Privacy Policy for Hillingdon Florist Customers
Introduction
This Privacy Policy describes how Hillingdon Florist collects, uses, stores, and protects your personal information. It covers all customers placing orders with Hillingdon Florist from Hillingdon and the surrounding districts. By placing an order, you agree to the data practices described herein, which comply with the General Data Protection Regulation (GDPR).
What Data We Collect
To process your order and provide our services, Hillingdon Florist may collect and process the following categories of personal data:
- Contact Information: Name, postal address, delivery address, telephone number, and other relevant contact details.
- Order Details: Product selections, delivery preferences, gift messages, and order history.
- Payment Information: Only relevant payment details necessary to process your transaction, such as payment method and confirmation of payment (we do not store your full card details).
- Correspondence: Records of communications with our team, such as queries, feedback, or complaints.
- Technical Data: IP address, browser type, device information, and anonymised analytics (when you use our website), to ensure website security and improve your experience.
Lawful Basis for Processing Your Data
Hillingdon Florist relies on the following lawful bases under GDPR to process your personal data:
- Contractual Necessity: To fulfil your order or to take steps prior to entering into a contract (e.g., confirming availability, processing payment, and providing delivery updates).
- Legal Obligation: To comply with laws requiring us to retain information for accounting, tax, or reporting purposes.
- Legitimate Interests: For effective business operation, such as order confirmation, customer support, complaint resolution, or improving our services. We always balance these interests against your data protection rights.
- Consent: Where required, for example if you opt in to receive marketing communications from us. You can withdraw your consent at any time.
How We Use Your Data
Your personal data is used strictly for the following purposes:
- Processing, confirming, and delivering your flower orders.
- Providing information about your order status and delivery updates.
- Responding to your queries, feedback, or complaints.
- Maintaining accurate records for our accounting and business integrity.
- Improving our services and website functionality through anonymous data analysis.
- Fulfilling legal obligations or defending our legitimate business interests if necessary.
Data Retention Periods
Hillingdon Florist retains your personal information only for as long as is necessary to fulfil the purpose for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. This means:
- Order Data: Kept for up to 7 years to comply with tax and accounting obligations.
- Customer Correspondence: Retained for up to 3 years after resolution of the enquiry or complaint.
- Marketing Preferences: Kept until you withdraw consent or opt out.
- Technical Data: Anonymised data and web logs are retained for up to 24 months.
Data will be securely deleted once the relevant retention period has elapsed or if you request erasure, subject to legal requirements.
Our Data Processors
We sometimes use trusted third-party service providers ("processors") to help us operate efficiently and to fulfil customer orders. These may include:
- Payment service providers processing payments securely on our behalf.
- Courier and delivery partners to deliver your orders to the correct address.
- IT and hosting providers, who help us store and safeguard data.
- Professional advisers (such as accountants or legal consultants) when necessary for business compliance and operation.
All processors are carefully selected, GDPR-compliant, and contractually bound to protect your data and process it only according to our instructions.
Your Data Protection Rights
Under GDPR, you are entitled to a range of rights regarding your personal data:
- Right to Access: You may request a copy of your personal data held by us.
- Right to Rectification: You may request correction of incomplete or inaccurate data.
- Right to Erasure: You can ask us to delete your data under certain circumstances (unless we must retain it for legal reasons).
- Right to Restrict Processing: You can ask us to suspend processing of your data while we resolve any concerns.
- Right to Data Portability: You may request a digital copy of data you have provided so you can transfer it elsewhere.
- Right to Object: You may object to data processing performed on the basis of legitimate interests or direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us using the channels provided on our website or at our shop. We aim to respond within one calendar month and may request identity confirmation to ensure security.
Security of Your Personal Data
Hillingdon Florist is committed to protecting your personal data. Your information is stored using secure systems, and we implement suitable technical and organisational measures to prevent unauthorised access, loss, or misuse. Only authorised staff and legitimate processors have access to your data as necessary for their role.
Policy Updates
We may update this Privacy Policy to reflect changes in our practices or legal obligations. Any significant changes will be communicated to you in an appropriate and transparent way. Please review this policy regularly if you are a returning customer.
Contact and Complaints
If you have any questions about this Privacy Policy, your data, or your rights, please contact us using the details provided on our website or at our shop. If you are dissatisfied with our response, you have the right to complain to the UK Information Commissioner's Office (ICO).