North Kensington Florist Privacy Policy
Introduction
This Privacy Policy outlines how North Kensington Florist collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). Our commitment to your privacy is a fundamental part of our service. This policy applies to all customers placing orders with North Kensington Florist, whether in North Kensington or the surrounding districts.
What Data We Collect
When you engage with North Kensington Florist, we collect a range of personal data to process your order and enhance your customer experience. Depending on your interaction with us – whether online, by phone, or in person – the following types of information may be collected:
- Contact Information: Name, delivery address, billing address, and contact details.
- Order Details: Products ordered, delivery instructions, and any personalised messages provided.
- Payment Information: We may collect payment card details for order processing, although these may be managed by third-party payment processors (see 'Processors').
- Account Information: If you create an account with us, login credentials are securely stored.
- Usage Data: Website navigation, preferences, and communications sent to or received from us.
- Technical Data: IP address, browser type and version, time zone setting, and device identifiers.
Lawful Bases for Processing Your Data
North Kensington Florist processes your personal data only when there is a lawful basis under GDPR. The primary lawful grounds for processing include:
- Contractual Necessity: To fulfill orders, provide requested services, and communicate with you regarding your purchase.
- Legitimate Interests: For business processes such as improving our services, fraud prevention, or responding to your enquiries, only where our interests are not overridden by your rights.
- Legal Obligation: To comply with relevant laws, such as tax or accounting requirements.
- Consent: In situations where specific consent is required, such as for marketing communications or survey participation, we will only process your data with your clear consent. You can withdraw consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing and fulfilling your flower orders.
- Managing payments, refunds, or resolving issues relating to your order.
- Communicating with you about your order and responding to your requests.
- Improving our website and services based on customer interactions and preferences.
- Complying with legal and regulatory obligations.
- Marketing our services to you, where you have opted in to receive such communications.
Retention of Your Data
We retain your personal data for as long as necessary to fulfill the purposes described above, and to comply with legal, regulatory, and accounting requirements. Typically:
- Order information is retained for a period of 7 years to meet statutory financial and tax obligations.
- If you have an account with us, your data will be kept for as long as your account is active. If your account is closed or inactive for a substantial period, it will be deleted or anonymised in accordance with our data retention policy.
- Marketing data is retained until you opt out, after which it is promptly removed from marketing lists.
After the applicable retention periods, your personal data is securely deleted or anonymised so it can no longer be associated with you.
Third-Party Processors
To operate efficiently, we sometimes share your data with trusted third-party service providers who help us with functions such as order delivery, payment processing, IT hosting, website analytics, and marketing services. All processors act under our instructions and are required to adhere to strict data protection standards:
- Payment processors handle your card details securely and are certified in accordance with PCI-DSS (Payment Card Industry Data Security Standards).
- Delivery partners receive your name, address, and order details solely to fulfil delivery.
- Technical service providers supply infrastructure, cloud hosting, and analytics services.
We do not sell or rent your personal data to third parties. Where data is transferred outside the UK or European Economic Area, we ensure appropriate safeguards are in place to protect your data as required by GDPR.
Your Rights
Under GDPR, you have a range of rights regarding how we use your personal data. You may exercise these rights by contacting North Kensington Florist and providing sufficient information to identify your data. Your rights include:
- Access: You can request details of the personal data we hold about you.
- Rectification: You have the right to correct your personal data if it is incomplete or inaccurate.
- Erasure: You may ask us to delete your data where there is no lawful basis for retaining it.
- Restriction: You can request the restriction of our processing where you believe data is inaccurate or our use is unlawful.
- Objection: Where we rely on legitimate interests, you have the right to object to such processing.
- Data Portability: You can request your data in a machine-readable format to transfer to another service provider.
- Withdrawal of Consent: Where consent is required, you may withdraw this at any time for future processing.
- Lodging a Complaint: If you are not satisfied with our response, you have the right to complain to the relevant supervisory authority.
Security of Your Data
North Kensington Florist takes the security of your data seriously. We implement technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encrypted communications, secure data storage, regular staff training, and access controls.
Policy Scope and Updates
This policy applies to all customers placing North Kensington Florist orders from North Kensington and the surrounding districts. We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The latest version will always be available on request and is effective from its date of publication.
Contact and Further Information
If you have any questions about this Privacy Policy, your data protection rights, or wish to make a request regarding your personal data, please contact North Kensington Florist through the contact methods provided at the point of order or on our website.