Florist Notting Hill Privacy Notice
Scope and Purpose of This Policy
This Privacy Notice explains how Florist Notting Hill collects, uses, stores, and protects your personal data when you place an order from Notting Hill and the surrounding districts. We recognize the importance of privacy protection and are fully committed to compliance with the European Union General Data Protection Regulation (GDPR). This policy applies to all customers who use our services within our delivery area, including online and over-the-phone orders.
What Personal Data We Collect
We collect the following categories of personal data to facilitate our services:
- Identity Data: Name of customer and recipient (if different).
- Contact Data: Delivery address, billing address, and contact phone number. We also collect email address for order updates and receipts.
- Order Data: Details of floral arrangements/products purchased, card messages, instructions, and delivery preferences.
- Payment Data: Payment method details (e.g., partial card information), but we do not store full card numbers; payments are handled securely by a third-party processor.
- Technical Data: IP address, browser type, and operating system, collected when using our website to improve service operation.
- Correspondence: Communications with our team, including inquiries, complaints, and feedback.
Lawful Bases for Processing Personal Data
Florist Notting Hill relies on the following lawful bases for the processing of your personal data:
- Contractual Necessity: Most of the personal data collected is necessary for us to fulfill our contract with you, such as processing your order and delivering products to you or your chosen recipient.
- Legal Obligation: We may process your information to comply with legal requirements, including accounting and tax regulations.
- Legitimate Interests: For quality control, business management, security, and to enhance our products and services, unless your fundamental rights override our interests.
- Consent: In certain situations, such as for direct marketing or newsletter subscriptions, we will obtain your explicit consent, which you can withdraw at any time.
How We Use Your Personal Data
Your data is used for the following purposes:
- Processing and fulfilling flower and gift orders.
- Communicating order updates, queries, or issues.
- Providing customer support and responding to inquiries.
- Improving our website, products, and services.
- Maintaining business records as required by law.
- Preventing and detecting fraud or misuse of our services.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes outlined in this policy, including satisfying any legal, accounting, or reporting requirements. Specifically:
- Order and contact data is typically retained for up to seven years in line with tax and business record-keeping obligations.
- Marketing consent records are held until you withdraw consent or unsubscribe from our communications.
- Technical data used for analytics may be anonymized and aggregated for statistical purposes and retained indefinitely.
When data is no longer required, we securely delete or anonymize it.
Processors and Data Sharing
We may use third-party service providers (processors) to carry out specific functions on our behalf. These include:
- Payment processors: To securely handle, authorize and process your payments.”
- IT and website hosting providers: To store data and ensure website functionality.
- Delivery partners: To assist with safe and timely order delivery.
- Professional advisors: As required for legal or auditing purposes.
All processors are contractually bound to safeguard personal data and process it only in accordance with our instructions and GDPR requirements. We do not sell or lease your personal data to third parties for marketing purposes.
International Transfers
All personal data is stored and processed within the United Kingdom or European Economic Area (“EEA”). In the rare case that personal data needs to be transferred outside the UK or EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses, to protect your information.
Your Rights Under GDPR
Under GDPR, as a data subject, you have a series of important rights relating to your personal data, including:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure: You may request that we delete your personal data in certain situations.
- Right to Restrict Processing: You can ask us to restrict processing of your data under specific conditions.
- Right to Data Portability: You can ask for your data to be transferred to you or another provider in a machine-readable format.
- Right to Object: You may object to our processing where we rely on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw it at any time without affecting the lawfulness of past processing.
To exercise any of these rights, please contact us using the methods described on our website. When making a request, we may ask for proof of identity to ensure the protection of your data.
How We Protect Your Data
Florist Notting Hill has implemented appropriate technical and organisational measures to ensure the security of your personal data against unauthorised access, loss, or misuse. These safeguards include secure servers, encryption tools, strict access controls, and regular staff training on data protection principles.
Cookies and Similar Technologies
Our website uses essential cookies to ensure proper functioning and may use analytics cookies to understand user experience and improve our services. Where non-essential cookies are used, you will be provided with the option to consent or manage your settings.
Policy Updates and Contacting Us
We may update this Privacy Policy periodically to reflect changes in technology, regulations, or our business. Updates will be clearly posted on our website, with the effective date noted. Continued use of our services after such changes signifies your acceptance of the revised policy. For more information or to exercise your rights, please refer to our website’s contact options.
Complaints
If you have any concerns about the way Florist Notting Hill handles your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority. We encourage you, however, to contact us first so we can address your concerns directly.