Barkingside Florist - GDPR-Compliant Privacy Policy
Introduction
This Privacy Policy explains how Barkingside Florist collects, uses, protects, and stores your personal data when you place orders with us in Barkingside and surrounding districts. We are dedicated to complying with the General Data Protection Regulation (GDPR) and to protecting your privacy at all times.
Scope of Policy
This policy applies to all customers who place orders through Barkingside Florist, whether via phone, in person at our store, or through our website, for delivery or pick-up in Barkingside and the surrounding areas. By placing an order, you acknowledge that your personal data will be processed in accordance with this policy.
What Data We Collect
When you interact with Barkingside Florist, we may collect the following types of personal data:
- Identification Data: Your name, title, and, where applicable, company or recipient's name.
- Contact Details: Delivery address, phone number, and other contact details you provide, such as recipient information for deliveries.
- Order Information: Records of products you order, delivery preferences, messages for gift cards, and transaction details.
- Payment Data: Payment method information required to process your order. We do not store full payment card details; these are handled by our secure payment processors.
- Communication Records: Notes from calls, inquiries, feedback, or complaints you make.
- Website Data: Technical data such as cookies, IP address, browser type, and usage data if you place an order online (cookie data is explained in our separate Cookie Policy).
Lawful Basis for Processing Data
Under GDPR, personal data must be processed under a valid lawful basis. Barkingside Florist processes your personal data based on one or more of the following:
- Performance of Contract: Processing is necessary for fulfilling your order and related customer service.
- Legal Obligation: We may need to process data to meet legal requirements, such as accounting and tax records.
- Legitimate Interests: We may process your data for our legitimate business interests, such as improving customer experience and preventing fraud. When we do so, we balance our interests with your rights and freedoms.
- Consent: Where required, we will seek your explicit consent, for example, for marketing communications (optional and separate from order processing).
How We Use Your Data
Barkingside Florist uses your personal data for the following purposes:
- Processing and delivering your flower or gift orders
- Communicating with you about your order, including confirmations and delivery updates
- Handling payment transactions
- Providing customer support, responding to inquiries, and resolving complaints
- Complying with legal obligations and record-keeping requirements
- Improving our products, services, and user experience
- Where you have opted in, sending you special offers or updates by your preferred communication method (you may opt out at any time)
How Long We Keep Your Data (Data Retention)
Barkingside Florist retains your personal data only as long as necessary to fulfil the purposes for which it was collected, as well as to comply with legal, accounting, and regulatory obligations. Generally, we keep order and customer records for a period of up to seven years to meet business and legal requirements. Customer communications and queries are retained for no more than two years unless a longer retention period is required for the resolution of a specific issue. Payment data is processed only as necessary and is not retained beyond completion of the transaction, except where required for dispute resolution.
Processors and Sharing of Data
We value your privacy and do not sell your personal data to third parties. However, we may share your data with third-party service providers (processors) who support us in providing our services. These include, but are not limited to:
- Payment processors, who handle secure transaction processing
- Delivery partners, to fulfil order deliveries to your specified address
- IT service providers, such as website hosting and data storage providers
- Professional advisors (e.g., accountants, auditors) for legal or business reasons
- Regulatory authorities, if required by law
All processors are contractually required to protect your data and only process it according to our instructions, under strict confidentiality and security standards.
How We Protect Your Data
We implement technical and organisational measures to safeguard your data against loss, theft, access, or disclosure. These include physical security in our shop, access controls, staff training, encrypted websites, and secure payment gateways. Whilst we take all reasonable steps to protect your information, transmitting data over the internet is never 100% secure, and you provide data at your own risk.
Your Rights under GDPR
As a customer placing an order with Barkingside Florist, you have several rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct or update inaccurate or incomplete data.
- Right to Erasure: You have the right to request that we delete your data, where there is no overriding legal justification for its retention.
- Right to Restrict Processing: You can request that we limit the way we use your data.
- Right to Data Portability: You can request that your data be provided to you or transferred to another provider, where technically feasible.
- Right to Object: You can object to certain types of processing, such as direct marketing.
- Right to Withdraw Consent: If processing is based on your consent, you may withdraw it at any time (this does not affect past processing based on prior consent).
- Right to Lodge a Complaint: You may lodge a complaint with the Information Commissioner’s Office or your local supervisory authority if you believe your rights have been infringed.
Changes to This Policy
Barkingside Florist may update this Privacy Policy as needed to reflect changes in our practices or legal requirements. The latest version will always be available in-store and on our website. We encourage you to review this policy periodically.
Further Information and Contact
If you have any questions or wish to exercise your GDPR rights regarding your personal data held by Barkingside Florist, please contact us using the details provided in-store or via our official website.