Berrylands Florist GDPR Privacy Policy
Introduction
This Privacy Policy outlines how Berrylands Florist collects, uses, manages, and protects your personal information in compliance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Berrylands Florist in Berrylands and surrounding districts. It explains what information we collect, the lawful basis for processing your data, how long we retain it, who processes your data, and your rights regarding your personal information.
What Data We Collect
When you place an order or interact with Berrylands Florist, we collect and process various types of personal data depending on the nature of your interaction. This may include:
- Identity Data: Your full name.
- Contact Data: Billing and delivery addresses, telephone number (if provided), and occasionally your email address for order confirmation and queries.
- Order Information: Details of products or services you have purchased, special delivery instructions, messages included with your flowers (such as card notes), payment details (although we do not store card numbers after payment).
- Transaction Data: Order history, purchase timestamps, and payment status.
- Communication Data: Records of correspondence if you contact us about your order or for customer service.
We do not collect or process sensitive personal data (special categories of data) unless explicitly required to fulfill your order and with your consent.
Lawful Basis for Processing Your Data
We process your personal data in accordance with the GDPR and only where a lawful basis exists. Depending on the nature of our relationship, we rely on one or more of the following legal bases:
- Contractual Necessity: To process your order, deliver products, communicate with you about your purchase, and manage your account, we require your data. This is necessary to fulfill the contract you have entered into with us.
- Legal Obligations: We may need to retain certain purchase information to comply with financial, tax, and business recordkeeping laws.
- Legitimate Interests: We may process and store your data for our legitimate business interests (for example, improving our services, handling customer queries, and ensuring delivery efficiency), provided your fundamental rights and freedoms are not overridden.
- Consent: Where we rely on your consent (for example, for marketing communications), you are free to withdraw that consent at any time.
How We Use Your Data
Berrylands Florist uses your data to:
- Process and fulfill your orders, including arranging delivery and addressing customer service queries.
- Contact you about your order or with service updates.
- Keep financial and transaction records in compliance with our legal obligations.
- Improve our services based on order trends, customer preferences, and feedback (ensuring any data used for analysis is anonymized where possible).
- Send relevant updates or marketing, but only where permitted by law or with your consent.
Data Processors and Sharing
Berrylands Florist may engage third-party service providers to enable efficient order processing and business operations. These may include:
- Payment Processors: To securely handle payments, we use trusted payment gateway services. Your payment details are processed in accordance with industry security standards and are not stored by us after the transaction is complete.
- Delivery Partners: Independent couriers or delivery services may receive your name, delivery address, and order details necessary to complete your delivery.
- IT and System Providers: We use reputable IT support and order management system providers who may, in the course of maintenance, have incidental access to customer data. All such processors are required to act in accordance with our instructions and the law, ensuring data confidentiality and security.
We do not sell or share your personal data with marketers, advertisers, or unrelated third parties.
Data Retention
Your personal data will only be kept for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Typically:
- Order and transaction details are maintained for up to six years in accordance with UK tax law and business records standards.
- If you make a customer service enquiry, we retain relevant correspondence for up to two years unless a longer retention is necessary.
- Where we have asked for your consent to process data (such as for direct marketing), we will retain your data until you withdraw your consent or until it is no longer relevant.
Once no longer needed, your personal data will be securely deleted or anonymized.
Your Privacy Rights
As a customer of Berrylands Florist, you have the following rights under the GDPR:
- Right to Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You can request corrections to inaccurate or incomplete data.
- Right to Erasure: In certain cases, you may ask us to delete your data ('right to be forgotten').
- Right to Restriction: You may request temporary suspension of processing your data in certain circumstances.
- Right to Object: You may object to our processing of your data for direct marketing or based on legitimate interest.
- Right to Data Portability: Where applicable, you can request transfer of your data to another provider.
- Right to Withdraw Consent: If you have provided consent, you have the right to withdraw it at any time.
To exercise these rights, please contact us directly with appropriate proof of identity to protect your data privacy. We will respond to your request within the timeframe set by law.
Data Security
Berrylands Florist employs suitable technical and organisational measures to protect your personal information from accidental loss, unauthorized access, alteration, or disclosure. Measures include secure storage, regular staff training, and limiting customer data access strictly to staff and processors who require it to fulfill their duties.
Policy Updates
We regularly review and update this Privacy Policy to reflect changes in law or practice. Any significant changes will be communicated to our customers, where appropriate. We encourage you to review this policy periodically for the latest information on our privacy practices.
Contacting Us
If you have any questions about how Berrylands Florist handles your data or wish to exercise your rights as described above, please contact us via our standard customer enquiry channels. We are committed to resolving concerns promptly and transparently, ensuring your trust in how we handle your personal information.