud prevention, and for marketing our products to existing customers. We always balance these interests against your rights and freedoms.
- Consent: Where you provide specific consent, such as signing up for marketing communications (which you can withdraw at any time).
How We Use Your Information
We use your personal data to:
- Process and complete floral orders, including confirming your order and arranging delivery.
- Communicate with you about orders, changes, and customer service inquiries.
- Fulfil our legal and contractual obligations.
- Improve our customer services and offerings based on feedback and purchase data.
- Detect and prevent fraudulent activities.
- Send marketing communications to existing customers, if you have not opted out.
- Monitor website usage to enhance security and performance.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Generally, customer and transaction records are kept for up to seven years to comply with legal and tax obligations. After this period, your information will be securely deleted or anonymized, unless we are required by law to retain it for a longer period.
Processors and Data Sharing
We may share your information with carefully selected third-party service providers (processors) who help us to deliver our products and services. These may include:
- Payment processors handling secure payment transactions.
- Courier and delivery partners to send orders to you or your recipients.
- IT service providers supporting our ordering platform and website.
- Accounting, legal, and compliance advisors.
All third-party service providers are contractually obliged to process your data only in accordance with our instructions and to adhere to the strict security provisions of the GDPR. We do not sell or rent your data to third parties for their own independent purposes.
Your Data Protection Rights
Under the UK GDPR, you have a range of rights regarding your personal data. These include:
- Right of Access: You can request confirmation of what personal data we hold about you and request a copy.
- Right to Rectification: You may ask us to correct or complete inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your personal data in certain circumstances (excluding where we have a legal requirement to retain it).
- Right to Restriction: You may ask us to temporarily halt processing of your personal data under certain conditions.
- Right to Data Portability: You are entitled to receive your personal data or have it transferred to another service provider where technically feasible.
- Right to Object: You can object to processing where our lawful basis is legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw this at any time.
If you wish to exercise any of these rights, please contact us by the appropriate means listed on our website or in writing.
Security of Your Data
Seven Sisters Florist implements appropriate technical and organizational measures to protect your personal data against unauthorized or unlawful processing and against accidental loss, destruction, or damage. Access to your personal data is restricted to those employees, agents, contractors, and service providers who have a business need to know.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in law, regulation, or our data practices. When that occurs, we will update the date of revision and encourage you to review the policy regularly.
Contact and Complaints
If you have questions about this policy or are dissatisfied with how we have processed your personal data, you may also lodge a complaint with the UK Information Commissioner's Office (ICO).