Enfield Town Florist GDPR Privacy Policy
Introduction
This privacy policy describes how Enfield Town Florist collects, uses, and protects your personal information in compliance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Enfield Town Florist from Enfield Town and the surrounding districts. By using our services, you agree to the terms outlined in this document. We are committed to handling your information responsibly and transparently.
What Data We Collect
Enfield Town Florist collects only the minimum personal data required to process, deliver, and manage your order. The types of personal data we may collect include:
- Contact Information: Name, delivery address, and occasionally billing address.
- Order Details: Information regarding your floral order including card message, preferences, and special instructions.
- Payment Information: Transaction and payment details (note: we do not store full card details, only transaction identifiers where necessary for order processing).
- Communication Records: Details from your interactions with us (e.g., feedback, customer service queries).
- Recipient Information: Name and delivery address of the recipient if different from the customer.
- Technical Data: When using our website, some technical data such as IP address, browser type, and device identifiers may be collected for security and analytics.
Lawful Basis for Processing
Enfield Town Florist only processes your personal information where we have a valid legal basis to do so under GDPR. The primary lawful bases include:
- Contractual Necessity: Most of the data we collect is needed to fulfil your order and provide you with services you request (e.g., delivering your flowers to the correct address).
- Legal Obligation: We may be required to retain certain records to comply with legal or accounting obligations.
- Legitimate Interests: We may use certain information (such as order history or contact details) for legitimate business purposes such as direct customer communication, improving our services, and internal record keeping. We balance our legitimate interests against your rights and interests.
- Consent: Where you have given us specific consent (e.g., receiving marketing communications), you may withdraw this consent at any time.
How We Use Your Data
Your personal data is used solely for the following purposes:
- Processing and fulfilling your flower orders.
- Delivering products to you or your chosen recipient.
- Communicating with you about your order or any requested service.
- Improving our website and services.
- Complying with accounting and legal requirements.
Data Retention
We will retain your personal data only for as long as is necessary to fulfil the purposes set out above, including for satisfying any legal, accounting, or reporting requirements. Typically:
- Order and delivery data is kept for up to six years, in compliance with accounting standards and regulatory obligations.
- Data related to inquiries or feedback not linked to an order may be held for up to two years for customer service purposes.
- Payment and transaction identifiers are retained only as long as required for processing and legal compliance, and we do not store your full card details after processing is complete.
- If you withdraw consent for marketing, we will remove you from our marketing lists immediately, retaining only proof that consent was withdrawn.
Data Processors and Sharing
We do not sell or rent your personal data to third parties. However, we may share your information with trusted third-party processors only as necessary to deliver our services and operate our business, such as:
- Payment services providers, to securely process your payment.
- IT service providers that support our website and order management systems.
- Delivery partners, where relevant, for the purpose of fulfilling your order.
- Accounting and legal professionals for compliance and audit purposes.
All third-party data processors are contractually required to handle your data in accordance with GDPR and to use it only for the specified purposes. Data is not transferred outside of the UK or EEA without appropriate safeguards.
Your Rights
As a customer, you have the following rights with respect to your personal data under GDPR:
- Right of Access: You may request a copy of the personal information we hold about you at any time.
- Right to Rectification: If any information we hold about you is inaccurate or incomplete, you have the right to request correction.
- Right to Erasure: You may request the deletion of your personal data where it is no longer needed or if you withdraw consent.
- Right to Restrict Processing: You can request us to limit the way we use your data in certain circumstances.
- Right to Data Portability: You can ask us to provide your information in a commonly used, machine-readable format or to transfer it directly to another controller.
- Right to Object: You have the right to object to how we use your personal data under certain circumstances, including direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise your rights, please contact us using the details provided on our website or in-store. We will respond to all requests within one month as required by GDPR.
Security of Your Information
Protecting your personal data is important to us. We implement appropriate technical and organisational measures to secure your data from unauthorised access, loss, destruction, or disclosure. Access to your data is limited to authorised staff and processors who require it to fulfil their role.
Policy Updates
We reserve the right to update or modify this Policy at any time to ensure ongoing GDPR compliance or to reflect changes in our practices. Customers are encouraged to review this Policy periodically. Material changes to this policy will be communicated on our website or at point of sale.
Contact and Complaints
If you have any questions or concerns about how we handle your personal data, or if you wish to make a complaint, please contact us at our store or using the contact information provided on our website. You also have the right to lodge a complaint with the UK Information Commissioner's Office regarding our data processing activities.