Florist Bowes Park Privacy Policy
Introduction
This Privacy Policy explains how Florist Bowes Park collects, uses, stores, and protects your personal information in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Florist Bowes Park from Bowes Park and surrounding districts. Please read this document carefully to understand your rights and how we handle your data.
What Data We Collect
We collect the following categories of personal data when you place an order or interact with us:
- Contact Information: Name, delivery address, billing address, and other details necessary to fulfill your order.
- Order Details: Product selections, order history, and special instructions.
- Payment Information: Limited payment details required to process your transaction. We do not store full card numbers.
- Communication Data: Any information you provide when contacting us or making enquiries, including messages and preferences.
- Technical Data: IP address, browser type, and patterns of use on our website (collected via cookies and similar technologies). This is predominantly non-identifiable statistical data.
Lawful Basis for Processing Your Data
We process your personal data under the following lawful bases, as defined by the GDPR:
- Contractual Necessity: Processing is necessary to fulfill your order and provide requested services.
- Legal Obligation: We may be required to process and retain certain information to comply with tax and accounting laws.
- Legitimate Interests: For purposes such as improving our services, internal administration, and mitigating fraud, provided these interests do not override your rights.
- Consent: In certain cases, such as marketing communications, we will request your explicit consent before processing your data.
How We Use Your Data
Your personal data may be used for the following purposes:
- Processing and delivering your floral orders
- Managing payments and refunds
- Responding to your queries or requests
- Sending order updates and delivery notifications
- Improving our website and customer service
- Fulfilling legal and regulatory obligations
- Subject to consent, sending special offers or marketing communications
Retention of Your Data
We will only retain your personal data for as long as necessary to fulfill the purposes for which we collected it, including legal, accounting, or reporting requirements. This typically means:
- Order and transaction details: Retained for up to 7 years to satisfy tax and legal requirements.
- Account and contact information: Held until you request removal or close your account, except where longer retention is required by law.
- Marketing preferences: Maintained until you opt-out or withdraw consent.
- Browsing data: Retained for a short period for analytical purposes only.
After these periods, your data is securely deleted or anonymised.
Third-Party Processors
To provide our services efficiently, we sometimes need to share your personal information with trusted third-party processors. These may include:
- Payment processing providers to complete transactions securely
- Delivery partners for handling and delivering floral orders
- IT service providers and website hosting companies
- Professional advisers for legal or accounting assistance
We only select processors who comply with GDPR requirements and ensure adequate data protection standards. Third parties are not permitted to use your data for their own purposes.
Your Rights Under the GDPR
You have the following rights regarding your personal data:
- Right of Access: Request access to your personal data and receive a copy.
- Right to Rectification: Have any incomplete or inaccurate data corrected.
- Right to Erasure: Request that we delete your personal data, where lawful to do so.
- Right to Restrict Processing: Ask us to suspend processing in certain scenarios.
- Right to Data Portability: Request transfer of your data to another provider in a commonly used format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time.
To exercise your rights, please contact us using the contact options provided on our website or with your order confirmation. Please note, we may require you to verify your identity before fulfilling your request.
Security Measures
Protecting your data is a priority. We implement appropriate technical and organisational security measures to prevent unauthorised access, alteration, disclosure, or destruction of your personal information.
- Use of encryption and secure storage for sensitive data
- Regular staff training on data protection responsibilities
- Restricted access to personal data on a need-to-know basis
- Routine security reviews of our IT systems
Despite these efforts, we advise you that no method of transmission over the Internet or method of electronic storage is completely secure. We maintain procedures to deal with any actual or suspected data breaches as required by law.
Updates to This Privacy Policy
We review this Privacy Policy regularly and reserve the right to update it as necessary to reflect changes in our practices or legal requirements. Any significant policy changes will be clearly communicated via our website or your contact details provided at the time of order.
Contact Us
If you have questions about this Privacy Policy, your data, or wish to exercise your GDPR rights, please contact us through the means available on our website. We are committed to working with you to ensure your privacy is protected.