Belgravia Florist Privacy Policy
Introduction
This Privacy Policy explains how Belgravia Florist handles your personal data when you place an order with us from Belgravia and surrounding districts. Protecting your privacy is very important to us. We are committed to complying with the General Data Protection Regulation (GDPR) and ensuring your information remains safe and handled transparently.
Who This Policy Applies To
This policy applies to all individuals who place orders either directly with Belgravia Florist or through our platforms, specifically based in Belgravia and the neighbouring districts. It covers all personal data collected in the course of our interactions, both online and offline.
What Personal Data We Collect
When you place an order with Belgravia Florist, we may collect and process the following types of personal data:
- Contact Information: Your name, billing and delivery address, telephone number, and other contact details.
- Order Details: Information about the products you purchase, messages for gift cards, delivery instructions, and recipient’s contact details (if different).
- Payment Information: Payment card details (processed via secure third-party payment processors).
- Communication Data: Records of your correspondence with us via forms, telephone, or in-person discussions regarding your order or enquiry.
- Website Usage Data: Information collected via cookies and analytics tools, such as your IP address, device type, and browsing patterns on our site (see our separate Cookie Policy for more detail).
Lawful Basis for Processing Personal Data
Belgravia Florist always requires a legal reason to process your personal data. Depending on the context, we rely on one or more of the following lawful bases:
- Contractual Necessity: To process and fulfil your order, including delivery and payment.
- Legal Obligation: To meet legal and tax requirements, such as maintaining records for accounting purposes.
- Legitimate Interests: For our legitimate business interests, such as improving services, resolving disputes, or enforcing our terms, balanced against your rights and freedoms.
- Consent: In some cases, such as sending marketing communications, we rely on your prior consent. You have the right to withdraw your consent at any time.
How We Use Your Information
We use your personal data for the following purposes:
- Processing and delivering your florist order, including contacting you or the recipient as required.
- Communicating with you about your order or any issues that may arise.
- Handling payment transactions securely.
- Maintaining accurate records as required by law and for our own business purposes.
- Improving our products, services, and customer experience.
- Sending you marketing emails or promotions, if you have given explicit consent.
How Long We Retain Your Data
Your personal data is retained only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting obligations. Typically:
- Order and delivery data is retained for up to 7 years in line with UK tax laws and accounting regulations.
- Marketing data is retained until you withdraw your consent or opt-out from our communications.
- Website analytics data is retained as described in our Cookie Policy.
Data Sharing and Processors
We do not sell your personal data to third parties. However, we may share your information with the following service providers (data processors) strictly for the purposes outlined above:
- Payment Processors: Securely processing your card payments.
- Delivery Partners: Facilitating local deliveries to you or your recipient.
- IT and Website Providers: Supporting our website functionality, hosting, and data security.
- Professional Advisors: Accountants, auditors, or legal experts for compliance and business operations.
We ensure all data processors comply with GDPR and our contractual terms. Where processors are located outside the UK or EU, we use appropriate legal safeguards to ensure your data is protected to UK/EU standards.
Your Rights Under GDPR
As a valued customer, you have important rights regarding your personal data:
- Right of Access: Request a copy of your personal data we hold.
- Right to Rectification: Ask us to correct inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data, where applicable.
- Right to Restrict Processing: Limit how we use your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used format and transfer it elsewhere.
- Right to Object: Object to certain uses of your data, such as direct marketing.
- Right to Withdraw Consent: Withdraw your consent at any time for processing where consent is relied upon.
To exercise any of these rights, please contact us and specify your request. We will take reasonable steps to confirm your identity before acting on your request.
Data Security
We take data security seriously and apply appropriate technical and organizational measures to safeguard your personal information against accidental loss, unauthorized access, or disclosure. This includes secure payment gateways, encrypted data transfers, and regular reviews of our security policies.
Children's Privacy
Belgravia Florist does not knowingly collect or process data concerning anyone under the age of 16 without parental consent. If we learn that a child has provided us with personal data without verifiable consent, we will ensure its prompt deletion.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The most current version will always be available through our website or on request.
Contact and Complaints
If you have questions about this Privacy Policy, your data, or wish to make a complaint, please contact us using the details provided on our website. Should you remain dissatisfied with our response, you have the right to contact the UK Information Commissioner's Office for further assistance.