Privacy Policy for Grove Park Florist Customers
Introduction
This Privacy Policy explains how Grove Park Florist ("we," "us," "our") collects, uses, and protects the personal data of customers placing orders from Grove Park and surrounding districts. We are committed to ensuring the privacy and security of your information in compliance with the General Data Protection Regulation (GDPR) and all relevant data protection laws.
Scope of the Policy
This policy applies to all individuals who place orders with Grove Park Florist for delivery or collection in Grove Park and its neighbouring areas. It covers personal data collected via in-store interactions, our website, telephone orders, and any other method used to process customer orders.
What Personal Data We Collect
To process your order and provide our services, we may collect and process the following types of personal data:
- Contact Information: Name, address, phone number, delivery details, and, where provided, email address.
- Order Details: Items ordered, delivery instructions, messages on cards, date and time of the order.
- Payment Information: Transaction details (note: payment card data is securely processed by our payment providers and is not retained by us).
- Recipient Details: Name, address, and contact information of the recipient where applicable.
- Communication Records: Correspondence with us, including messages, calls, or feedback related to your order.
- Technical Information: IP address, device, and browsing activity relating to online orders (where applicable).
Lawful Basis for Processing
We only use your personal data when there is a valid legal basis to do so as outlined by the GDPR. The main lawful bases on which we rely are:
- Contractual Necessity: Processing is needed to fulfil your order or take steps prior to entering a contract at your request.
- Legitimate Interests: For purposes such as improving our services, handling enquiries, or supporting business operations, provided these interests are not overridden by your rights.
- Legal Obligations: Where we must process your data to comply with statutory or regulatory duties.
- Consent: For certain communications and marketing (if applicable), we rely on your explicit consent, which you may withdraw at any time.
How We Use Your Personal Data
Your personal data is used for the following purposes:
- Processing and delivering your order
- Contacting you regarding your order (e.g., confirmations, updates, and queries)
- Personalising your order (e.g., custom cards or arrangements)
- Improving our products and customer service
- Addressing enquiries, feedback, or complaints
- Meeting legal and regulatory obligations
- Internal record keeping and financial accounting
- With your permission, sending you updates or marketing communications
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Typically, personal data relating to orders will be kept for up to 7 years to comply with tax and record-keeping laws, after which it will be securely deleted or anonymised.
Data Processors and Third Parties
To provide our services and fulfil your orders, we may share your personal data with trusted third-party service providers ("data processors") who perform services on our behalf. These include:
- Payment processors securing your transactions
- Delivery partners ensuring successful order delivery
- IT service providers supporting our systems and website
- Professional advisors (such as accountants or auditors) as required by law
All such providers operate under contractual obligations to protect your data in accordance with the GDPR and may only process it for agreed purposes. We do not sell or rent your personal data to third parties. Data may be transferred outside the UK or EEA only where adequate safeguards are in place, in accordance with data protection laws.
Your Rights
As a customer, you are entitled to the following rights under the GDPR:
- Right to Access: Request a copy of your personal data we hold.
- Right to Rectification: Ask us to correct any inaccuracies in your personal data.
- Right to Erasure: Request the deletion of your data where there is no lawful reason for its continued processing.
- Right to Restrict Processing: Ask us to restrict the processing of your data in certain circumstances.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format.
- Right to Object: Object to our processing of your personal data when done on the basis of legitimate interests or direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on your consent.
- Right to Lodge a Complaint: Complain to the relevant data protection supervisory authority if you believe your data protection rights have been breached.
Data Security
We implement appropriate physical, technical, and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. Access to your data is restricted to authorised personnel and service providers who are also bound by confidentiality and data security obligations.
Policy Updates
We may review and update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We recommend you review this policy periodically to be informed about how we protect your information.
Contact and Further Information
If you have questions about this Privacy Policy or wish to exercise any of your data protection rights, please contact us using our usual business contact channels or visit our shop during opening hours. We are committed to helping you understand and control your personal information.