Florist Hackney Marshes Privacy Policy

Introduction

This Privacy Policy explains how Florist Hackney Marshes collects, processes, stores, and safeguards your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable UK privacy laws. This policy applies to all customers placing orders with Florist Hackney Marshes from Hackney Marshes and its surrounding districts. By using our services, you acknowledge and agree to the terms set out in this Privacy Policy.

What Data We Collect

When you place an order or interact with Florist Hackney Marshes, we collect the following categories of personal data:

  • Identification Details: Name, surname, and any recipient details you provide for delivery.
  • Contact Information: Address, delivery address, and postcode. We may also collect your email address for order confirmations and updates.
  • Order and Transaction Details: Details of products purchased, order notes (such as messages to be included with flowers), date and time of delivery, and payment confirmation details.
  • Payment Data: We process payment through secure third-party payment gateways. We do not directly store full card numbers or payment information.
  • Technical Data: IP address, browser type, device information, and how you interact with our website (e.g., cookies and analytics data). This is mainly for website security and improvement purposes.

Lawful Basis for Processing

Florist Hackney Marshes only processes your personal data where there is a lawful basis to do so, as outlined by the GDPR. Our main lawful bases include:

  • Performance of Contract: We need to process your personal data to fulfil an order you have placed, such as delivering flowers or processing payment.
  • Legal Obligations: Retaining certain information for tax or accounting purposes as required by law.
  • Legitimate Interests: We may process your data to improve our services, secure our website, respond to your queries, or provide customer support. We always balance these interests against your rights and freedoms.
  • Consent: Where you have given clear consent for us to process your personal data (e.g., if you sign up for optional communications).

How We Use Your Data

Your personal information is used solely for the following purposes:

  • To process and fulfil your flower orders, including arranging delivery and communicating with you regarding your order status.
  • To respond to your enquiries and provide customer support upon request.
  • To comply with legal and regulatory obligations.
  • To improve the functionality, security, and usability of our website and services.
  • To send you marketing communications only if you have actively opted in.

Data Retention

Florist Hackney Marshes retains your personal data only as long as necessary for the purposes outlined above. This typically means:

  • Order information is retained for up to six years to meet accounting and legal requirements.
  • If you create a customer account, we will retain your data until you instruct us to delete it, or until it becomes inactive for a substantial period.
  • Marketing data (where consent has been given) will be kept until you withdraw your consent or request deletion.
  • Technical and analytics information is usually anonymised or deleted after a reasonable period for website management.

Once data is no longer required, it is securely deleted or anonymised.

Processors and Third Parties

In certain circumstances, we use trusted third-party processors to help deliver our services. These may include:

  • Payment processors for secure handling of transactions
  • Delivery partners or couriers for fulfilling and delivering orders
  • Website hosting providers for operating and maintaining our website
  • IT service providers who help manage our digital and security infrastructure
  • Accounting or legal professionals for business compliance purposes
  • Analytics providers for website improvement (using aggregated or anonymised data where possible)

All third-party processors are required to comply with data protection standards and only process your data on our instructions. We do not sell or share your personal data for third-party marketing.

Data Security

We implement appropriate technical and organisational measures to protect your personal data from loss, misuse, access by unauthorised parties, or disclosure. These measures include data encryption, secure servers, restricted access controls, and staff training in data protection. While we strive to protect your data, no internet-based service is ever completely secure; we encourage you to use strong passwords and protect your information when placing orders online.

Your Rights

Under the GDPR and UK data protection laws, you have rights concerning your personal data. These include:

  • Access: You have the right to request a copy of your personal data we hold.
  • Rectification: If any information we have about you is inaccurate or incomplete, you may request corrections.
  • Erasure: You can ask us to delete your personal data under certain circumstances. This is sometimes called the 'right to be forgotten.'
  • Restriction: You can request the restriction of processing of your data if certain conditions apply.
  • Data Portability: You have the right to obtain and reuse your personal data for your own purposes across different services.
  • Objection: You may object to processing in cases where we process data on the grounds of legitimate interest or for direct marketing purposes.
  • Withdraw Consent: If you have given consent to any processing activity, you can withdraw it at any time.

To exercise any of these rights, a request can be submitted in writing. We may need to verify your identity before processing your request. Please note that certain legal or regulatory obligations may limit your ability to exercise some of these rights in specific contexts.

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or customer feedback. The latest version will be available on our website, and significant changes will be communicated accordingly. Please review the policy periodically to stay informed of how we protect your data.

Contact and Complaints

If you have questions or concerns about how we handle your personal data, wish to submit a rights request, or have a complaint, you can contact us as detailed on our website. You also have the right to lodge a complaint with the data protection supervisory authority if you believe your rights have been infringed.