New Cross Florist - GDPR Privacy Policy
Introduction
At New Cross Florist, we are committed to safeguarding the privacy and personal data of our customers. This Privacy Policy explains how we collect, use, retain, and protect your data in accordance with the General Data Protection Regulation (GDPR). It applies to all individuals placing orders with New Cross Florist in New Cross and surrounding districts.
What Data We Collect
When placing an order or interacting with us, we may collect and process the following categories of personal data:
- Contact Information: This includes your name, delivery address, billing address, and (where applicable) recipient details if you are sending flowers to someone else.
- Order Details: Details of the products and services you order, personal messages to recipients, delivery preferences, and transaction details.
- Payment Information: Details relevant to payment, such as card information and payment confirmations. Please note, payment processing is carried out securely by third-party payment processors; we do not retain your full payment card data.
- Communication Records: Any correspondence or enquiries you have with us, including customer service communications and feedback.
- Technical Information: Information about how you interact with our website or digital services, such as your browser type, IP address, device information, and cookies (where applicable and with your consent).
Lawful Basis for Processing Your Data
Under GDPR, every processing activity must have a lawful basis. At New Cross Florist, we process your personal data on the following grounds:
- Contractual Necessity: Most of your data is processed to fulfil your order, arrange delivery, process payments, and provide customer service as per our agreement with you.
- Legitimate Interests: To improve our products and services, prevent fraud, and maintain business records, where these interests are not overridden by your rights and interests.
- Legal Obligations: In some instances, we are required to process and retain certain information to comply with accounting, taxation, or regulatory requirements.
- Consent: We may seek your explicit consent to use certain optional data, for example for marketing communications. You can withdraw your consent at any time.
How We Use Your Data
Your information is used strictly for the purposes for which it was provided, and only when permitted by law. Specifically, we use your personal data to:
- Process and deliver your orders accurately and on time.
- Communicate with you about your orders, address any issues, and respond to your enquiries.
- Complete secure payment transactions through trusted payment providers.
- Send customer feedback requests or updates about your orders.
- Improve our offerings, products, and services based on your feedback and behaviour (when permitted).
- Meet any legal and regulatory obligations.
Data Retention
We retain your personal data only for as long as it is necessary to fulfil the purpose for which it was collected, or as long as required by law. Typically, order and customer account information is kept for a period of seven years for business, financial, and legal purposes. After this period, your data will be securely deleted or anonymised unless exceptional circumstances justify longer retention (for example, ongoing disputes or statutory requirements).
Who Processes Your Data
Your personal data is mainly handled by the staff at New Cross Florist responsible for order processing, customer service, and delivery arrangements. In addition, we share relevant data with carefully selected third-party service providers ("data processors") who assist us in operating our business, such as:
- Payment processing providers for secure card transactions.
- IT hosting and systems management companies.
- Delivery couriers who require recipient contact and address details.
All service providers engaged by us are contractually required to handle your data in compliance with the GDPR and are not permitted to use your information for any purpose other than providing services to New Cross Florist. We do not sell or trade your personal data to any third parties.
Your Data Protection Rights
Under GDPR, you have several important rights regarding your personal data:
- The Right to Access: You can request confirmation of the personal data we hold about you and ask for a copy of that information.
- The Right to Rectification: You may request prompt correction of inaccurate or incomplete data about you.
- The Right to Erasure: You may request deletion of your personal data in certain circumstances, such as when the information is no longer required or if you have withdrawn consent (where applicable).
- The Right to Restrict Processing: You can request that we restrict the processing of your data, for example, if you contest its accuracy or object to processing.
- The Right to Data Portability: You may have the right to receive your data in a commonly used, machine-readable format and transmit it to another controller.
- The Right to Object: You have the right to object to processing based on our legitimate interests or for marketing purposes. We will stop such processing unless we have compelling legitimate grounds.
- The Right to Withdraw Consent: Where you have provided consent, you may withdraw it at any time. This will not affect any processing carried out before withdrawal.
To exercise your rights or if you have questions regarding your data, please contact us using the details provided on our website or in your order confirmation.
Data Security
We implement appropriate technical and organisational measures to protect your data from unauthorised access, loss, misuse, alteration, or disclosure. These include access controls for staff, secured databases and payment systems, encrypted data transmission, regular security assessments, and staff training on data privacy responsibilities.
Changes to this Policy
We may occasionally update this Privacy Policy to reflect changes in our data processing practices or legal requirements. We encourage you to review this Policy periodically to stay informed about how we protect your information.
Contact and Complaints
If you have any concerns about your personal data or this Privacy Policy, please contact us via the contact details provided on our official website. If you are dissatisfied with our response, you are entitled to lodge a complaint with the relevant supervisory authority for data protection in the UK.
This Policy is effective from June 2024 and applies to all customers placing New Cross Florist orders from New Cross and surrounding districts.