Edgware Flowers Privacy Policy
Introduction
This Privacy Policy explains how Edgware Flowers collects, uses, protects, and processes personal data when you place an order with us. It applies to all customers ordering floral products or related services from Edgware Flowers within Edgware and its surrounding districts. We are fully committed to complying with the UK General Data Protection Regulation (GDPR) and ensuring that your personal information is handled appropriately and lawfully.
What Data We Collect
When you order from Edgware Flowers, we collect the following types of personal data to fulfil your order and manage our services:
- Contact Details: Your name, delivery address, billing address, phone number, and, if applicable, the recipient’s name and address.
- Order Information: Details of products or services ordered, delivery instructions, and payment confirmation data (note: payment card details are processed securely by third-party providers and not stored by us).
- Communication Data: Any communication you send us by email, website forms, or letters, including queries, feedback, and complaints.
- Technical Data: Data such as your IP address, browser type, and device information when you browse our website. This is collected through cookies and similar technologies for website security and analytics.
Lawful Basis for Processing
Edgware Flowers processes your data under the following lawful bases, as defined by the GDPR:
- Contractual Necessity: Processing your data is necessary for us to fulfil the contract to provide goods and services you have ordered, including delivery and customer service.
- Legal Obligation: We may need to process personal data to comply with legal requirements, such as record-keeping or tax reporting.
- Legitimate Interests: We may process data for legitimate business interests, such as improving our services, direct communications about your order, or preventing fraud, provided your rights do not override these interests.
- Consent: In some cases, such as optional marketing communications, we will only process your data if you have specifically given your consent. You are free to withdraw your consent at any time.
Data Retention
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected. In general:
- Order details, contact information, and transaction data are retained for up to 6 years from the date of your last transaction, to meet legal and accounting obligations.
- Communications such as inquiries and feedback are retained for up to 2 years, unless required for ongoing dispute resolution or legal matters.
- Technical and website usage data may be retained for up to 2 years for analytical and security purposes.
Once data is no longer needed, it is securely deleted or anonymised.
Data Processors and Third Parties
Edgware Flowers shares your personal data only with trusted third parties who assist us in delivering our services. These third parties act as data processors and are contractually obligated to safeguard your information in compliance with GDPR.
Categories of processors include:
- Payment Service Providers: For processing card payments securely (your full card details are not visible to us).
- Delivery Partners: To ensure your flowers arrive at the correct destination.
- IT and Website Support Providers: To help us maintain secure and functional technology systems, including website hosting and analytics providers.
We do not sell or rent your data to third parties. Personal data may be disclosed when required by law, for example, to comply with a legal process, law enforcement request, or regulatory obligation.
Your GDPR Rights
Under the GDPR, you have specific rights regarding your personal information:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can request corrections to any inaccurate or incomplete data.
- Right to Erasure: Also known as the ‘right to be forgotten’, you may request deletion of your data where there is no legal reason for us to keep it.
- Right to Restrict Processing: You can ask us to pause the processing of your data under certain circumstances.
- Right to Data Portability: Where applicable, you may request that we transfer your data to another service provider.
- Right to Object: You have the right to object to certain types of processing, such as direct marketing.
- Rights Related to Automated Decision-Making: Edgware Flowers does not make any automated decisions affecting your rights or freedoms using your personal data.
Security Measures
We employ a combination of technical, physical, and organisational safeguards to protect your personal data from unauthorised access, disclosure, alteration, or loss. These include encrypted data transfers, secure data storage, and regular staff training on data security obligations.
International Data Transfers
Edgware Flowers primarily stores and processes your data within the UK or the European Economic Area (EEA). If any data must be transferred outside the EEA, we ensure that suitable safeguards are in place in accordance with GDPR requirements.
Policy Updates
We keep this Privacy Policy under regular review and may update it from time to time to reflect changes in our practices or relevant legislation. The effective date of the latest version will always be noted at the beginning of the policy. Continuing to use our services after changes means you accept these updates.
Contact and Concerns
If you wish to exercise your data protection rights, express concern about how we use your data, or request further information about our privacy practices, please get in touch using the contact methods available on our website or at our Edgware shop. If you have unresolved concerns, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).
Thank you for trusting Edgware Flowers. We remain committed to protecting your privacy at every step of your customer journey.