West Brompton Florist Privacy Policy
  Introduction
This Privacy Policy explains how West Brompton Florist collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with West Brompton Florist in West Brompton and the surrounding districts. We are committed to safeguarding your privacy and ensuring you are fully informed of your rights relating to your personal data.
What Personal Data Do We Collect?
When you place an order with West Brompton Florist, we collect the following types of personal data as necessary for our services:
  - Contact Information: Name, delivery address, billing address, and telephone number.
 
  - Order Information: Details of your order, including product selection, delivery preferences, and any personal messages included with your order.
 
  - Payment Information: Payment method details (note: direct card details are processed securely by our payment processors and are not stored by us).
 
  - Communication History: Records of emails or messages exchanged regarding your order, queries, or feedback.
 
  - Usage Data: Information about how you use our website, such as your IP address, browser type, and cookies that help improve user experience (where applicable).
 
Lawful Basis for Processing Your Data
Under GDPR, we must have a valid legal basis to collect and process your personal information. West Brompton Florist relies on the following lawful bases:
  - Contractual Necessity: Processing your personal data is essential to fulfil your order and provide related customer services.
 
  - Legal Obligation: We retain certain information to comply with tax, accounting, or other legal requirements.
 
  - Legitimate Interest: We may process your data for legitimate business purposes such as improving our services, fraud prevention, or customer communications, provided these interests are not overridden by your rights and interests.
 
  - Consent: Where we seek to send you marketing communications by email or other means, we will always request your explicit consent. You may withdraw this consent at any time.
 
How We Use Your Personal Data
West Brompton Florist uses your personal information for the following purposes:
  - To process and deliver your flower orders accurately and on time.
 
  - To communicate with you about your order, answer your queries, or provide customer service.
 
  - To handle payments securely via trusted processors.
 
  - To comply with legal, tax, and regulatory obligations.
 
  - For internal business management, analysis, and service improvement.
 
  - To send you marketing or promotional communications, only where you have opted in.
 
Data Retention
We store your personal data only for as long as necessary to achieve the purposes outlined in this policy, and to meet legal obligations:
  - Order and Contact Information: Retained for up to 7 years to comply with accounting and legal requirements.
 
  - Payment Data: Not stored directly by us. Our payment processors retain transaction data in accordance with their own legal obligations.
 
  - Marketing Preferences: Kept until you withdraw your consent or request deletion.
 
  - Usage Data: Retained for up to 2 years for analytical and security purposes.
 
We regularly review our data retention practices and will securely delete or anonymise information when it is no longer required.
Data Processors and Sharing
We may share your information with trusted third-party service providers where necessary for order fulfilment, payment processing, IT services, and regulatory compliance. These companies process your data strictly in accordance with our instructions and policies:
  - Payment Processors: Securely handle payment transactions for your orders.
 
  - Delivery Partners: Facilitate the delivery of your ordered flowers to the chosen address.
 
  - IT Service Providers: Provide and secure website hosting, customer databases, and communications systems.
 
  - Legal and Regulatory Bodies: Where required by law, we may share data to comply with legal obligations.
 
We never sell your personal data to third parties for commercial purposes.
Your Rights Under GDPR
As a resident in West Brompton or surrounding districts using our services, you have the following rights regarding your personal data:
  - Right of Access: You can request confirmation of what personal data we hold about you and obtain a copy.
 
  - Right to Rectification: You may request correction of inaccurate or incomplete data.
 
  - Right to Erasure: You can ask us to delete your personal data when it is no longer necessary or where lawful grounds apply.
 
  - Right to Restrict Processing: You have the right to ask us to limit how we use your data under certain circumstances.
 
  - Right to Data Portability: You may request a copy of your data in a commonly used machine-readable format for transfer to another service provider.
 
  - Right to Object: You may object to processing based on our legitimate interests or to receiving direct marketing emails.
 
  - Right to Withdraw Consent: Where we process your data on the basis of consent (such as marketing), you can withdraw this consent at any time.
 
  - Right to Lodge a Complaint: You have the right to lodge a complaint with the relevant data protection authority if you are unhappy with how we manage your data.
 
Data Security
We apply appropriate technical and organisational measures to protect your personal data against loss, misuse, unauthorised access, alteration, or destruction. Access to your information is limited to staff and service providers who need it to deliver our services. All third-party processors are carefully selected and required to comply with applicable data protection laws.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legal requirements or our services. We encourage you to review this notice regularly to stay informed about how your data is protected and used.
Contact and Further Information
If you wish to exercise your rights or have questions regarding this policy, you may contact us through our main business address. Our team is committed to protecting your information and responding to your enquiries promptly and transparently.
This policy was last updated in June 2024.