Florist Leyton GDPR Privacy Policy
Introduction
This Privacy Policy describes how Florist Leyton ('we', 'us', 'our') uses and safeguards the personal data of customers placing flower orders from Leyton and the surrounding districts. We are committed to upholding your privacy and ensuring that your personal information is handled in accordance with the General Data Protection Regulation (GDPR) and applicable UK data protection legislation. Please read this policy carefully to understand what data we collect, how and why we process it, with whom we might share it, how long we retain it, and your rights as a customer.
Scope of the Policy
This policy applies to all personal data collected from customers who order flowers, gifts, or related items directly from Florist Leyton, whether through our website, phone orders, or in-person at our premises. Our services primarily cover Leyton and neighboring districts.
What Data We Collect
Florist Leyton collects and processes various types of data to fulfill your order and enhance your experience. The personal data we may collect includes:
- Name: Your full name for identification and personalization.
- Contact Details: Delivery address, billing address, phone number, and (optionally) any alternative contact number.
- Email Address: To provide order confirmations, receipts, and communication regarding your order.
- Order Details: Information about your purchase, such as product selection, delivery date, and special instructions.
- Payment Information: When you make a payment, we process essential details for transaction completion. Please note that we do not store full payment card numbers or CVV codes; payments are processed via secure third-party payment processors.
- Recipient Information: If sending flowers to a third party, we collect the recipient's name, delivery address, and contact information solely to complete the delivery.
- Communication Records: Details of your interactions with us, including queries and complaints.
- Technical Data: When using our website, we may collect limited technical information such as your IP address, browser type, and device details to help ensure website functionality and security.
Lawful Basis for Processing
Florist Leyton processes your personal data under one or more of the following GDPR lawful bases:
- Contractual Necessity: Most data is processed to create and fulfill the contract of sale or service between you and Florist Leyton, such as delivering your order and processing payment.
- Legitimate Interests: We may process limited data for improving our services, ensuring security, and conducting customer service communications where it does not override your rights.
- Legal Obligation: We may be obliged to process certain personal information for compliance with applicable legal and regulatory requirements, such as record-keeping for tax purposes.
- Consent: Where required, we may request your explicit consent for specific kinds of data processing (e.g., for optional marketing communications).
How We Use Your Personal Data
We use your personal data for the following key purposes:
- Processing and delivering your flower orders to the specified addresses.
- Communicating with you about your orders, including confirmations and service updates.
- Handling payments and refunds.
- Managing any requests, queries, or feedback you may have.
- Improving our customer service and product range through limited analytics or customer feedback (where lawful).
- Maintaining internal records and complying with legal obligations.
Data Retention
Florist Leyton retains your personal data only for as long as necessary for the purposes it was collected. Our standard retention periods are as follows:
- Order and transaction information: Kept for seven years to comply with tax and accounting obligations.
- Customer service and communication records: Kept for up to two years to resolve queries or complaints.
- Consent-based data (e.g., marketing): Retained until you withdraw your consent or opt out.
After the applicable retention period, your personal data will be securely deleted or anonymized.
Data Processors and Sharing
We may use trusted third-party service providers (data processors) to assist with order payments, deliveries, and IT services. Examples include payment processors (for handling card payments), delivery couriers, and email service providers. These partners are contractually bound to adhere to GDPR standards and may only process your data on our instructions for the specified purposes.
Florist Leyton does not sell your personal data to third parties. We may share personal data as required by law or as necessary to protect our legal rights.
Your Rights
Under GDPR, you have a number of important rights with respect to your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request corrections to any inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your personal data under certain circumstances.
- Right to Restriction: You may ask us to restrict how we process your data in certain cases.
- Right to Data Portability: Where applicable, you may request your data in a machine-readable format.
- Right to Object: You may object to specific processing activities, such as direct marketing.
- Right to Withdraw Consent: If you have given consent for a specific reason, you can withdraw it at any time.
- Right to Lodge a Complaint: If you believe your rights have not been respected, you can file a complaint with your local data protection supervisory authority.
We will respond to any rights request in accordance with GDPR requirements and within the applicable timeframes. To make a rights request, please contact us directly in writing or in person at our shop.
Data Security
Florist Leyton takes your privacy seriously. We implement appropriate technical and organisational measures to protect your personal data from loss, misuse, unauthorised access, alteration, or disclosure. This includes secure storage, limited access, and regular review of security policies.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our data practices or legal obligations. The latest version will be available in-store and on our website. Your continued use of our services after changes are posted will be deemed to indicate your acceptance of those changes.
Contact Us
If you have any questions about this Privacy Policy or your personal data, please contact us by visiting our shop in Leyton or using our official communication channels. We are committed to helping you exercise your data protection rights and to resolving any concerns as efficiently as possible.