Privacy Policy for Hatch End Florist Customers
Introduction
This Privacy Policy explains how Hatch End Florist collects, uses, retains, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Hatch End Florist from Hatch End and the surrounding districts. Please review the following information carefully to understand our practices and your rights regarding your personal data.
What Data We Collect
Hatch End Florist collects and processes the following types of personal data in connection with customer orders:
- Identity Information: Your full name.
- Contact Information: Address, phone number, and where applicable, delivery address of the recipient.
- Order Details: Product selections, card messages, and any specific delivery instructions provided by you.
- Payment Information: Limited payment and transaction details for order fulfillment (note: we do not store full payment card details).
- Communications: Any correspondence you have with us regarding your order or queries, whether by phone, in writing or in-person.
We do not knowingly collect any sensitive personal data (such as health, ethnicity or religious information) or data from individuals under the age of 16. Please do not provide such information when placing orders.
Lawful Basis for Processing Your Data
Hatch End Florist processes your personal data based on the following lawful grounds under the GDPR:
- Contract: The majority of our data collection is necessary for performing a contract with you, namely processing and delivering your floral order.
- Legal Obligation: Certain information may be required to comply with legal and financial obligations, such as record retention for tax purposes.
- Legitimate Interest: We may use your data for our legitimate business interests, such as improving services, maintaining customer records, handling complaints, or managing fraud risk, provided your rights and freedoms are protected.
- Consent: If we ever wish to send you marketing materials (for example, about new products or offers), we will only do so with your explicit consent. You may withdraw this consent at any time.
How We Use Your Information
Your personal data is used for the following purposes:
- Processing and delivering your floral orders.
- Communicating with you about your order status or responding to your enquiries.
- Handling payments and financial transactions.
- Maintaining our customer records for service quality and legal requirements.
- Improving our products and customer services, using aggregated and anonymised data.
We do not use automated decision-making or profiling with your personal information.
Data Retention
We retain your personally identifiable information for as long as necessary to fulfill the purposes it was collected for, including fulfilling orders, resolving queries, and complying with our legal and accounting obligations. Typically, order-related data is held for up to six years from the end of the financial year in which your order was placed, according to legal retention requirements. After this time, your personal data will be securely deleted or anonymised.
Data Sharing and Processors
Your personal information is treated confidentially and is only shared with trusted processors involved in fulfilling your order. These may include:
- Payment processors for secure transaction handling.
- Delivery partners and couriers responsible for delivering your order.
- Our cloud-based software providers for order management, if used internally.
All data processors are contractually required to process your data only as instructed by us and to implement appropriate data security measures. We do not sell or rent your personal information to third parties for marketing purposes. Where legally required, we may share your information with government authorities if requested.
Your Rights Under GDPR
You have the following rights regarding your personal data under the GDPR:
- The right to access: You may request information about the personal data we hold about you, including copies, at any time.
- The right to rectification: You can ask us to update or correct inaccurate or incomplete personal data.
- The right to erasure: You may request that we delete your personal data in certain circumstances, unless legal obligations require us to retain it.
- The right to restrict processing: You may request that we restrict the processing of your data in certain circumstances.
- The right to object: You may object to the processing of your data based on legitimate interest or direct marketing.
- The right to data portability: You may request your data be provided in a structured, machine-readable format, or transferred to another service provider where feasible.
- The right to withdraw consent: Where processing is based on your consent, you may withdraw it at any time, without affecting previous processing.
To exercise your rights, please contact us in writing or visit our premises. We will respond to your request in accordance with GDPR requirements, typically within one month.
Data Security
We take the security of your personal data seriously. Hatch End Florist implements technical and organisational measures to protect your data from loss, misuse, unauthorised access, alteration, or disclosure. Access to your data is restricted to those employees, agents, and processors who require it for order fulfillment or compliance.
Changes to This Privacy Policy
We reserve the right to amend or update this Privacy Policy to reflect changes in our practices or legal requirements. Any significant changes will be communicated by updating this page and, where appropriate, by other means. We recommend that you review this Privacy Policy regularly to stay informed about how we are protecting your data.
Contacting Hatch End Florist
If you have any questions about this Privacy Policy or how your data is processed, please contact us in writing or by visiting our shop. We are committed to resolving any concerns you may have about your personal data.
