Privacy Policy for Maida Vale Florist Orders
Introduction
This Privacy Policy outlines how Maida Vale Florist collects, uses, stores, and protects your personal data when you place orders for our floral products and services in Maida Vale and the surrounding districts. Our commitment is towards ensuring the privacy and security of your information in compliance with the General Data Protection Regulation (GDPR).
Scope of this Policy
This Privacy Policy applies to all customers who place orders with Maida Vale Florist from Maida Vale and neighbouring areas. By using our services and providing your personal data, you acknowledge and accept the practices described here.
Data We Collect
Maida Vale Florist collects different types of personal data to fulfil and process your flower orders effectively. We may collect the following information:
- Identity Data: Your full name, billing address, delivery address, and any recipient’s name for delivery purposes.
- Contact Data: Telephone numbers and other contact details required to communicate regarding your order.
- Order Details: Items ordered, your messages to recipients, and delivery preferences.
- Payment Information: Payment confirmation and transaction details. (Please note, card details are processed securely and are not stored by us.)
- Usage Data: Records of how you interact with our ordering system for customer service and quality assurance purposes.
Lawful Basis for Processing
The GDPR requires Maida Vale Florist to have a lawful basis for processing your data. The principal bases used are:
- Contractual Necessity: Most of the data we collect is necessary to process and fulfil your floral order, communicate with you about your order, and deliver your goods as requested.
- Legal Obligations: We may process and retain certain data to comply with relevant tax, accounting, and regulatory requirements.
- Legitimate Interests: We may use your data for quality assurance, to improve our services, prevent fraud, or ensure network and information security. We always balance our interests with your privacy rights.
- Consent: In circumstances where we require your explicit consent (such as for marketing communications), we will request and record your consent, and you can withdraw this at any time.
Data Retention
We will retain your personal data only as long as necessary to fulfil the purposes it was collected for, including the fulfilment of your order and any subsequent customer service needs. Typically, order-related data is retained for up to seven years to comply with legal and accounting requirements. If you request deletion and it is legally permissible, your data will be erased sooner.
Data Processors and Third Parties
Your personal data may be shared with trusted third parties, known as data processors, to enable us to deliver our services efficiently. These include:
- Payment Service Providers: To securely process payments for your orders.
- Courier and Delivery Companies: To deliver your flowers and gifts to specified addresses.
- IT and System Support Providers: For maintenance and support of our customer order and communication systems.
- Accountants and Regulatory Bodies: For fulfilling legal and regulatory obligations.
All third-party processors are contractually bound to comply with GDPR requirements and are only permitted to process your data as instructed by us, ensuring the ongoing protection and confidentiality of your information.
Your Rights Under GDPR
As a customer, you are entitled to a number of rights concerning your personal data. These include:
- Right of Access: You have the right to request access to your personal data and obtain a copy of the information we hold.
- Right to Rectification: If you believe that your data is incorrect or incomplete, you may request us to correct or update it.
- Right to Erasure ('Right to be Forgotten'): In certain circumstances, you have the right to request the deletion of your personal data.
- Right to Restrict Processing: You can request restriction on the processing of your personal data in specific situations.
- Right to Data Portability: Where applicable, you may ask for your data to be transmitted to you or another controller in a structured, commonly used, and machine-readable format.
- Right to Object: You are entitled to object to certain types of data processing, such as receiving marketing communications.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time. This does not affect processing carried out before withdrawal.
- Right to Lodge a Complaint: You have the right to file a complaint with the UK Information Commissioner's Office or other relevant supervisory authority if you believe your data has been mishandled.
Data Security
Maida Vale Florist employs robust technical and organisational measures to safeguard your personal data against unauthorised access, improper use, loss, or disclosure. We regularly review our policies, procedures, and security standards to ensure your information remains protected.
International Data Transfers
We do not typically transfer customer personal data outside the United Kingdom. If it becomes necessary to transfer your data abroad to fulfil your order or for support services, we will ensure that any such transfer is done in accordance with GDPR requirements and appropriate safeguards are in place.
Changes to this Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our data processing activities. The most recent version will always be available when placing orders with us, and we encourage you to review this page periodically.
Contacting Us About Your Data
If you have any questions, requests, or concerns about how Maida Vale Florist handles your personal data or wish to exercise any of your GDPR rights, please get in touch using the appropriate contact channels or by sending a written request to our business address.