New Barnet Florist GDPR Privacy Policy
Introduction
Your privacy is important to New Barnet Florist. This Privacy Policy explains in clear terms how we collect, use, store, process, and protect personal data when you place orders with New Barnet Florist if you are located in or around New Barnet and surrounding districts. Our practices comply with the General Data Protection Regulation (GDPR) as it applies to all processing of customer data.
Scope of the Policy
This Privacy Policy applies to all customers placing orders with New Barnet Florist, whether online, in person, or through other communication means, in New Barnet and adjacent areas. It is relevant whenever you provide us with personal information in relation to a purchase or enquiry.
What Personal Data Do We Collect?
When you interact with New Barnet Florist, we may collect and process the following categories of personal data:
- Contact Information: Name, address, postcode, delivery address (if different), and telephone number.
- Order Details: Information about your orders, including flower selections, special instructions, messages attached to your order, and payment method used (note: we do not store card details, but payment providers may process them).
- Recipient Details: Name, delivery address, and contact information for the person receiving the order, where supplied by you.
- Communication Records: Details of any queries, correspondence, or complaints via phone, in person, or through our online forms.
- Transaction and Billing Information: Purchase history and billing address for invoicing and accounting purposes.
- Technical Data (where applicable): IP address, browser type, and other technical data collected via our website or ordering system, where lawful and relevant.
Lawful Basis for Processing Personal Data
New Barnet Florist processes your personal data under the GDPR when there is a lawful basis to do so. We rely primarily on the following lawful bases:
- Contractual Necessity: To fulfil orders, process payments, and deliver products to you or the recipient specified by you.
- Legitimate Interests: To pursue our legitimate business interests in providing services, maintaining records, improving our offerings, and communicating with you, balanced against your rights and freedoms.
- Legal Obligation: For compliance with applicable laws and regulations, such as accounting or tax requirements, and responding to requests from authorities when legally obliged.
- Consent: Where appropriate, such as for marketing communications, we will request your consent. You may withdraw this consent at any time.
How Do We Use Your Data?
Your personal data is used exclusively to:
- Process and manage your orders, communicate regarding deliveries and provide customer support.
- Deliver flowers or other goods to the specified recipient.
- Manage transactions and comply with legal and financial reporting requirements.
- Respond to customer service requests or enquiries.
- If consented, send you updates about our products and seasonal promotions.
How Long Do We Keep Your Data?
We retain your personal data only as long as necessary for the purposes for which it was collected, or as required by law. In general:
- Order and transaction records are retained for up to 7 years for accounting and legal purposes.
- Contact details used solely for marketing will be kept until you notify us to opt out or withdraw consent.
- Records related to complaints, queries, or communications will be retained as long as needed to resolve your issue satisfactorily and comply with relevant laws.
Who Processes Your Data?
To deliver our services, we may share or transfer your personal data with the following categories of data processors, in compliance with GDPR requirements and under suitable contracts to protect your data:
- Payment Service Providers: To securely process your payment transactions after you place orders. Card details are not stored by us.
- IT and System Support Providers: For the hosting, maintenance or support of our ordering system and website.
- Delivery Partners: For executing your order delivery to the intended recipients.
- Accounting and Audit Professionals: For legitimate business, tax, or auditing purposes as legally required.
Your data is never sold or shared with third parties for unrelated marketing purposes. All processors act strictly under our instructions.
International Data Transfers
Your personal data is stored and processed within the United Kingdom or European Economic Area (EEA). If in future we need to transfer data outside this area, we will ensure suitable safeguards, as required by law, are in place to protect your privacy rights.
Cookies and Website Data
If you use our website, technical data may be collected by cookies to improve your experience and for security purposes. We only use cookies that are necessary for the functioning of our website, analytics, or as required for certain services. You can adjust your browser settings to disable cookies at any time, which may affect parts of our website.
Your Rights Under GDPR
Under GDPR, you are entitled to the following rights over your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request corrections to inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data in certain circumstances.
- Right to Restrict Processing: Ask us to limit how we use your data in specific circumstances.
- Right to Object: Objection to certain uses of your data, including direct marketing.
- Right to Data Portability: Ask for your structured, commonly used data to be transferred to you or another provider.
- Right to Withdraw Consent: Where consent has been given, you have the right to withdraw it at any time.
To exercise any of these rights, you may contact us as described at the end of this policy. We may need to verify your identity before fulfilling your request and will respond within the timeframe required by law.
Security Measures
We take the security and confidentiality of your personal data seriously. Appropriate technical and organisational measures are in place to protect your data against accidental loss, misuse, unauthorised access, disclosure, alteration, or destruction. Only authorised personnel and processors with a legitimate need to access your data are permitted to do so.
Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in the law, our business, or processing practices. Any material changes will be clearly communicated according to legal requirements.
Contact and Complaints
If you have questions, concerns, or wish to exercise your GDPR rights in relation to your personal data held by New Barnet Florist, please contact us using the methods provided on our official communications channels or by visiting our shop in person. If you remain unsatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office or relevant authority.