South Kensington Florist Privacy Policy
Introduction
This Privacy Policy explains how South Kensington Florist collects, uses, stores, and protects your personal data. This policy applies to all customers placing orders with South Kensington Florist in South Kensington and surrounding districts. We are committed to complying with the General Data Protection Regulation (GDPR) and safeguarding your personal information at all times.
What Data We Collect
When you place an order with South Kensington Florist, or interact with our business, we may collect and process the following categories of personal data:
- Identity Data: Includes your name and, if you are ordering for someone else, the recipient's name.
- Contact Data: Includes billing and delivery addresses, telephone numbers, and delivery instructions.
- Order Information: Includes details of your purchase, delivery preferences, messages with orders, and payment method.
- Transaction Data: Details about payments to and from you, and other details of products and services you have purchased from us.
- Technical Data: Includes IP address, browser type and version, time zone settings, and other technology on the devices you use to access our website.
- Marketing Preferences: Your preferences regarding receiving marketing from us.
Lawful Basis for Processing Your Data
We process your data only when we have a lawful basis under the GDPR. These include:
- Performance of Contract: Collecting and processing your data to fulfill and manage your purchase orders.
- Legal Obligation: Retaining certain data where legally required (for example, finance or tax records).
- Legitimate Interests: Managing and improving our business, products, and customer experience, provided our interests are not overridden by your rights.
- Consent: For certain communications, such as marketing emails, we request your explicit consent. You can withdraw this consent at any time.
How We Use Your Data
The data we collect is used for the following purposes:
- Processing and delivering your flower orders, including managing payments and arranging delivery.
- Communicating with you regarding your order, changes, or queries.
- Providing customer support and responding to your requests.
- Improving our website, products, and services based on customer feedback and behavior.
- Complying with legal requirements and resolving disputes.
- Subject to your consent, sending you marketing material about our products, services, and special offers.
Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including for legal or accounting requirements, or to resolve disputes. Typically:
- Order and Transaction Data: Kept for up to seven years in line with legal accounting obligations.
- Marketing Data: Retained until you withdraw your consent or unsubscribe from communications.
- General Enquiries: Data provided via contact or enquiry forms is deleted after the enquiry is closed, unless a business relationship develops.
Sharing Your Data & Data Processors
Your personal data may be shared with trusted third-party processors and service providers to facilitate our business operations, such as payment processing, order delivery, IT services, and website hosting. These include:
- Payment service providers, who process your transactions securely.
- Trusted delivery partners, for order fulfillment.
- IT and system administration service providers who support our website and systems.
We require all third-party processors to respect the security of your personal data, only process it for specified purposes, and treat it in accordance with the law. We do not sell or rent your data to any third parties.
Your Rights Under GDPR
As a customer and data subject, you have the following rights regarding your personal data under GDPR:
- The right to access: You may request access to your personal data and obtain a copy of the information we hold.
- The right to rectification: You can correct any inaccurate or incomplete personal data.
- The right to erasure: You may request deletion of your data under certain circumstances (subject to retention requirements).
- The right to restrict processing: You can request us to pause processing your data, for example if you contest its accuracy.
- The right to object: You can object to processing based on legitimate interests, or to direct marketing at any time.
- The right to data portability: You are entitled to receive your data or have it transferred to another controller, where technically feasible.
- The right to withdraw consent: Where consent is relied upon, you have the right to withdraw this at any time.
If you wish to exercise any of these rights, please contact us using methods provided on our website or in your order confirmation communications.
International Data Transfers
We do not routinely transfer data outside the European Economic Area (EEA). If, for technical or operational reasons, such transfers are necessary, we ensure appropriate safeguards are in place in accordance with GDPR requirements.
Data Security
We implement appropriate technical and organizational measures to protect your data against accidental or unlawful loss, alteration, unauthorized disclosure, or access. Access to your personal data is limited to staff, agents, and contractors who have a business need to know, and who are bound by confidentiality obligations.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our data handling practices or legal requirements. Any updates will be published on our website. Continued use of our services after updates implies acceptance of the revised policy.
Contact and Further Information
If you have questions about this policy, your personal data, or wish to exercise your rights, please contact our customer team as set out on our website or on your order communications. We are committed to resolving any concerns promptly and transparently.