Florist St Mary Cray Privacy Policy
Introduction
This Privacy Policy explains how Florist St Mary Cray ("we", "our" or "us") collects, processes, stores, and protects the personal data of our customers. This policy applies to all customers placing orders with Florist St Mary Cray from St Mary Cray and its surrounding districts. We are committed to safeguarding your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR) and relevant UK data protection laws.
What Data We Collect
When you place an order or interact with our services, we may collect the following types of personal data:
- Contact Details: Your name, address, telephone number, and any alternative contact numbers you provide.
- Recipient Details: Name, delivery address, phone number (if provided) for the intended recipient of your order.
- Transaction Information: Details of your order, billing address, and payment method used (note: we do not store full card information, only transaction references and partial details as required for processing and compliance).
- Communications: Records of your correspondence with us, including order confirmations, enquiries, and messages.
- Technical Data: IP address, browser type, access times, and related website usage data, collected through cookies or similar technologies to help manage and improve our website.
Lawful Basis for Processing
We process your personal data on the following lawful bases, as permitted by GDPR:
- Contractual Necessity: To process and fulfil your order, respond to your enquiries, and provide you with customer support.
- Legal Obligations: To comply with accounting, tax, and regulatory obligations as required by law.
- Legitimate Interests: To improve our products and services, facilitate customer service, and communicate with you about existing orders. Where appropriate, we may use your details for limited direct marketing purposes, provided this does not override your rights.
- Consent: When you actively opt in to receive marketing communications, we rely on your consent. You can withdraw this consent at any time.
How We Use Your Data
Your data is used to:
- Process and deliver your orders correctly and on time
- Contact you about your order or to clarify instructions
- Process payments and prevent fraud
- Comply with our legal and regulatory obligations
- Respond to your enquiries, requests, or complaints
- Enhance and improve our website and customer service
- Send you marketing communications if you have consented to them
Data Retention
We retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Generally, the retention periods are:
- Order and transaction records: Kept for a minimum of 6 years to comply with tax and accounting laws.
- Marketing data: Retained until you withdraw your consent or opt out of communications.
- Correspondence and enquiry records: Retained for no longer than 2 years after your last contact with us unless required for legal reasons.
When we no longer need your data, it will be securely deleted or anonymised.
Processors and Data Sharing
We may share your personal data with trusted third-party service providers who act as data processors on our behalf, such as:
- Payment processors to approve and complete your transactions
- Delivery partners working with us to fulfil and deliver orders
- IT service providers for our website, communications, and data storage
- Professional advisers, such as accountants or legal consultants, as required
All third parties are contractually obligated to safeguard your data, act only on our instructions, and comply with GDPR. We do not sell, rent, or trade your personal data to any third parties for marketing purposes.
On rare occasions, we may disclose your information to authorities as required by law, or for fraud prevention or similar purposes.
Your Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Access: You can request a copy of your personal data and details of its processing.
- Rectification: You can ask us to correct inaccurate or incomplete data we hold about you.
- Erasure: You may request your data is deleted in certain circumstances, for example, where it is no longer necessary for the original purpose.
- Restriction: You have the right to restrict or limit our processing of your data in some cases.
- Data Portability: Where applicable, you can request a copy of your data in a portable format.
- Objection: You may object to processing based on our legitimate interests, including direct marketing.
- Withdraw Consent: If you have provided consent for any specific purpose, you can withdraw it at any time.
To exercise your rights, please contact us using the details on our website. We will respond to all legitimate requests within one month and may require verification of your identity for security purposes.
Safeguarding Your Data
We apply reasonable and appropriate security measures to protect your personal data from loss, misuse, unauthorised access, disclosure, or alteration. We review our information collection, storage, and processing practices regularly to ensure ongoing security.
International Transfers
We generally store and process your data within the United Kingdom or European Economic Area (EEA). If we need to transfer your data outside these regions, we ensure an adequate level of protection and implement safeguards required by data protection law.
Changes to Our Privacy Policy
We may revise this Privacy Policy from time to time. Any changes will be published on our website with an updated effective date. Your continued use of our services following such updates confirms your acceptance of the revised policy.
Contacting Us
If you have any questions or concerns about this Privacy Policy or how your data is handled, please use the contact details provided on our website to reach us. We are committed to working with you to fairly resolve any privacy concerns.