Flowers St John's Wood Privacy Policy

Introduction

This Privacy Policy explains how Flowers St John's Wood collects, uses, stores, and protects your personal data when you place an order with us, either directly or through affiliated services. Our commitment to safeguarding your privacy is paramount, and we adhere to the requirements of the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders from St John's Wood and surrounding districts.

What Data We Collect

When you place an order with Flowers St John's Wood, we may collect and process the following categories of personal data:

  • Identity Data: Full name, title
  • Contact Data: Delivery address, billing address, telephone number (where provided)
  • Order Details: Description of products or services purchased, notes attached to orders
  • Payment Data: Payment details (handled securely through payment processors and not stored by us directly)
  • Transaction Data: Records of payments, fulfillment details, invoices, and purchase history
  • Technical Data: IP address, device information, browser type (collected via website analytics tools for security and performance)

We do not intentionally collect any special category (sensitive) data, such as health, race, or biometric information.

Lawful Basis for Data Processing

Flowers St John's Wood only processes your personal data when we have a lawful basis for doing so. The lawful bases relevant to our processing activities include:

  • Contractual Necessity: To fulfill your order and deliver products or services as requested.
  • Legitimate Interests: To communicate with you about your order, improve our services, and ensure the security of our operations, provided that these interests are not overridden by your rights.
  • Legal Compliance: To meet statutory or regulatory requirements, such as maintaining financial and tax records.
  • Consent: Where required (for example, for direct marketing communications), we will seek your explicit consent and give you the right to withdraw it at any time.

Data Retention Periods

We only retain your personal data for as long as necessary for the purposes for which it was collected, including:

  • Order fulfillment and record-keeping
  • Accounting and legal obligations
  • Customer care and dispute resolution

Generally, we retain personal data related to orders for up to 6 years to comply with accounting and tax requirements. Data used for marketing or communications purposes is retained only as long as you remain subscribed and have not withdrawn consent.

Third-Party Data Processors

To operate efficiently and provide the best service possible, Flowers St John's Wood uses trusted third-party service providers ("data processors"). These processors may include:

  • Payment processors for securing and handling online payments
  • Delivery and courier services to fulfill orders
  • IT and cloud service providers to maintain our website, order management, and secure data storage
  • Professional support services such as accounting or legal advisors when necessary

All third-party processors are contractually obligated to process your personal data securely, only as instructed by us, and strictly in accordance with GDPR.

Your Rights Under GDPR

The GDPR grants you various rights regarding your personal data. These include:

  • Access: You can request details of the personal data we hold about you.
  • Rectification: You can request corrections to any inaccurate or incomplete data.
  • Erasure: You can request deletion of your data, subject to certain exceptions (for example, compliance with legal obligations).
  • Restriction: You can request restriction of processing in specific circumstances.
  • Objection: You may object to processing where we rely on legitimate interests or direct marketing.
  • Portability: You may request a copy of your data in a structured, commonly used format.
  • Withdrawal of Consent: Where processing relies on your consent, you may withdraw this at any time without affecting the lawfulness of prior processing actions.

You have the right to raise concerns or lodge a complaint with your local data protection authority if you believe your data has been mishandled.

Data Security

We are committed to maintaining the security of your personal data. We implement appropriate technical and organizational measures to prevent unauthorized access, disclosure, alteration, or destruction. Access to data is limited to employees and processors who need access to fulfill orders or carry out required functions, and all such individuals are subject to confidentiality obligations.

International Data Transfers

As a general policy, Flowers St John's Wood seeks to store and process your data within the UK or the European Economic Area (EEA). Should we need to use data processors located outside these areas, we will ensure appropriate safeguards are in place as required by GDPR.

Policy Updates

We may update this Privacy Policy from time to time to reflect changes in our business practices, legal requirements, or technology. We encourage customers to review this policy periodically to stay informed.

Scope of Policy

This Privacy Policy applies to all customers who place orders with Flowers St John's Wood from St John's Wood and the surrounding districts. By placing an order, you acknowledge the terms detailed in this policy.

Contact and Queries

If you have any questions or concerns about how your data is handled, or if you wish to exercise any of your rights under GDPR, please contact us using the contact methods displayed on our website or customer correspondence materials.