Florist Lewisham Privacy Policy
Scope and Purpose
This Privacy Policy explains how Florist Lewisham (“we”, “our”, or “us”) collects, uses, stores, and protects your personal data when you place orders for flowers and related services via our channels. This policy applies to all customers placing Florist Lewisham orders from Lewisham and surrounding districts. We are committed to processing your personal data transparently, ethically, and in line with the General Data Protection Regulation (GDPR).
What Data We Collect
When you place an order or interact with Florist Lewisham, we collect and process personal data as follows:
- Identity Data: Name, title, and where applicable, your recipient’s name for delivery purposes.
- Contact Data: Billing address, delivery address, phone numbers (where shared), and in some cases, email address for order confirmations and communications.
- Order Data: Details of the products you order, delivery instructions, card messages, and any notes you provide regarding your purchase.
- Payment Data: Transaction records, payment method used, and amounts paid. We do not store or process full card or banking data ourselves; see Processors below.
- Communication Data: Records of communications you may have with our staff, customer service notes, and feedback or complaints if received.
- Technical Data: When using our website, we may collect technical information, such as IP address, browser type, and cookies or analytics data when applicable. Please refer to our separate Cookie Policy for more detail on this aspect.
Lawful Bases for Processing
Under GDPR, we must have a valid legal basis for each type of data processing. Florist Lewisham relies on the following grounds:
- Contractual Necessity: Much of your data is collected in order to fulfil your order and for us to enter into or perform our contract with you (Article 6(1)(b) GDPR). This includes name, address, and order details.
- Legal Obligation: We retain records of transactions to meet legal requirements regarding tax, accounting, and fraud prevention (Article 6(1)(c) GDPR).
- Legitimate Interests: We may use your order and contact details to improve our service, manage our relationship with you, or handle feedback/complaints, provided such use does not override your data protection interests (Article 6(1)(f) GDPR).
- Consent: For marketing communications (such as newsletters or offers), we only use your data where you have actively opted in. You have the right to withdraw your consent at any time.
How We Use Your Data
Your data is used for the following purposes:
- Processing and delivering your orders (including delivery tracking where relevant)
- Managing payments and refunds
- Communicating with you regarding your order, or responding to queries
- Fulfilling our legal and accounting obligations
- Improving the quality of our service based on customer feedback and analytics
- Sending updates or marketing (where you have opted in)
Retention of Personal Data
We only retain personal data for as long as necessary to fulfil the purposes set out in this policy or to comply with legal, tax, or regulatory requirements. Broadly:
- Order and transaction records: retained for up to six (6) years in line with statutory requirements for business and tax records.
- Customer communications and complaints: usually retained for up to two (2) years, unless a longer retention period is needed due to an ongoing dispute or legal process.
- Data provided for marketing purposes: retained until you withdraw your consent or unsubscribe.
Processors and Third Parties
Florist Lewisham uses data processors to support essential operations, all of whom are subject to GDPR obligations by contract. These processors may include:
- Payment Service Providers: Secure card and transaction processing platforms who process your payment information on our behalf.
- Delivery Partners: Trusted couriers or in-house drivers, who are supplied with necessary contact and delivery address details to complete your delivery.
- Technology Providers: Providers of website, hosting, or customer management systems that assist in securely storing or transmitting your data.
- Professional Advisors: Legal, tax, or audit professionals who may need to review data in some circumstances as required by law.
Florist Lewisham does not sell your personal data to any third parties. Data shared with processors is always minimised to what is strictly necessary. Where transfer outside the UK/EEA is required, we ensure such transfers are protected by appropriate safeguards.
Your Data Rights
Under GDPR, you have the following rights regarding your personal information:
- The right to access– Request a copy of your personal data held by us.
- The right to rectification– Ask that we correct or update incomplete or inaccurate information.
- The right to erasure– Request deletion of your personal data in certain circumstances (“the right to be forgotten”).
- The right to restrict processing– Ask us to suspend processing where you believe data is inaccurate or there is a dispute about lawful processing.
- The right to object to processing based on legitimate interests or for direct marketing purposes.
- The right to data portability– Where applicable, request a digital copy of your data for your own use or to transfer to another provider.
- The right to withdraw consent– Where processing is based on your consent, you may withdraw this at any time; this does not affect any processing undertaken before withdrawal.
If you wish to exercise any of these rights or have concerns about how Florist Lewisham processes your data, please contact us using the contact details published on our website or in your order confirmation.
Security and Safeguarding
We take appropriate technical and organisational measures to protect your personal information from unauthorised access, accidental loss, destruction, or disclosure. These measures include secure storage systems, restricted access to data, and regular staff training on data protection and privacy practices.
Children’s Privacy
Florist Lewisham does not knowingly collect or process data relating to children. Our services are not directed at children under the age of 16. If we become aware personal data of a child has unintentionally been collected, we will take steps to securely delete it as soon as practicable.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The date of the latest revision will always be indicated at the end of this document. We encourage customers to periodically review this policy when placing orders.
Contact and Complaints
If you have questions about this policy, your privacy, or if you wish to make a complaint, please reach out using the standard contact details provided on our website or in your order documentation. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) or your local data protection authority.
Last updated: June 2024