Florist Swiss Cottage Privacy Policy
Introduction
This Privacy Policy outlines how Florist Swiss Cottage collects, uses, stores, and protects personal data provided by customers placing orders from Swiss Cottage and the surrounding districts. Florist Swiss Cottage is committed to respecting your privacy and ensuring that your personal data is handled in full compliance with the UK General Data Protection Regulation (GDPR).
Scope of This Policy
This policy applies to all customers of Florist Swiss Cottage who place orders for floral products and services, whether online, by phone, or in person, for delivery or collection within Swiss Cottage and its surrounding districts. By placing an order, you agree to the practices described in this Privacy Policy.
Categories of Personal Data We Collect
To process your orders and provide our services, Florist Swiss Cottage collects the following types of personal data:
- Identification Information: Name, title, and contact details (such as postal address, delivery address, and telephone number).
- Order Information: Order details, delivery preferences, product selections, and any personal messages provided for delivery.
- Payment Information: Payment details will be processed securely by our payment processors and are not stored by Florist Swiss Cottage beyond necessary transaction records.
- Communication Data: Correspondence history, including customer service requests or feedback provided to us.
- Technical Data: Device information, IP address, browser type, and cookies may be collected when you use our website to enhance your experience and maintain security.
Lawful Basis for Processing Your Data
Florist Swiss Cottage processes your personal data on the following lawful grounds, as required by the GDPR:
- Contractual Necessity: We need your information to perform the contract of sale or service you request, such as fulfilling your order and delivering flowers to the intended recipient.
- Legal Obligation: We process certain data to comply with legal and regulatory obligations, such as retaining transaction records for tax or accountancy purposes.
- Legitimate Interests: We may process your data for our legitimate business interests, for example to improve our products or services, prevent fraud, and ensure network and information security. We always balance our interests with your rights and freedoms.
- Consent: Where you have specifically consented (e.g., to receiving marketing communications), we process your personal data accordingly. You can withdraw your consent at any time.
How We Use Your Personal Data
We use your personal data for the following purposes:
- Processing and fulfilling orders, including delivery and customer support
- Managing customer accounts and processing payments
- Communicating with you regarding your orders, updates, and service notifications
- Enhancing your experience on our website and tailoring future interactions
- Complying with legal and regulatory requirements
- Sending promotional offers or newsletters, only if you have provided consent
Data Retention
We retain personal data only for as long as is necessary for the purposes for which it was collected and to meet our legal obligations. Typically, we retain:
- Order and transaction records: Retained for up to 7 years to comply with taxation and accounting requirements.
- Marketing data: Retained until you withdraw your consent or request deletion.
- Communication data: Retained for up to 3 years after your last contact.
After these periods, data is securely deleted or anonymised.
Data Sharing and Processors
Florist Swiss Cottage does not sell your personal data. However, we may share your data with trusted third-party processors, strictly for the purposes outlined below and in accordance with data protection laws:
- Delivery partners: To ensure your order reaches its destination.
- Payment service providers: To process secure transactions. Payment details are not stored by us beyond necessary transaction references.
- IT and hosting providers: To maintain our website, store data, and keep our systems secure.
- Professional advisers: Such as accountants or legal experts, to comply with our legal obligations.
All processors are contractually obliged to process your data securely and only for the specified purposes.
Your Rights Under GDPR
As an individual within the scope of GDPR, you have the following rights with respect to your personal data:
- Right to Access: Request access to your personal data and obtain a copy.
- Right to Rectification: Request correction of incorrect or incomplete data.
- Right to Erasure: Request deletion of your data in certain circumstances.
- Right to Restrict Processing: Ask us to restrict processing if you contest its accuracy or our use.
- Right to Data Portability: Receive your data in a structured, commonly used format and transmit it to another controller.
- Right to Object: Object to our processing of your data in certain cases (such as direct marketing).
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw it at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the relevant supervisory authority if you believe we have not complied with data protection laws.
International Data Transfers
Your personal data is primarily processed within the United Kingdom. Should data be transferred outside of the UK, we ensure adequate safeguards are in place in compliance with UK GDPR requirements.
Security of Your Data
We implement suitable technical and organisational measures to protect your personal data from loss, theft, unauthorised access, disclosure, or alteration. Our employees and processors are trained to handle your data securely and confidentially.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or technology. Please refer to this page regularly for the latest information. Any significant changes will be communicated when appropriate.
Contact Information
If you wish to exercise your rights or have questions regarding your personal data and this Privacy Policy, please contact us using our official channels as listed on our website.