Bowes Park Florist Privacy Policy
Introduction
This Privacy Policy explains how Bowes Park Florist ('we', 'our', or 'us') collects, uses, stores, and protects your personal data. This policy applies to all customers placing orders with Bowes Park Florist in Bowes Park and the surrounding districts. We are committed to handling your personal information in accordance with the UK General Data Protection Regulation (GDPR) and other applicable data protection laws.
What Data We Collect
To fulfill your orders and provide outstanding customer service, we may collect the following types of personal data:
- Identity Data: Name, title, and contact person details (if acting on behalf of an organisation)
- Contact Data: Recipient and sender address, phone numbers, and (if provided) email addresses
- Order Data: Products or services purchased, delivery and billing addresses, special delivery instructions, and order history
- Payment Data: Payment transaction details (processed securely via our payment processors; we do not store full card numbers)
- Correspondence: Records of communications (such as orders, complaints, feedback, or queries you send us)
- Technical Data: IP address, browser type and version, time zone setting, operating system, and platform (collected automatically via cookies for analytics and website functionality)
Lawful Basis for Processing
We process your data based on the following legal grounds:
- Contractual Necessity: Processing your data is necessary for entering into or performing our contract (e.g., fulfilling your flower order or arranging delivery).
- Legal Obligation: We may need to process your data to comply with applicable laws and regulations (for example, tax records retention).
- Legitimate Interests: We may use your data for legitimate business interests (such as improving our services, managing operations, or responding to your queries), provided those interests do not override your fundamental rights and freedoms.
- Consent: Where required by law (for example, for sending marketing communications), we will obtain your explicit consent before processing your data for these purposes. You can withdraw your consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing and delivering your flower order, including delivery to your specified recipient
- Contacting you regarding your order, queries, or issues
- Processing payments and refunds as necessary (securely via our payment processors)
- Maintaining our business and financial records
- Improving our website, products, and services
- Complying with legal duties and obligations
- With your consent, sending occasional marketing communications (you can unsubscribe anytime)
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which we collected it, including satisfying legal, accounting, and reporting requirements. Typically:
- Order and billing data is retained for at least 6 years as required by tax laws
- Communication and query records are retained for up to 2 years unless requested otherwise
- Payment information is not stored by us, as all card processing is completed via secure third-party providers
Once your data is no longer needed, it will be securely deleted or anonymised.
Data Processors and Third Parties
To provide our services, we may share your personal data with trusted third-party service providers, known as data processors. These may include:
- Payment processing companies to securely handle your card transactions
- Delivery and courier services to deliver your floral orders
- IT service providers who assist in website hosting, email communication, and maintenance
- Professional advisers, such as accountants or legal advisers, when necessary for compliance and business operations
We ensure all our third-party processors comply with GDPR requirements and only process your data on our instructions. We do not sell or share your personal information with third parties for their own marketing purposes.
Data Security
We take appropriate security measures to prevent unauthorised access, disclosure, alteration, or destruction of your personal data. These measures include secure storage, use of encrypted connections (SSL), and restricted access to authorised personnel only.
Your Rights
Under GDPR, you have a number of important rights regarding your personal data. These include:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of incorrect or incomplete data.
- Right to Erasure: You may request the deletion of your personal data where there is no good reason for us continuing to process it.
- Right to Restrict Processing: You may request that processing be restricted under certain circumstances.
- Right to Data Portability: You may request transfer of your personal data to another party in a structured, commonly-used, and machine-readable format.
- Right to Object: You may object to the processing of your data in certain situations, including direct marketing.
- Right to Withdraw Consent: If you gave your consent for specific processing, you can withdraw this consent at any time.
If you wish to exercise any of these rights, please contact us using our website's contact form or other advertised contact methods. We may need to verify your identity before acting on your request. We aim to respond within one month, in accordance with legal requirements.
Policy Updates
We may update this Privacy Policy from time to time to reflect legal or regulatory changes or improvements to our business. The updated version will be indicated by the "Last Updated" date at the end of the policy. We encourage you to review this policy periodically.
Contact and Complaints
If you have any questions about this Privacy Policy, or about how your personal data is handled, please contact us via the details provided on our website. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Last Updated: June 2024