Catford Florist Privacy Policy for Customers
Introduction
This Privacy Policy sets out how Catford Florist ('we', 'us', 'our') collects, processes, uses, and protects personal data of customers placing orders in Catford and the surrounding districts. We are committed to complying with the United Kingdom General Data Protection Regulation (UK GDPR) and related privacy laws.
Scope of This Policy
This Privacy Policy applies to all customers who place orders with Catford Florist, whether in person, by telephone, online, or through any other ordering channel, and who reside or send orders to addresses in Catford or surrounding areas. By placing an order, you agree that your personal data will be processed as described below.
What Personal Data We Collect
We may collect and process the following categories of personal data:
- Identity Data: Your name, surname, and, where relevant, the recipient’s name.
- Contact Data: Your address, email address, and telephone number, plus the contact information for delivery recipients as necessary for order fulfilment.
- Order Details: Information about products ordered, delivery instructions, and order notes.
- Payment Data: Payment confirmation details (note: we do not store full payment card numbers, but our authorized payment processor may process your payment information).
- Communication Data: Correspondence, feedback, enquiry details, and reviews provided by you.
- Technical Data: IP address, browser type, and device identifiers collected when you interact with our website, for analytic and security purposes.
Lawful Bases for Processing Your Data
Under GDPR, we must have a valid reason to use your personal data. We rely on the following lawful bases:
- Contractual Necessity: To fulfil and manage your order and deliver goods or services you have requested.
- Legal Obligation: To comply with statutory obligations, such as maintaining records for tax purposes.
- Legitimate Interests: To improve our services, handle customer enquiries or complaints, or conduct analytics, provided these interests do not override your rights and freedoms.
- Consent: For specific uses, such as sending marketing communications if you have opted in. You may withdraw consent at any time.
How We Use Your Personal Data
We use your personal data to:
- Process and fulfil your orders, including arranging delivery to the nominated recipient.
- Manage payments and issue receipts or invoices.
- Contact you regarding your order or to respond to your enquiries.
- Handle returns, refunds, and customer support queries.
- Improve our services and operations, for example, by analysing feedback.
- Send periodic updates or marketing material when you have given explicit consent.
- Comply with any relevant legal or regulatory obligations.
Data Retention
We retain your personal data only for as long as is necessary to fulfil the purpose for which it was collected, including the fulfilment of orders, record keeping, and compliance with legal requirements. As a general guideline, order records are retained for up to six years to meet tax and contract law obligations. Information held solely for marketing purposes is kept only while you remain subscribed or until you withdraw consent.
Data Processors and Third Parties
We may engage third-party service providers who process your data on our behalf ("processors") to assist with order delivery, payment processing, IT support, and analytics services. We ensure that such processors comply with GDPR by entering into appropriate data processing agreements that require them to process your data securely and only as instructed by Catford Florist.
Examples of processors may include:
- Payment gateway providers to process card transactions securely.
- Delivery and courier services for order handling and tracking.
- IT infrastructure and website hosting service providers.
- Analytics providers to help us understand website usage and customer patterns (using aggregate or pseudonymised data where possible).
Your personal data is not sold or shared with third parties for their own marketing purposes. Data transfers outside the UK/EU, if any, will only occur where adequate safeguards are in place to protect your information.
Your Data Protection Rights
Under data protection law, you have the following rights:
- Right of Access: You may request details of personal data we hold about you.
- Right to Rectification: You may have inaccurate or incomplete data corrected.
- Right to Erasure: You can request deletion of your data when there is no compelling reason for its continued processing.
- Right to Restrict Processing: You may ask us to stop processing your data in certain circumstances.
- Right to Data Portability: You may request your data in a structured, commonly used, and machine-readable format.
- Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: When we rely on your consent, you can withdraw it at any time.
To exercise any of these rights, please contact us using the contact details made available when placing your order or on our website. We may need to verify your identity before actioning your request. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you are unhappy with how we handle your data.
How We Protect Your Personal Data
We implement appropriate technical and organisational measures to safeguard your information, including secure storage solutions, encryption of payment transactions, and restricted access to your data on a need-to-know basis by authorised staff and processors only.
Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in operational practices or legal requirements. Any significant changes will be communicated through our usual customer channels or on our website. Your continued use of our services constitutes your acceptance of any amended policy.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please reach out to us through the methods provided on our website or at our Catford premises. We are committed to protecting your privacy and upholding your data protection rights.
