Privacy Policy for East Dulwich Florist Customers
  Introduction
This Privacy Policy describes how East Dulwich Florist collects, uses, and protects personal data provided by customers placing orders with us from East Dulwich and the surrounding districts. We are committed to maintaining the confidentiality, integrity, and security of your personal data, in full compliance with the General Data Protection Regulation (GDPR) and other relevant data protection laws.
Scope of Policy
This policy applies to all individuals who place orders with East Dulwich Florist, whether through our retail location, telephone, or electronic means, as long as the delivery address or main service requirement is within East Dulwich or the neighbouring districts.
Data We Collect
As part of our provision of floristry services, we collect and process various types of personal data, which may include:
- Contact details: Your full name, delivery address, billing address (if different), telephone number, and where relevant, your email address.
- Order details: Information about the products and floral arrangements you order, delivery preferences, and special instructions.
- Recipient information: If you are ordering flowers for delivery to another individual, their name, address, and contact telephone number.
- Payment information: Details necessary to process your payment (e.g., card details), which are handled securely by our payment partners and not retained by us.
- Correspondence: Records of any communications between you and East Dulwich Florist regarding your order or our services.
- Technical information: When you use our website, we may collect your IP address, browser type, and information provided by cookies, necessary for site functionality and analytics.
Lawful Bases for Processing Your Data
Under GDPR, we must have a lawful basis for processing your personal data. East Dulwich Florist relies on the following bases:
- Contractual necessity: Processing your data is necessary to fulfil your order and provide the services you request.
- Legal obligations: We may be required to process certain data to comply with accounting, tax, or other legal requirements.
- Legitimate interests: We may process limited data to improve our services, respond to queries, or send occasional updates, provided these interests are not outweighed by your rights and interests.
- Consent: Where we process your data beyond the above bases, for example, for marketing not directly related to a recent order, we will seek your explicit consent, which you may withdraw at any time.
How We Use Your Information
Your personal data is used to:
- Process, fulfil, and deliver your flower orders
- Communicate with you regarding your order, delivery or any inquiries
- Handle payments and maintain accurate records
- Comply with legal and regulatory requirements
- Improve our products and customer service
How Long We Keep Your Data (Retention)
We only retain your personal data for as long as necessary to achieve the purposes described above. Typically, order and transaction data is stored for up to six years to comply with tax, legal, and accounting requirements. Any information processed solely with your consent (not required for contractual or legal purposes) will be deleted on request or within twelve months of your original consent, unless renewed.
Data Processors and Third Parties
East Dulwich Florist may share personal data with trusted third-party providers who act as data processors on our behalf. This includes:
- Payment processing companies to handle card transactions
- IT service providers supporting our electronic systems
- Delivery partners if required to ensure successful delivery of orders
- Professional advisors (such as accountants) where required by law
All data processors are contractually bound to process your data only as instructed by East Dulwich Florist and must adhere to high standards of security and confidentiality. We do not share or sell your data for marketing purposes to third parties outside the scope of your orders.
Protection of Your Data
We implement appropriate technical and organisational measures to protect your data from unauthorised access, alteration, disclosure, or destruction. This includes secure storage, access controls, encryption where appropriate, and staff training on data protection responsibilities.
Your Rights under GDPR
As a customer, you have the following rights regarding your personal data:
- Right of access: You can request information about the personal data we hold about you and how we use it.
- Right of rectification: You may ask us to correct inaccurate or incomplete personal information.
- Right to erasure: Also known as the 'right to be forgotten,' you can request that we delete your personal data, provided there is no overriding legal reason for us to retain it.
- Right to object: You have the right to object to any data processing based on our legitimate interests.
- Right to restriction: You may request that we restrict processing of your data in certain circumstances.
- Right to data portability: Where applicable, you can request a copy of your personal data in a structured, commonly used, and machine-readable format.
- Right to withdraw consent: If we process your data based on consent, you can withdraw this at any time.
Policy Updates
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The latest version will always be available at our store and on our website.
Contact and Queries
If you have questions, concerns, or wish to exercise any of your data rights under GDPR, please contact us using the contact methods advertised in our store or on our official website. We are committed to working with you to resolve any concerns regarding your privacy and our handling of your data.