Harlesden Florist Data Privacy Policy
Introduction
This Privacy Policy outlines how Harlesden Florist handles personal data for all customers placing orders from Harlesden and its surrounding districts. We are committed to safeguarding your information and ensuring full compliance with the UK General Data Protection Regulation (GDPR).
What Data We Collect
When you place an order or interact with Harlesden Florist, we may collect the following data:
- Personal Identification Information: Name, delivery address, telephone number, and, if provided, recipient's name and address.
- Order and Transaction Data: Details of your orders, purchase history, billing information, and payment confirmations (note: we do not directly store payment card details; these are processed securely through third-party payment processors).
- Contact Information: Email address and phone number for order confirmations, delivery updates, or customer service purposes.
- Correspondence: Any information you provide via phone, in-person requests, or electronic correspondence (such as questions, special instructions, or feedback).
- Website Usage Data: Information about your interaction with our website, including pages viewed, navigation patterns, IP addresses, and browser type. We use cookies and similar technologies to enhance user experience; details are available on request.
Lawful Basis for Processing
Harlesden Florist collects and processes your data in accordance with the lawful bases set out under GDPR. These include:
- Performance of a Contract: Most data processing is necessary to fulfill your flower order, process payment, and arrange delivery.
- Legal Obligation: We are required by law to retain some transaction records for tax and accounting purposes.
- Legitimate Interest: For running and improving our business, managing customer relationships, and where relevant, sending communications about your order or related offerings. We ensure that our legitimate interests do not override your data protection rights.
- Consent: If we ever wish to process your personal data for direct marketing purposes outside the scope of an ongoing transaction, we will obtain your explicit consent in advance.
How We Use Your Data
We use the personal data we collect for the following purposes:
- Processing and fulfilling your orders, including contacting you or the delivery recipient if required.
- Managing payments and confirming transactions.
- Handling customer service requests or queries.
- Improving our products, services, and website experience.
- Complying with legal and regulatory requirements.
How Long We Retain Your Data
Your personal data is only retained for as long as necessary to fulfill the purposes outlined in this Privacy Policy. Typically, order and transaction data are kept for up to seven (7) years to meet accounting and legal obligations. Customer correspondence not subject to legal retention may be deleted after two (2) years. Website usage data, such as analytics, is retained for no longer than twelve (12) months, unless needed for security or improvement purposes. When data is no longer required, it is securely destroyed or anonymised.
Third-Party Processors
We may engage third-party processors to facilitate some aspects of our business, including:
- Payment Services Providers: To securely process card payments.
- IT Service Providers: For hosting our website and managing certain electronic communications.
- Delivery Partners: In rare instances, for logistics or to facilitate delivery during busy periods.
- Professional Advisors: Such as accountants or legal advisors, for compliance and business administration.
All third-party processors are contractually obliged to comply with GDPR requirements and process your data only for specified purposes under our instructions.
User Rights Under GDPR
Under the GDPR, you have several important rights regarding your personal information:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct any incorrect or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You may ask us to delete your information where there is no compelling reason for its continued processing.
- Right to Restrict Processing: You can request restriction or suppression of your personal data usage in certain circumstances.
- Right to Object: You can object to processing based on legitimate interests or direct marketing at any time.
- Right to Data Portability: You have the right to receive your information in a structured, machine-readable format.
To exercise any of these rights, please submit a request in writing. We will respond in accordance with statutory timescales and requirements. Proof of identity may be necessary prior to fulfilling some requests.
Security of Your Data
Harlesden Florist employs appropriate technical and organisational measures to protect your personal data from accidental loss, disclosure, unauthorised access, alteration, or destruction. Such measures include secured IT infrastructure, access controls, data minimisation, and staff training.
Children's Privacy
Harlesden Florist does not knowingly collect or process data from individuals under the age of 16. If we learn that data from a child under 16 has been provided, we will take appropriate steps to remove such information from our systems.
Policy Updates
We may update this Privacy Policy from time to time in response to legal, technical, or business developments. Any significant changes will be made available through our website. We encourage you to review this Policy periodically.
Contact and Further Information
If you have questions or concerns about this Privacy Policy, your personal data, or your rights, please contact us in writing or visit us in store. We take your privacy seriously and are happy to assist with any queries regarding our processing of your information.