Florist Holloway Privacy Policy
Privacy Policy Overview
This Privacy Policy describes how Florist Holloway ("we", "our", "us") collects, processes, stores, and protects your personal information. It also explains your rights under the UK General Data Protection Regulation (GDPR). This policy applies to all individuals placing orders with Florist Holloway from Holloway and surrounding districts. We are dedicated to ensuring your personal data is treated safely and securely.
What Data We Collect
When you place an order or contact Florist Holloway, we may collect the following types of personal data:
- Identity Data: Your name and, if applicable, the recipient’s name.
- Contact Data: Your address, delivery address, and postcode; your contact details such as phone number(s) and billing/delivery email addresses.
- Order Details: Purchase history and specific order information, including selected products, messages, and delivery instructions.
- Payment Data: Transaction details; please note we do not store credit or debit card numbers as payments are processed securely by third-party providers.
- Technical and Usage Data: When you use our website, information such as IP address, browser type, device ID, and website activity (such as orders placed and preferences).
- Correspondence: If you contact us, we may retain a record of communications, such as feedback, queries, or complaints.
Lawful Basis for Processing
Processing of your personal data will only occur where there is a lawful basis under GDPR. These are:
- Contractual Necessity: Most data processing occurs to fulfill our contract with you when you place an order (e.g., processing payments, arranging delivery, and communicating order status).
- Legal Obligation: We process certain data to comply with legal obligations (such as accounting or tax records).
- Legitimate Interests: On occasion, we may process your data for our legitimate business interests, for example, to improve customer service or prevent fraud. We always balance these interests against your rights and freedoms.
- Consent: Where we wish to send you marketing materials or request your feedback, we ask for your consent in advance. You can withdraw this consent at any time.
Purpose of Data Collection
We use your personal data for several purposes, including:
- Processing orders and arranging delivery of flowers and related products.
- Confirming and updating you about your order status.
- Customer support and responding to your queries or complaints.
- Improving our products, operations, and website based on customer interactions and feedback.
- Maintaining accurate business records and complying with legal and regulatory requirements.
- Sending marketing communications if you have provided consent.
Data Retention
We retain your personal information only as long as needed for the purposes stated in this policy or as required by law. Specific retention periods are as follows:
- Customer and Order Information: Retained for up to six years after your last order to fulfill our financial and legal record-keeping obligations.
- Communications: Retained for up to two years after last contact for customer service purposes.
- Marketing Consents: Retained until you withdraw your consent or request erasure.
Once the relevant retention period expires, your data will be securely deleted or anonymised.
Data Processors and Third Parties
To provide our service efficiently, we may share your information with trusted third-party processors strictly for the purposes outlined in this policy. These may include:
- Payment service providers for secure transaction processing.
- Courier and delivery partners to ensure your orders reach their destination.
- Technology providers supporting our website, communication systems, and data storage.
- Professional advisers such as accountants or legal teams bound by confidentiality agreements.
All processors are vetted and contractually required to process your data securely and in line with GDPR requirements. Data is not transferred outside the UK or EEA unless adequate safeguards are in place.
Your Rights under GDPR
You have several rights in relation to your personal information:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of incomplete or inaccurate data.
- Erasure: Request deletion of your data in certain circumstances (e.g., where no longer needed for purposes collected).
- Restriction: Request we temporarily or permanently stop processing all or part of your data.
- Portability: Request transfer of your data to you or a third party in a structured, commonly used format.
- Objection: Object to processing based on legitimate interests, direct marketing, or processing for research/statistical purposes.
- Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of previous processing.
To exercise any of these rights, please contact us using the channels provided on our official website or in your order documentation. We are committed to responding to your request within one month, in line with GDPR obligations.
Data Security
Florist Holloway uses appropriate technological and organisational measures to safeguard your personal information. Access is restricted to staff and processors who require it to deliver our services. Data is stored on secure servers and all payment information is transmitted and stored using encrypted protocols. We continually review our practices to ensure an ongoing level of security appropriate to the risk.
Policy Scope and Updates
This Privacy Policy applies to all Florist Holloway customers placing orders from Holloway and surrounding districts. Our policy is periodically reviewed, and we may make updates to reflect legal or business changes. The updated policy will be published on our website, and where appropriate, we will notify you directly.
Contact and Complaints
If you have any queries or concerns regarding your data privacy, please refer to the contact information found on our website. Should you remain dissatisfied, you may contact the UK Information Commissioner’s Office (ICO).