Florist Cockfosters Privacy Policy
Introduction
This Privacy Policy outlines how Florist Cockfosters collects, processes, stores, and protects personal data relating to customers placing orders from Cockfosters and its surrounding districts. We are committed to safeguarding your privacy and complying with the UK General Data Protection Regulation (GDPR) as well as all other relevant data protection laws.
Scope of the Policy
This policy applies to all individuals who place orders with Florist Cockfosters, whether via our website, over the phone, or in person, and covers data collected during the course of these transactions. The geographical applicability comprises Cockfosters and neighbouring areas serviced by our shop.
What Data We Collect
We may collect and process the following categories of personal data when you interact with us, place an order, or use our services:
- Personal identification information: Name, surname, address, and postcode
- Contact details: Telephone number and, if provided, email address
- Order details: Gift message, flower selections, order instructions, and delivery recipient information (including their name, address, and contact number)
- Payment details: Payment card information is processed securely by our trusted payment provider, and we do not store full card data
- Communications: Any correspondence between you and Florist Cockfosters, including order confirmations and customer service interactions
- Website usage information: Technical data such as IP address, browser type, and cookies, to enhance security and improve your shopping experience
Lawful Basis for Data Processing
We process your personal data strictly in accordance with the lawful bases outlined in the GDPR:
- Contractual necessity: Most of the data we collect is required to fulfil your order and provide customer support, making it necessary for the performance of a contract with you
- Legal obligations: We may process data where necessary to comply with UK law, such as keeping records for tax purposes
- Legitimate interests: In certain cases, we may process data to improve our services, ensure website security, or communicate important information relevant to your purchase, provided these interests do not override your rights and freedoms
- Consent: We will only use your data for direct marketing or optional features (such as newsletters) if you have explicitly granted your consent. You have the right to withdraw your consent at any time.
How We Use Your Data
Your data is used for the following purposes:
- Processing and delivering your orders
- Communicating order status, delivery information, or responding to queries
- Accounting, record-keeping, and legitimate business operations
- Improving our services and personalising your experience
- Ensuring the security and integrity of our website and customer data
- Complying with legal and regulatory requirements
Data Retention
We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically, we hold order information for up to six years to comply with financial record-keeping obligations. Data used for marketing is retained until you opt out or withdraw consent. Additional retention periods may apply where required by law.
Personal Data Processors
We may share your personal data with carefully selected third-party service providers (data processors) who assist us in delivering our services. These may include:
- Payment processors for secure transaction handling
- Delivery partners responsible for fulfilling floral deliveries
- Website hosting providers and IT support partners
- Professional advisors, such as accountants or legal counsel, where necessary
All data processors are contractually obliged to comply with GDPR and handle your data only as instructed by us, ensuring its security and confidentiality.
International Data Transfers
Your personal data is generally processed within the UK or European Economic Area (EEA). Should there be a need to transfer your data outside these regions, we will ensure appropriate safeguards are in place to protect your information, in accordance with applicable data protection laws.
Your Rights Under GDPR
You have several rights concerning your personal data under the GDPR. These include:
- The right to access: You can request a copy of the personal data we hold about you
- The right to rectification: You can ask us to correct inaccurate or incomplete data
- The right to erasure: In certain circumstances, you can request the deletion of your data
- The right to restrict processing: You can ask us to limit the way we use your information
- The right to data portability: Where applicable, you can request your data in a machine-readable format
- The right to object: You can object to processing based on legitimate interests, including direct marketing
- The right to withdraw consent: Where processing is based on consent, you may withdraw it at any time
- The right to lodge a complaint: You also have the right to complain to a supervisory authority if you believe your data rights are not being upheld
Data Security
We take your data security seriously. All personal data is stored securely and protected using appropriate technical and organisational measures to prevent unauthorised access, disclosure, alteration, or destruction. Our staff are trained on data protection responsibilities and access to your data is restricted to those who require it to fulfil their duties.
Updates to this Policy
We regularly review and update this Privacy Policy to reflect changes in our practices, legal requirements, or for other operational reasons. Any significant updates will be clearly communicated to customers as appropriate.
Contact and Further Information
If you have any questions about this policy, how we handle your personal data, or wish to exercise any of your rights, you are encouraged to contact us by the methods provided on our website or at our premises in Cockfosters.