Raynes Park Florist Privacy Policy
Introduction
At Raynes Park Florist, we are dedicated to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the UK General Data Protection Regulation (GDPR). The policy applies to all customers placing orders with Raynes Park Florist from Raynes Park and the surrounding districts.
What Data We Collect
When you place an order with us or interact with our services, we may collect the following types of personal data:
- Full Name
- Contact Information (such as address and telephone number)
- Email address
- Order Details (such as recipient name, delivery address, message for the recipient, specific product selections, and delivery instructions)
- Payment Information (such as the last four digits of your credit or debit card, payment method, and transaction reference)
- Communication Records (details of any correspondence via online forms, or customer feedback)
We may also collect technical information about your visit to our website, such as your IP address, browser type and version, time zone setting, browser plug-in types, operating system, and platform.
Lawful Basis for Processing
We process your personal data only when we have a lawful basis to do so under GDPR. The lawful bases on which we rely include:
- Contractual Necessity: To process and fulfill your floral order, arrange delivery, and communicate about your purchase.
- Legal Obligations: To comply with applicable laws and regulations governing business and financial records.
- Legitimate Interests: To communicate with you regarding your order, seek feedback, improve our services, and where required for fraud prevention or IT security.
- Consent: When you sign up for marketing communications or newsletters, we will obtain your explicit consent before sending promotional material. You can withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing and fulfilling your orders
- Delivering products to the correct address and recipient
- Providing customer service and responding to your queries
- Managing payments and preventing fraud
- Keeping internal records for financial, legal, and regulatory purposes
- Improving our services based on your feedback and usage patterns
- Sending you marketing communications, only where you have given consent
Data Retention
We retain your personal data for as long as necessary to fulfil the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements. In general:
- Order and delivery information is retained for up to 7 years, in line with accounting and tax regulations.
- Communication records may be retained for up to 2 years to resolve queries or disputes.
- Data used for marketing purposes will be kept until you withdraw your consent or request deletion.
Once your data is no longer required, it will be securely deleted or anonymised.
Data Processors and Third Parties
We may use third-party service providers to assist with operating our business and providing our services. Examples of trusted processors include:
- Payment processing companies for facilitating your transactions
- IT and web hosting providers for maintaining the security and functionality of our website
- Delivery and courier services to ensure your orders reach their destination
- Customer relationship management providers for handling customer service queries
All third-party providers are required to comply with the GDPR, treat your information confidentially, and only use it for the specific services they perform on our behalf. We do not sell or rent your personal data to third parties.
Your Rights as a Data Subject
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request corrections to any inaccurate or incomplete information.
- Right to Erasure: You can request deletion of your data when it is no longer necessary for us to retain it, subject to legal restrictions.
- Right to Restrict Processing: You may request us to restrict the processing of your personal data under certain circumstances.
- Right to Data Portability: You can request that your data be provided to you in a commonly used electronic format.
- Right to Object: You may object to processing your data for direct marketing or legitimate interests.
- Right to Withdraw Consent: Where processing relies on your consent, you may withdraw it at any time.
To exercise any of these rights, please contact us using the details provided on our website. We will respond to your request within one month, subject to any legal obligations or exceptions.
Data Security
Raynes Park Florist takes your data security seriously. We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. Access to your data is limited only to those employees, agents, and processors who need it to carry out their duties, and all such parties are bound by confidentiality obligations.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or for other reasons. Any changes will be effective when published on our website. We encourage you to review this policy periodically to stay informed about how we are protecting your information.
Contacting Us
If you have any questions or concerns about this policy or how we use your personal data, please consult our website for ways to get in touch with us. We are committed to resolving any concerns in a timely and transparent manner.