Gidea Park Flowers Privacy Policy
Introduction
This Privacy Policy explains how Gidea Park Flowers ('we', 'our', 'us') collects, uses, stores, and protects your personal information in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Gidea Park Flowers from Gidea Park and the surrounding districts.
What Data We Collect
We collect the following categories of personal data when you interact with Gidea Park Flowers, whether you place an order through our website, by phone, or in person:
- Contact Information: Such as your name, delivery address, and contact details.
- Recipient Details: If you send flowers to others, we collect the recipient’s name, address, and, if applicable, their phone number.
- Order Information: Including order details, purchase history, and payment status.
- Payment Details: Such as partial card information, depending on the payment processor specifics (full card details are not stored by us).
- Communication Records: Including emails, messages, or phone call records relating to customer service queries or order updates.
- Technical Data: Such as IP address, browser type, device information, and cookies, when you visit our website.
Lawful Basis for Data Processing
Our collection and use of your personal information is grounded in one or more of the following lawful bases under the GDPR:
- Contract Performance: We need your data to process and fulfil your orders and provide customer service.
- Legal Obligations: We may process your information to comply with legal and regulatory requirements, such as tax or accounting obligations.
- Legitimate Interests: To conduct and manage our business, improve services, prevent fraud, or ensure network and information security, except where such interests are overridden by your interests or fundamental rights and freedoms.
- Consent: Where applicable, for activities such as sending marketing communications if you have opted in. You can withdraw your consent at any time.
Data Retention
We retain your personal data only for as long as necessary for the purposes outlined in this Policy, including satisfying any legal, accounting, or reporting requirements.
- Order and contact information is typically retained for up to 7 years to meet legal and accounting obligations.
- Marketing consent records are kept until you withdraw your consent or for as long as required by law, whichever is shorter.
- Technical and cookie data are stored in line with industry standards and our own cookie policies, usually up to 2 years.
Data Processors and Third Parties
We may share your personal information with trusted third-party data processors who assist us in providing our services, such as payment processors, IT service providers, delivery companies, and accounting services. These processors are engaged under contract and are obliged to safeguard your information, comply with GDPR requirements, and act only on our instructions.
We do not sell, rent, or lease your personal data to third parties. We will only disclose your data to regulatory authorities or law enforcement if required by law.
How We Protect Your Data
We implement appropriate technical and organizational security measures to ensure a high level of protection for your personal data against unauthorized access, accidental loss, destruction, or disclosure. Our measures include access controls, encryption, secure payment gateways, staff training, and regular review of our security practices.
Your Rights under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- The right to access: Obtain confirmation as to whether we process your personal data and request a copy of the information we hold about you.
- The right to rectification: Request correction of any inaccurate or incomplete data.
- The right to erasure ("right to be forgotten"): Ask us to delete or remove your data, subject to certain legal exemptions.
- The right to restrict processing: Request restriction of our processing of your information in certain circumstances.
- The right to data portability: Receive your data in a structured, commonly used, and machine-readable format and have the right to transmit this data to another controller.
- The right to object: Object to our use of your data for direct marketing or processing based on legitimate interests.
- The right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- The right to complain to a supervisory authority: If you’re dissatisfied with how we handle your data, you can file a complaint with your local data protection authority.
Children’s Privacy
Our services are not intended for use by children under the age of 16, and we do not knowingly collect personal data from children. If you believe we have inadvertently collected such information, please contact us, and we will take steps to delete it promptly.
International Transfers
Your data is stored and processed within the United Kingdom or the European Economic Area (EEA). In rare cases where processors operate outside these regions, we will ensure appropriate safeguards are in place in compliance with GDPR standards.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or our services. The latest version will always be available in-store and on our website. We encourage customers to review this policy regularly.
Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us by using the contact methods provided on our website or in-store. We aim to respond promptly and support you in managing your personal data.