Putney Florist GDPR-Compliant Privacy Policy
Introduction
This Privacy Policy outlines how Putney Florist (“we”, “us”, “our”) collects, uses, and protects your personal data when you place orders with us within Putney and nearby districts. We are committed to ensuring your privacy and compliance with the General Data Protection Regulation (GDPR). By ordering from us, you consent to the policies described herein.
Scope of this Policy
This policy applies to all existing and prospective customers of Putney Florist who place orders for floral products or related services within Putney and the surrounding areas. It covers all data we collect directly, indirectly, or through our service providers about your transactions and interactions with us.
What Data We Collect
We collect personal data only as necessary to fulfil your orders, improve our services, and meet legal obligations. The types of data we may collect include:
- Contact Details: Full name, delivery address, billing address, and telephone number.
- Order Information: Product selections, delivery details, messages included with your order, and transaction history.
- Payment Data: Limited payment details (such as the last four digits of your payment card and payment confirmation) processed via secure third-party payment processors. We do not store full card numbers or security codes.
- Communication Data: Any feedback, inquiries, or correspondence you send us before, during, or after an order.
- Technical Information: IP address, browser type, and website usage data collected through our website to ensure security and enhance user experience.
Lawful Basis for Processing Your Data
We ensure that all personal data processing is lawful, fair, and transparent. Our primary lawful bases for processing your data under GDPR are:
- Contractual Necessity: To process your order, arrange deliveries, and provide customer support.
- Legitimate Interests: To improve our products, services, and website while respecting your privacy rights.
- Legal Compliance: To comply with legal obligations, such as record-keeping for tax purposes.
- Consent: Where you have specifically provided consent, for instance, for marketing communications. Consent can be withdrawn at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- To process and deliver your floral orders.
- To communicate with you regarding your order status and delivery.
- To address queries or resolve issues you raise.
- To maintain internal records and meet our legal obligations.
- To enhance and improve our products, services, and customer experience.
- To offer you updates, promotions, or content where you have opted in to receive marketing communications.
Data Retention
We retain your personal data only as long as necessary to fulfil the purposes described in this policy or to comply with applicable laws. Standard retention periods include:
- Order and transaction data: Retained for up to six years to meet accounting and legal requirements.
- Marketing preferences: Retained until you withdraw consent or ask to be removed from our communications.
- Technical data: Stored for up to one year for security and analytical purposes.
Upon expiry of retention periods or upon your validated request for erasure, your data will be securely deleted or anonymised.
Data Processors and Sharing
We may engage third-party service providers (“processors”) to facilitate certain aspects of our service. These trusted processors may handle data for payment transactions, order deliveries, website hosting, or customer communications. We ensure all processors safeguard your data to GDPR standards and only process your data according to our instructions. We do not sell or otherwise share your data with unaffiliated third parties for marketing purposes.
Other circumstances where sharing may occur include:
- Where legally required, such as to comply with law enforcement or regulatory authorities.
- To protect the rights, property, or safety of our customers or staff.
Your Data Protection Rights
Under GDPR, you have several rights regarding your personal data, including:
- Right to Access: You may request confirmation of whether we hold personal data about you, and obtain a copy of that data.
- Right to Rectification: You can request that we correct or update your personal data if it is inaccurate or incomplete.
- Right to Erasure: You may ask us to erase your personal data when it is no longer needed for the purpose collected or if you withdraw consent.
- Right to Restriction: You may request restriction of processing under certain circumstances.
- Right to Data Portability: You have the right to receive your data in a structured, commonly used format and transmit it to another controller.
- Right to Object: You may object to processing when we rely on legitimate interests. We will respond unless we have compelling legitimate grounds.
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw this at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to raise concerns with a supervisory authority if you believe we have not complied with GDPR requirements.
Data Security
We implement appropriate security measures to protect your personal data against accidental loss, unauthorised access, disclosure, or alteration. This includes technical, administrative, and physical safeguards. Our staff and service providers are trained on the importance of data protection and confidentiality.
Changes to This Policy
This Privacy Policy may be updated periodically to reflect changes in legal or regulatory requirements, our practices, or technology. Updated versions will be available through our usual customer communication methods and on our service premises.
Contact and Questions
If you have questions or concerns about your personal data or this Privacy Policy, you can contact us at our premises in Putney for further information or to exercise your data protection rights. Our data protection lead will aim to address all queries promptly and transparently.