Winchmore Hill Florist Privacy Policy
Introduction
This Privacy Policy explains how Winchmore Hill Florist (“we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you place an order with us. This policy applies to all customers ordering with Winchmore Hill Florist, whether residing in Winchmore Hill or the surrounding districts, and outlines our commitment to your privacy under the General Data Protection Regulation (GDPR).
What Data We Collect
In the course of providing our florist services, we collect the following categories of personal data from our customers:
- Identification Information: Your full name
- Contact Information: Address, delivery address (if different), and, if necessary, telephone number
- Transaction Details: Details of the products you order, payment method, and delivery instructions
- Payment Details: We process payment securely via third-party payment processors. We do not retain full credit or debit card details
- Correspondence: Any communication between you and us regarding your orders, feedback, or queries
- Recipient Information: If you are sending flowers to another person, we may collect their name, address, and (if required) contact number for delivery purposes
We do not intentionally collect special categories of personal data (such as health or religious information) or data relating to persons under 18 years of age. Please only provide personal information that is necessary to fulfill your order.
Lawful Basis for Processing Your Personal Data
In accordance with GDPR, Winchmore Hill Florist processes your personal data under the following lawful bases:
- Contractual Necessity: Processing your data is necessary for us to fulfill our contract with you, such as processing and delivering your orders
- Legal Obligation: We may process your data to comply with legal requirements, including accounting and tax purposes
- Legitimate Interests: We may use your data to improve our services and offer customer support, provided such processing does not override your rights
- Consent: If you have opted in, we may send you special offers or marketing communications. You can withdraw your consent at any time
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements. Typically:
- Order and transaction data are retained for up to 7 years to comply with tax and financial regulations
- Customer correspondence may be retained for up to 2 years from the last point of contact, to provide ongoing support and resolve any queries
- Marketing preferences will be retained until you opt out or withdraw your consent
After the retention period expires, your personal data will be securely deleted or anonymised.
Data Processors and Third Parties
We use select processors to ensure the safe and efficient operation of our business. These processors act on our instructions and are GDPR-compliant. Third parties used may include:
- Payment Service Providers: To securely process card and online payments
- Delivery Partners: For efficient, secure delivery of your order
- IT Service Providers: Such as website hosting, security, and communication platforms
- Accounting Services: For compliance with tax and audit requirements
We do not sell or share your personal information with third parties for their own marketing purposes. Personal data is only shared when necessary to fulfill your order or comply with legal obligations.
Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of Access: You are entitled to request access to the personal information we hold about you
- Right to Rectification: You can ask us to correct inaccurate or incomplete personal data
- Right to Erasure: You may request deletion of your data where it is no longer necessary, or if processing was based on consent and you withdraw that consent
- Right to Restrict Processing: You can request restriction of processing in certain situations (for example, while we review a correction request)
- Right to Data Portability: You may ask us to provide your data in a structured, commonly used electronic format for transfer to another provider
- Right to Object: You can object to processing where we base it on legitimate interests or direct marketing
- Right to Withdraw Consent: You can withdraw your consent at any time where consent is the basis for processing. This does not affect any processing already undertaken
- Right to Lodge a Complaint: You may lodge a complaint with a supervisory authority if you believe your data has not been handled lawfully
If you wish to exercise any of these rights, please contact us using the details provided on our website.
Security of Your Personal Data
We take the security of your information seriously. Appropriate technical and organisational measures are in place to prevent misuse, loss, unauthorized access, disclosure, or alteration of your personal data. All processors and service providers are contractually required to adhere to similar standards of data protection. Access to your data is restricted to authorized personnel only, and is protected with both physical and digital safeguards.
Policy Scope and Updates
This Privacy Policy applies to all customers who place orders with Winchmore Hill Florist in Winchmore Hill and surrounding districts, whether orders are placed online, by telephone, or in person. We may update this Privacy Policy from time to time to reflect changes in legal requirements or business practices. Updated versions will be made available on our website with a new revision date.
Contact and Further Information
If you have any questions regarding this Privacy Policy or how your personal data is processed, or if you wish to make a request relating to your rights, please refer to our contact information listed on our official website. We are committed to addressing your queries and upholding your data rights under GDPR.