Privacy Policy for Florist Elephant and Castle Customers
Introduction
Florist Elephant and Castle is committed to protecting and respecting your privacy. This Privacy Policy outlines how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Florist Elephant and Castle in Elephant and Castle and the surrounding districts.
What Data We Collect
When you interact with Florist Elephant and Castle, we may collect the following categories of personal data:
- Identity Data: Name, title, and any information you provide for identification.
- Contact Data: Address, postcode, delivery address, billing address, and other contact details, excluding email or phone numbers as per the exclusions in this policy.
- Order Data: Details of your orders, delivery instructions, order history, and payment information (but not full card details).
- Transaction Data: Records of payments to and from you.
- Technical Data: Device information, IP address, browser type, and website usage (if you use our website).
- Correspondence: Any written communications between you and Florist Elephant and Castle regarding your order or our services.
Lawful Basis for Processing
We only collect and process your personal data when we have a valid legal basis under GDPR. These are:
- Contractual Necessity: To fulfill and deliver your order, process payments, or provide customer support relating to your purchase.
- Legal Obligation: To comply with laws and regulations, including tax and accounting obligations.
- Legitimate Interests: To improve our services, ensure smooth deliveries, and protect the security of our operations.
- Consent: On certain occasions, for example where we wish to use your data for optional marketing or surveys, we will ask for your explicit consent, which you can withdraw at any time.
Purpose of Data Collection and Use
Your data is collected and used for the following purposes:
- To process, confirm, and deliver your flower orders.
- To manage payments, fees, and charges.
- To communicate information relevant to your current or future orders.
- To respond to your enquiries, requests, or complaints.
- To keep appropriate business records and comply with legal responsibilities.
- To analyse trends and improve our customer service and business operations.
Retention of Your Personal Data
We only retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
Typically, order and transaction data will be retained for up to six years after your last interaction with Florist Elephant and Castle, unless a longer retention is required by law. After this period, your data will be securely deleted or anonymised.
Our Data Processors
To ensure efficient business operations, we sometimes share your data with trusted third-party service providers ("processors") who perform functions on our behalf. These processors include:
- Payment service providers for processing card payments.
- Delivery partners or couriers for fulfilling orders.
- IT support providers who maintain our digital infrastructure and ensure data security.
- Professional advisers such as accountants or legal consultants required for compliance and regulatory purposes.
All processors acting on our behalf are subject to contractual obligations to ensure your data remains secure and is processed strictly in accordance with this Privacy Policy and applicable data protection laws.
User Rights Under GDPR
Under the GDPR, you have rights regarding your personal data held by Florist Elephant and Castle:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may ask us to correct incomplete or inaccurate information.
- Right to Erasure: You may request deletion of your personal data (subject to any legal obligations preventing us from doing so).
- Right to Restrict Processing: You may request a restriction of data processing under specific circumstances.
- Right to Data Portability: You may request to receive your personal data in a structured, commonly used format and transmit it to a different controller.
- Right to Object: You may object to our processing of your data based on legitimate interests, or for direct marketing purposes (where consent has previously been given).
- Right to Withdraw Consent: If we process your data based on consent, you may withdraw that consent at any time.
- Right to Lodge a Complaint: You may lodge a complaint with a supervisory authority if you believe your rights have been infringed.
To exercise any of your rights, you should contact us directly and we will respond in accordance with GDPR requirements.
Data Security
We implement suitable technical and organisational security measures to safeguard your personal data from accidental loss, destruction, unauthorised access, disclosure, or alteration. Our staff and processors are trained to understand the importance of protecting personal data according to GDPR standards.
While we strive to protect your information, please note that the transmission of information via the internet is not completely secure and is at your own risk.
International Data Transfers
Your personal data is generally processed within the United Kingdom and the European Economic Area. Should it be necessary to transfer data outside these locations, we will ensure it is protected to a standard that is comparable to the requirements of the GDPR.
Policy Updates
Florist Elephant and Castle may update this Privacy Policy from time to time to reflect changes in law or our practices. We encourage users to review this policy periodically to stay informed about how we protect and use your information.
Contact and Further Information
If you have any queries or requests regarding your personal data or this Privacy Policy, please contact us using the methods described on our official platforms. We are committed to resolving any concerns you may have.