Privacy Policy for Brent Cross Florist Orders
Introduction
At Brent Cross Florist, we are committed to safeguarding the privacy and security of our customers' personal information. This Privacy Policy explains the types of personal data we collect, the purposes and lawful bases for processing it, retention periods, the use of third-party processors, and the rights you have as a data subject under the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Brent Cross Florist, whether located in Brent Cross or neighbouring districts.
What Personal Data We Collect
During the order process, we may collect and process the following categories of personal data:
- Identity Information: This includes your full name, delivery recipient's name, and, if necessary, birthday or anniversary information for special orders.
- Contact Details: Such as email address, delivery address, billing address, and phone numbers if required to coordinate delivery.
- Order Details: The product(s) you purchase, order instructions, delivery date and time, and any gift messages you provide alongside your order.
- Payment Information: We may collect payment details such as your method of payment, but please note that all payments are processed through secure third-party providers, and Brent Cross Florist does not store your full payment card details.
- Correspondence: Any communications or complaints you send to us related to your order (e.g., via website forms or in writing).
- Technical and Usage Data: Data identifying how you interact with our website or ordering systems, including IP address, browser type, and cookies, for security and analytic purposes.
Lawful Basis for Processing
Your personal data is processed using one or more of the following lawful bases, as outlined by GDPR:
- Performance of Contract: Processing is necessary to fulfill your order and deliver products as per your request.
- Legal Obligation: We may need to process certain data to comply with UK legal and tax requirements.
- Legitimate Interests: Data may be used for internal administrative purposes, quality assurance, fraud prevention, and customer service improvements, provided these interests do not override your rights and freedoms.
- Consent: Where you have specifically agreed (for example, by subscribing to marketing updates), we may process your data for these purposes. Consent can be withdrawn at any time by contacting us.
How We Use Your Data
Brent Cross Florist uses your personal data to:
- Process and fulfill your flower and gift orders, including coordinating delivery logistics.
- Contact you regarding your order status, confirmation, or any issues fulfilling your requests.
- Handle customer service enquiries and resolve complaints.
- Comply with applicable laws and regulations, including tax and accounting requirements.
- Improve the quality and functionality of our website, services, and customer experience through anonymised analytics.
Retention of Personal Data
We retain your personal information only for as long as necessary to fulfill the purposes described in this policy, and as required by law. Typically:
- Order and transaction data is retained for a minimum period as mandated by UK accounting and tax regulations (usually up to 6 years from the date of transaction).
- Contact and correspondence data are retained as long as necessary to respond to your queries or to resolve disputes.
- Technical usage data may be retained for up to 26 months for analytic and security purposes.
Once data is no longer required, it will be securely deleted or anonymised.
Data Processors and Third Parties
Brent Cross Florist works with trusted third-party service providers who assist in the operation of our business. These processors may include:
- Payment gateway providers to process transactions securely.
- Delivery service partners who require delivery information to fulfill your order.
- IT and website hosting providers who support the technical infrastructure of our online services.
- Professional advisors (such as accountants) for legal or regulatory compliance.
All third-party processors are assessed to ensure they adhere to GDPR standards and only process your personal data based on our instructions. Data is not sold or shared with any external parties for their independent use or marketing. International transfers of your data, if any, will be subject to appropriate safeguards as required by law.
Your Rights Under the GDPR
Under the GDPR, you have specific rights regarding your personal data:
- Right of Access: You can request confirmation of whether we process your personal data and obtain a copy of such data.
- Right to Rectification: You may ask us to correct inaccurate or incomplete personal data.
- Right to Erasure ('Right to be Forgotten'): In certain circumstances, you can request that we delete your personal information.
- Right to Restrict Processing: You may request restrictions on the processing of your data under specific conditions.
- Right to Data Portability: You may obtain your data in a structured, machine-readable format or request that we transmit it directly to another organisation where technically feasible.
- Right to Object: You can object to the processing of your data for direct marketing purposes or where processing relies on our legitimate interests.
- Right to Withdraw Consent: If consent is the legal basis, you have a right to withdraw it at any time without affecting earlier lawful processing.
To exercise your rights, please contact us using the details provided on our website. Upon receiving a request, we may require identification to verify your identity.
Data Security
We are dedicated to keeping your data secure. We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. Our procedures are regularly reviewed, and those third-party processors with whom we work are contractually obligated to follow similar standards.
Policy Updates
Brent Cross Florist may update this Privacy Policy from time to time to reflect changes in regulations or business operations. The most recent version will always be available on our website, with the date of the latest revision included.
Contact Information
If you have questions regarding this Privacy Policy, your data rights, or how we process your information, please use the contact details provided on our official website to reach our Data Protection Officer. We are committed to addressing your privacy-related enquiries promptly and transparently.