Privacy Policy for Hornsey Florist Customers
Introduction
At Hornsey Florist, we are committed to protecting the privacy and security of our customers’ personal data. This Privacy Policy sets out how we collect, use, store, and safeguard your information in compliance with the General Data Protection Regulation (GDPR) and other relevant data protection laws. This policy applies to all individuals placing orders with Hornsey Florist from Hornsey and surrounding districts. By placing an order with us, you acknowledge and accept the practices described in this document.
What Data We Collect
When you engage with Hornsey Florist, we may collect, process, and store the following categories of personal data:
- Identification Details: Name, surname, and, where necessary, your title or preferred form of address.
- Contact Details: Delivery address, billing address, telephone number, and, if applicable, alternative recipient information.
- Transaction Data: Order history, purchase details, method of payment (note: payment card information is processed in accordance with industry standards and not stored by Hornsey Florist), and any relevant invoicing or delivery notes.
- Correspondence: Email communications, written feedback, or other interactions related to customer service or enquiries.
- Technical Data: Limited device and browser information, IP address, and website usage data, where collected for site security or improvement purposes.
Purposes and Lawful Basis for Processing
We process your personal data only when we have a lawful basis for doing so, as required under the GDPR. The table below summarises the primary purposes and the lawful grounds for processing:
- Order Fulfilment: To process, manage, and deliver your floral orders, including customer support and notification about your order. Lawful basis: Performance of a contract.
- Payments and Invoicing: To handle payments and complete transactions securely. Lawful basis: Performance of a contract; Legal obligation.
- Customer Service: To handle enquiries, complaints or requests, and provide support. Lawful basis: Legitimate interests; Performance of a contract.
- Marketing Communications: To send you updates about products, offers, or events (only if you have provided explicit consent). Lawful basis: Consent.
- Legal and Regulatory Compliance: To comply with obligations under the law, such as recordkeeping and fraud prevention. Lawful basis: Legal obligation.
Data Retention Policy
Hornsey Florist will retain your personal data only as long as necessary for the purposes for which it was collected. The specific retention periods are as follows:
- Order and Transaction Data: Retained for up to six years to comply with tax, accounting, and regulatory requirements.
- Customer Support Correspondence: Retained for up to two years after the issue has been resolved or the enquiry closed.
- Marketing Data: Data used for marketing purposes is kept until you withdraw your consent or request erasure.
- Technical Data: Retained for no longer than one year for website security and performance monitoring purposes.
Once the retention period has expired, your data will be securely deleted or anonymised unless a longer retention period is required or permitted by law.
Data Processors and Sharing Practices
We may share your personal data with selected third parties, known as data processors, for the purposes described above. These parties process data on our behalf and are strictly contractually obligated to protect your information. Examples of processors and third parties include:
- Payment Processing Providers: For secure transaction handling.
- Delivery Partners: For delivering orders to you or your recipients.
- IT System Providers: To support our order management, website hosting, and communications systems.
- Professional Advisors: Including accountants or legal representatives, as necessary for compliance and business operations.
Personal data is not transferred outside the European Economic Area (EEA) unless adequate safeguards are in place. Hornsey Florist does not sell or rent your personal data to any third parties for commercial purposes.
How We Protect Your Data
Your security is important to us. Appropriate technical and organisational measures are in place to protect your data against unauthorised access, loss, alteration, or destruction. These include secure data storage, encryption technologies where appropriate, strict access controls, and regular data protection training for staff.
Your Rights Under GDPR
As a data subject, you have a number of rights concerning your personal data. These rights include:
- Right of Access: You are entitled to request copies of your personal data we hold and to know how it is used.
- Right to Rectification: You can ask us to correct or update inaccurate or incomplete information.
- Right to Erasure: Also known as the 'right to be forgotten', you can request deletion of your data in certain circumstances.
- Right to Restrict Processing: You may ask us to limit the way your data is used in some situations.
- Right to Data Portability: You can request a copy of your information in a structured, commonly used, and machine-readable format, where applicable.
- Right to Object: You may object to certain types of processing, such as direct marketing, at any time.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw this consent at any time.
If you wish to exercise any of these rights, please contact us using our standard communication channels.
Policy Applicability and Updates
This Privacy Policy applies exclusively to all customers placing orders with Hornsey Florist from Hornsey and surrounding districts. Periodically, we may update this policy to reflect changes in our practices or to stay in line with legal requirements. The latest version will always be made available upon request and published through usual communication methods.
Contact and Further Information
For further information regarding this Privacy Policy, your data rights, or how we handle your personal data, please contact us directly. We will respond to all requests and questions in accordance with applicable data protection law and our internal procedures.