Harold Hill Florist Privacy Policy
Overview
This Privacy Policy sets out how Harold Hill Florist collects, processes, and protects the personal data of all customers who place orders with us, whether online, in-store, or via phone, and applies specifically to customers based in Harold Hill and surrounding districts. We are committed to upholding your privacy rights and ensuring transparency in line with the EU General Data Protection Regulation (GDPR) and applicable UK data protection laws. Please review this policy to understand what data we collect, how we use it, and your rights regarding your personal information.
What Data We Collect
To provide our services effectively, Harold Hill Florist collects the following types of personal data as necessary for order processing and customer service:
- Identifying Information: Name, delivery address, billing address, and contact details (such as phone number).
- Order Details: Purchase history, chosen delivery date, product preferences, and any personalized messages for card inscriptions.
- Payment Information: We collect necessary payment details for transaction processing, such as card or bank information. Note that sensitive payment data is handled via secure third-party payment processors (see below), and is not stored by Harold Hill Florist unless a retention period is legally mandated.
- Communication Records: Correspondence with customer service, feedback, and any complaint details.
- Website Usage Information (if applicable): Technical data received via cookies, IP address, browser type, and device identifiers when using our website to place orders.
Lawful Basis for Processing Your Data
Harold Hill Florist processes your personal data according to one or more of the following lawful bases in compliance with GDPR:
- Contract: Most data is processed to fulfill our contract with you, i.e., to process, fulfill, and deliver your orders and communicate with you about them.
- Legal Obligation: Certain data retention and processing may be required by law, such as the need to retain invoices or transaction records for tax purposes or to comply with regulatory requirements.
- Legitimate Interests: We may use your information where necessary for our legitimate interests, provided these do not outweigh your rights and freedoms. This includes internal record-keeping, analytics, or quality management.
- Consent: In specific cases, where required (for example, for marketing communications not directly related to your order), we will obtain your explicit consent and you have the right to withdraw this consent at any time.
How We Use Personal Data
We use your personal data to:
- Process and deliver your flower orders as requested.
- Contact you about your order, delivery status, or to clarify details.
- Improve our services by analyzing order trends and customer preferences.
- Maintain accurate records for compliance and accounting.
- Send marketing updates or offers (only if you have given explicit consent).
Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes it was collected for, including for satisfying any legal, accounting, or reporting requirements. Typically:
- Order and identification data: Retained for up to 7 years to comply with tax and business record requirements.
- Payment data: Handled by third-party processors, with only transaction references kept by us as required by law.
- Marketing consent: Retained until you withdraw your consent or request deletion.
- Communication records: Retained for up to 3 years post-interaction for quality and complaint monitoring.
Once data is no longer required, it is securely deleted or anonymised.
Processors and Third Parties
Your personal data may be shared with third-party processors strictly as necessary to fulfill your order or improve service. These include:
- Payment Providers: Trusted payment gateway partners process transaction data securely.
- Delivery Partners: Courier or delivery companies are provided with your delivery address and contact information for fulfillment of your order.
- IT and Software Providers: Website hosting services, order management systems, or technical support parties that help maintain and improve our digital services.
All third-party processors are required to adhere to data protection requirements in accordance with GDPR and act only under our instructions. Harold Hill Florist never sells your personal data to third parties.
Your Data Protection Rights
Under GDPR, you have several rights in relation to your personal information. These include:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to have inaccurate or incomplete data corrected.
- Right to Erasure: Known as the "right to be forgotten", you may request deletion of your data when it is no longer needed or upon withdrawal of consent (where applicable), subject to certain legal exceptions.
- Right to Restriction: You may ask us to restrict how we process your data in certain circumstances.
- Right to Portability: Request your data in a portable format to transfer to another provider, where technically feasible.
- Right to Object: Object to certain processing activities, such as receiving direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time; this does not affect previous lawful processing.
To exercise these rights, please contact us using the contact options provided on our website or in store. We may need to verify your identity before processing your request to protect your data privacy.
Data Security
We take the protection of your data seriously and implement suitable technical and organizational measures to prevent unauthorized access, disclosure, alteration, or destruction. Access to customer information is restricted to personnel, agents, and processors on a need-to-know basis only, all of whom receive regular data protection training.
Policy Changes
This Privacy Policy may be reviewed and updated from time to time to ensure ongoing GDPR compliance and to reflect changes in our services or legal requirements. We encourage you to review this policy periodically.
Contact and Complaints
If you have questions about this Privacy Policy, or wish to exercise your data rights, please use the contact information provided on our website or speak to our staff in store. Should you feel your data has not been handled properly, you are also entitled to lodge a complaint with the UK Information Commissioner's Office or your local supervisory authority.