Tulse Hill Florist Privacy Policy
Introduction
This Privacy Policy describes how Tulse Hill Florist collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Tulse Hill Florist from Tulse Hill and surrounding districts. We are committed to safeguarding your privacy and ensuring transparency regarding your personal data.
What Data We Collect
When you place an order with Tulse Hill Florist, we collect the following categories of personal data:
- Identification Information: Full name, billing address, and delivery address.
- Contact Details: Phone number and, when provided, email address.
- Order Details: Product selection, special instructions, card messages, and order history.
- Payment Data: Information needed to process your payment (handled securely by our payment processors; Tulse Hill Florist does not store your full card details).
- Website Usage Data: IP address, browser type, and cookies, for website optimization and security.
Lawful Basis for Processing
We process your personal data based on the following lawful bases under GDPR:
- Contractual Necessity: To process and fulfill your order, including contacting you about your purchase or its delivery.
- Legitimate Interests: To improve our services, prevent fraud, maintain network security, and respond to your queries.
- Legal Obligations: To comply with tax, accounting, or regulatory requirements.
- Consent: For marketing communications, when you explicitly opt in. You can withdraw consent at any time.
How We Use Your Data
Your data is used for the following purposes:
- Processing orders and arranging delivery.
- Providing customer support and responding to enquiries.
- Sending order confirmations and updates.
- Improving our website and services based on usage data.
- Fulfilling mandatory record-keeping or legal requirements.
- Sending marketing updates if you have provided explicit consent.
Retention of Your Data
We retain your personal data for as long as necessary to fulfill the purposes for which it was collected, including meeting legal, accounting, or reporting requirements. Specifically:
- Order and contact information are retained for seven years to comply with tax and legal obligations.
- Website usage data and cookies are retained for up to two years for site security and analytics purposes.
- Marketing preferences are retained until you withdraw consent or unsubscribe.
Once personal data is no longer required, it is securely deleted or anonymised.
Processors and Data Sharing
To fulfill your order and operate our services, we may share your personal data with trusted third-party processors, who process your data on our instructions only and subject to strict data protection and confidentiality agreements. These may include:
- Payment Processors: Securely handling your payment transactions.
- Delivery Partners: Enabling the delivery of your order.
- IT Service Providers: Supporting our website and electronic communications.
- Professional Advisors: Such as accountants or legal consultants, when required for regulatory compliance.
We do not sell or rent your personal data to third parties. Any sharing is strictly for operational purposes, and all processors are required to adhere to GDPR standards.
User Rights Under GDPR
You have several rights under GDPR regarding your personal data:
- Right of Access: You can request confirmation of what personal data we hold about you and access to that data.
- Right to Rectification: You have the right to request correction of inaccurate or incomplete data.
- Right to Erasure: You may request deletion of your personal data, subject to any legal obligations that require us to retain certain information.
- Right to Restrict Processing: You can ask us to suspend the use of your personal data in specific circumstances.
- Right to Data Portability: Where applicable, you can request your data in a structured, commonly used, machine-readable format to transfer to another provider.
- Right to Object: You can object to the processing of your data where we rely on legitimate interests or where your data is being used for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw it at any time. Doing so will not affect the lawfulness of processing before withdrawal.
All requests regarding your rights are handled promptly and in accordance with legal timelines.
Data Security
We implement appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Our measures include secure servers, encryption of payment transactions, access controls, and staff training in data privacy.
International Data Transfers
Your data is stored primarily within the United Kingdom and European Economic Area (EEA). If data must be transferred outside the EEA, we ensure adequate safeguards are in place as required by GDPR.
Policy Updates
This Privacy Policy may be updated occasionally to reflect changes in our practices or for legal reasons. Significant changes will be communicated, and the most recent version will always be available upon request.
Contact and Concerns
If you have questions or concerns regarding the handling of your personal data at Tulse Hill Florist, or if you wish to exercise any of your GDPR rights, please contact us in writing or by visiting our store. You also have the right to lodge a complaint with the UK Information Commissioner’s Office if you are dissatisfied with our response.