Charing Cross Florist Privacy Policy
Introduction
This Privacy Policy describes how Charing Cross Florist ('we', 'our', 'us') collects, uses, stores, and protects the personal information of customers placing orders from Charing Cross and the surrounding districts. We are committed to safeguarding your privacy and complying with the General Data Protection Regulation (GDPR) and other relevant UK data protection laws. By placing an order with Charing Cross Florist, you acknowledge that you have read and understood this policy.
What Data We Collect
When you use our services or place an order with Charing Cross Florist, the following categories of personal data may be collected:
- Identity Information: Name, surname, and, if applicable, the name of the recipient.
- Contact Information: Delivery address, billing address, telephone number, and email address.
- Order Information: Order details, particular product choices, purchase history, requested delivery date and time, and any message or note attached to your order.
- Payment Information: Limited details such as payment method and transaction references. (We do not store or directly process your full payment card details; these are managed securely by our payment processors.)
- Technical Data: IP address, browser type and version, time zone setting, and details about the device you use to access our website, where applicable.
- Communications: Correspondence with us, including enquiries, feedback, or complaints.
Lawful Basis for Processing Your Data
Charing Cross Florist processes your personal data only when permitted under GDPR. Our lawful bases for processing include:
- Performance of a Contract: Most of the data is required to fulfill your order and to provide associated services.
- Consent: With your explicit permission, we may process data for marketing communications, if you have opted in.
- Legal Obligation: Sometimes we are required by law to process and retain certain data (e.g., for tax or accounting purposes).
- Legitimate Interests: We may use certain data as necessary for our legitimate interests, such as improving our products and services, fraud prevention, and ensuring the security of transactions—provided that such interests are not overridden by your rights.
How We Use Your Personal Data
Your data may be used for the following purposes:
- To process and deliver your floral orders.
- To communicate order updates or resolve queries related to your purchase.
- To process payments and refunds.
- To improve our products, customer experience, and website usability.
- For internal record keeping and compliance with legal obligations.
- With your consent, to send promotional and marketing material, offers, or information about new products or events.
How We Share Your Data
We take your privacy seriously and do not sell or rent your information to third parties. We may share certain data only when necessary and with the following categories of recipients:
- Processors: Trusted service providers who assist in the delivery of our services—such as payment processors, delivery couriers, IT service providers, and website hosting services. These processors handle your data strictly on our instructions, under confidentiality agreements, and in compliance with the GDPR.
- Legal Authorities: Where required by law or to protect our rights, property, or safety.
- Professional Advisors: Such as accountants or legal counsel when necessary for compliance or auditing purposes.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes it was collected for, including to satisfy any legal, accounting, or reporting requirements. The retention periods are:
- Order and account details are generally kept for up to six years after the last interaction to comply with tax laws and resolve possible disputes.
- Communications and transactional correspondence are retained for up to three years unless a longer period is required by law.
- If you subscribe to our marketing communications, we keep your contact details until you withdraw your consent or opt-out, after which we will securely delete the relevant data.
Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
- The Right to Access: You may request to see the data we hold about you and receive a copy.
- The Right to Rectification: If your information is incorrect or incomplete, you have the right to request an update.
- The Right to Erasure: You can request we erase your personal data, subject to legal or contractual restrictions.
- The Right to Restrict Processing: In some circumstances, you can request we limit how we use your data.
- The Right to Data Portability: You may request transfer of your personal data to another provider, in a usable electronic format, subject to limitations.
- The Right to Object: You can object to certain types of processing, such as direct marketing.
- The Right to Withdraw Consent: Where processing is based on your consent, you can withdraw it at any time. This will not affect the lawfulness of processing before withdrawal.
- The Right to Lodge a Complaint: You also have the right to raise a concern with the Information Commissioner’s Office (ICO) if you believe your data rights have been infringed.
Data Security
We are committed to protecting your personal data and employ appropriate technical and organisational measures to safeguard it from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include encrypted transmissions, secure payment gateways, regular security reviews, and staff training.
International Data Transfers
Where our data processors are located outside the UK or European Economic Area (EEA), we require them to protect your data to a similar standard as under UK laws, typically through contractual agreements or certification schemes.
Policy Updates
We may update this Privacy Policy occasionally to reflect changes to our services or applicable law. The updated version will always be available in our store and on our website, with the date of the latest revision clearly shown. Your continued use of our services after changes are made constitutes your acceptance of the updated policy.
Contact and Queries
If you have any questions, requests, or concerns relating to this Privacy Policy or how your data is handled, please contact us by post or in person at Charing Cross Florist. We are always happy to assist with your data protection enquiries.
This Privacy Policy applies to all customers placing orders with Charing Cross Florist from Charing Cross and the surrounding districts.