Your Personal Data and Leytonstone Florist: Our Privacy Commitment
Privacy Policy for Leytonstone Florist Customers
This Privacy Policy outlines how Leytonstone Florist ("we", "us", "our") collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and relevant UK legislation. It applies to all customers who place orders with Leytonstone Florist and reside in Leytonstone and the surrounding districts.
What Data We Collect
When you place an order with Leytonstone Florist, we may collect the following categories of personal data:
- Contact Information: Name, delivery address, billing address, and telephone number.
- Order Information: Details of your flower order, card message, delivery preferences, and any special instructions.
- Payment Details: Information needed to process your payment, such as transaction amount and method (please note: sensitive payment card data is processed directly by our secure payment processors and is not retained by us).
- Communication Records: Correspondence with us by email, telephone, or through our website regarding your order.
- Consent Preferences: Your preferences in receiving marketing and other communications.
Lawful Basis for Processing Your Data
We process your personal data under the following lawful bases, as defined in Article 6 of the GDPR:
- Contractual Necessity: We require certain details to process your orders, arrange deliveries, and fulfil our contract with you.
- Legal Obligation: To comply with applicable legal requirements, such as tax and accounting regulations.
- Legitimate Interests: To improve our products, services, and customer experience, provided these do not override your rights or interests.
- Consent: For marketing and promotional purposes, we obtain your clear consent before sending such communications. You may withdraw your consent at any time.
How We Use Your Data
Your personal data enables us to provide our services efficiently and safely. Specifically, we use your data to:
- Process, confirm, and deliver your orders
- Communicate with you regarding your order or respond to your enquiries
- Maintain financial and transaction records as legally required
- Send you updates or promotional information (if you have opted in)
- Analyse and improve our processes, services, and customer experience
Retention of Your Data
We retain your personal data only for as long as is necessary to fulfil the purpose for which it was collected, or as required by law. The retention periods are as follows:
- Order and Transaction Data: Retained for up to 7 years for accounting and legal compliance purposes.
- Marketing Data: Held until you withdraw your consent or unsubscribe from marketing communications.
- Order Communications: Retained for up to 2 years to assist with customer enquiries.
- Once your data is no longer required, it is securely deleted or anonymised.
Who Processes Your Data (Data Processors)
In order to fulfil orders and manage our business operations, we share necessary parts of your personal data with trusted third-party service providers strictly on a need-to-know basis. Examples include:
- Delivery services responsible for ensuring your flowers reach their destination
- Payment processing companies that handle payments securely on our behalf
- IT service providers maintaining and hosting our website and order management systems
- Marketing platforms (only if you have provided marketing consent)
All processors are contractually obliged to handle your data securely, confidentially, and in compliance with GDPR requirements. They are not permitted to use your data for any purpose other than delivering the services we have commissioned.
Your Rights Under GDPR
As a Leytonstone Florist customer, you have the following rights with regard to your personal data:
- Right to Access: You can request confirmation of the data we hold about you and receive a copy of it.
- Right to Rectification: You can ask us to correct or update any inaccurate or incomplete data.
- Right to Erasure: You may request deletion of your personal data where legally permissible.
- Right to Restrict Processing: You can ask us to restrict processing in certain circumstances.
- Right to Data Portability: In applicable cases, you can request to receive your data in a commonly used and machine-readable format.
- Right to Object: You have the right to object to processing activities where we rely on legitimate interests as a basis, including profiling for direct marketing.
- Withdraw Consent: Where we process your data with your consent, you may withdraw it at any time. Withdrawing consent will not affect the lawfulness of processing carried out before withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you feel your data has been processed unfairly or unlawfully.
How We Protect Your Data
We implement robust physical, technical, and organisational safeguards suitable for the personal data we process, including encryption, secure storage, restricted access, and staff training to prevent unauthorised access, disclosure, alteration, or destruction.
International Data Transfers
In the rare event that your data is transferred outside the UK or European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission, to maintain adequate data protection standards.
Updates to This Policy
We may occasionally update this Privacy Policy to reflect changes in the law, our data processing practices, or our business operations. The latest version will always be available via our service channels, and significant changes will be communicated to you.
Contacting Us About Your Privacy
If you have questions, concerns, or wish to exercise any of your rights under this Policy, please contact us using the customer service details available through our usual communication methods. We are committed to responding to all requests promptly and fairly.