Florist Earlsfield Privacy Policy
  Introduction
This Privacy Policy explains how Florist Earlsfield collects, uses, and protects the personal data of our customers in accordance with the UK General Data Protection Regulation (GDPR). This policy applies to all individuals placing orders with Florist Earlsfield from Earlsfield and the surrounding districts. By using our services, you acknowledge and accept the practices described in this statement.
What Personal Data We Collect
We collect personal data necessary to process your orders and provide quality customer service. The types of personal data we may collect include:
	- Contact details: Such as full name, delivery address, billing address, telephone number, and email address.
 
	- Order information: Details about the products you order, delivery preferences, and messages you wish to include with your floral arrangements.
 
	- Payment information: Information required to process your payment, such as partial card data (handled securely by our payment processors).
 
	- Communication data: Records of correspondence with our customer service team, including order queries, feedback, or complaints.
 
	- Website usage data: Information collected via cookies and analytics tools, such as IP address, browser type, device information, and pages visited, to help us improve the customer experience.
 
Lawful Basis for Data Processing
Under the GDPR, we must have a lawful basis for processing your personal information. Florist Earlsfield relies on the following lawful bases:
	- Performance of a contract: Processing your information is necessary to fulfil your floral order, including payment, delivery, and aftercare services.
 
	- Legal obligation: We retain certain information as required by law, such as transactional records for accounting or tax purposes.
 
	- Legitimate interests: We may process data for our legitimate interests, such as improving services, responding to queries, and ensuring security—balanced against your rights and interests.
 
	- Consent: When we wish to send you marketing communications or newsletters, we will only do so with your explicit consent. You can withdraw your consent at any time.
 
How We Use Your Data
Your data is used to:
	- Process and deliver your orders accurately and efficiently.
 
	- Communicate with you regarding your orders, including confirmations, updates, and any necessary customer support.
 
	- Personalise your experience and improve our website and services based on customer feedback and browsing habits.
 
	- Comply with legal and financial obligations.
 
	- Send you relevant news or special offers, only where you have opted in.
 
Data Retention Policy
We retain your personal data only as long as necessary to fulfil the purposes outlined in this policy unless a longer retention period is required or permitted by law. The retention periods are as follows:
	- Order and contact data: Kept for up to seven years to comply with legal, accounting, and tax requirements.
 
	- Marketing data: Kept until you withdraw your consent or request deletion.
 
	- Website analytics data: Kept for up to two years for trend analysis and service improvement.
 
Once data is no longer needed, it is securely deleted or anonymised.
Sharing Your Data with Processors
We only share your data with trusted third-party service providers, known as processors, who help us to deliver our services. These include:
	- Payment processors: Securely process your payments without sharing full card details with us.
 
	- IT and hosting providers: Support our website infrastructure and securely store data.
 
	- Courier and delivery partners: Enable order deliveries to your chosen address.
 
	- Marketing partners: Distribute newsletters or special offer emails with your consent.
 
All processors act on our instructions and are bound by contractual obligations to keep your data secure and process it only for the specified purposes. We do not sell or rent your personal information to any third party. Your data is processed only within the UK and the European Economic Area (EEA), and we take steps to ensure it remains protected in line with GDPR.
Your Rights as a Data Subject
You have important rights regarding how we handle your personal data. These include:
	- Right to access: Request a copy of the personal data we hold about you.
 
	- Right to rectification: Request correction of inaccurate or incomplete information.
 
	- Right to erasure: Request deletion of your personal data in certain circumstances, such as when it is no longer necessary for the purposes collected.
 
	- Right to restrict processing: Request us to stop processing your data, subject to certain legal limitations.
 
	- Right to data portability: Request a copy of your data in a commonly used electronic format for transfer to another service provider.
 
	- Right to object: Object to data processing undertaken for legitimate interests or direct marketing purposes.
 
	- Right to withdraw consent: Where processing is based on consent, you can withdraw this at any time without affecting the lawfulness of previous processing.
 
To exercise any of your rights, please contact us using the details provided on our website. We may require verification of your identity before actioning certain requests, and we will respond promptly in line with GDPR timeframes.
Children's Privacy
Our services are not intended for individuals under the age of 16. We do not knowingly collect or process data relating to children. If we are informed that we have inadvertently collected such data, we will remove it as soon as possible.
Data Security
We are committed to ensuring that your information is secure. Appropriate technical and organisational measures are in place to prevent unauthorised access, disclosure, alteration, or destruction of your data. While we strive to protect your information, please be aware that no security system can be guaranteed as completely secure. We advise you to take suitable precautions when communicating with us or using our website.
Changes to This Policy
Florist Earlsfield periodically reviews this policy and may update it to reflect changes in legal requirements or our processes. The latest version will always be available on our website. We encourage you to check this page from time to time to ensure you remain informed about how we protect your privacy.
Contact and Complaints
If you have any questions about this Privacy Policy or how your personal data is managed, please use the contact options provided on our website. If you are unsatisfied with our response, you can also lodge a complaint with the UK Information Commissioner's Office (ICO) as the supervisory authority.