Clerkenwell Florist Privacy Policy
About This Privacy Policy
This Privacy Policy explains how Clerkenwell Florist ("we," "our," or "us") collects, uses, stores, and protects your personal information in compliance with the General Data Protection Regulation (GDPR). This policy applies to all customers who place orders for products or services with Clerkenwell Florist from Clerkenwell and the surrounding districts. Our commitment to your privacy means handling your information with transparency, care, and respect.
Personal Data We Collect
To fulfill your orders and provide you with our services, we may collect the following categories of personal data:
- Identity Data: This includes your name, and the names of recipients (if you are ordering flowers for someone else).
- Contact Data: Your delivery address, billing address, and location information; this also includes recipient addresses.
- Order Information: Details of the products or services you purchase from us, purchase history, and any special instructions related to the order.
- Payment Data: Transaction details necessary for processing payments, such as payment method, card number (processed securely by payment processors), and payment confirmation details.
- Correspondence Data: Information you provide when you communicate with us, whether by phone, in writing, or in-person at our shop, including queries, feedback, or complaints.
- Technical Data: Limited data when you interact with us digitally, such as IP addresses, browser types, device information, and access times. We only collect these for security and analytics purposes where applicable.
We do not collect or process any special categories of personal data (sensitive data) unless required by law or you explicitly provide it for service purposes.
Lawful Basis for Processing
Under GDPR, we must have a lawful basis to collect and process your data. The main lawful bases under which we process your data are as follows:
- Contractual Necessity: Most of the data collection described above (such as identity and contact data) is necessary for us to process and deliver your orders, issue you with invoices, and provide customer service.
- Legal Obligation: We may process and retain your data to comply with applicable laws, such as those related to accounting, tax, and fraud prevention.
- Legitimate Interests: We may use your data to improve our services, respond to your queries, and enhance your overall customer experience, provided these interests are not overridden by your rights and interests.
- Consent: In cases where we use your information for purposes beyond the performance of a contract or legal compliance (such as sending marketing information), we will seek your explicit consent, which you may withdraw at any time.
How We Use Your Data
We use your personal data to:
- Verify your identity and process your orders
- Deliver flowers and related products to you or specified recipients
- Process payments and issue invoices or receipts
- Contact you with updates regarding your order or in response to your inquiries
- Maintain our business accounts and records
- Improve our services by analyzing customer preferences and feedback
- Comply with legal obligations (such as maintaining mandatory business records)
Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes outlined in this privacy policy, including for the purposes of satisfying any legal, accounting, or reporting requirements. Typically, customer and order data are retained for up to seven years to comply with tax and financial regulations. After this period, data is securely deleted or anonymized.
Third-Party Processors
To provide certain services, we may need to share your information with third-party service providers, also known as data processors. We only use processors that adhere to GDPR and relevant data security standards. These may include:
- Payment Processing Providers: Companies that manage your online card transactions. Clerkenwell Florist does not store your full payment details; these are handled directly by the payment processor.
- Delivery and Logistics Partners: Couriers and postal services that assist in delivering your orders to the specified address.
- IT and Technical Support: Providers who maintain our ordering systems, website, or email hosting services.
All data processors are contractually obligated to safeguard your personal data and process it only as instructed by us. We never sell or rent your personal data to third parties.
Your Rights as a Data Subject
Under the GDPR, you have a number of important rights in relation to your personal data, including:
- Right to Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You may ask us to update or correct inaccurate or incomplete data.
- Right to Erasure: In certain circumstances, you can request the deletion of your personal data, for example, if it is no longer necessary for the purposes for which it was collected.
- Right to Restrict Processing: You can ask us to restrict the processing of your data in certain circumstances, such as while we consider a correction request.
- Right to Data Portability: You may request that we provide you with your data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
- Right to Object: You have the right to object to certain types of processing, including direct marketing.
- Right to Withdraw Consent: Where you have given consent for us to process your data, you may withdraw your consent at any time.
To exercise any of these rights, you may contact us via the contact methods detailed on our website or in-store. We may need to verify your identity before processing your request for security reasons.
Data Security
We have implemented appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, use, alteration, or disclosure. These measures include staff training, password protection, secure payment processing, and restricted system access. In the unlikely event of a data breach, we will notify you and the relevant supervisory authorities as required by law.
Changes to This Policy
We may occasionally update this Privacy Policy to reflect changes in our legal obligations or business practices. We recommend reviewing this notice periodically to stay informed about how your information is protected.
Contact and Complaints
If you have any questions, concerns, or requests regarding your personal data or this privacy policy, please use the contact methods provided on our website or speak to a team member in-store. If you feel your data protection rights have not been respected, you also have the right to lodge a complaint with the relevant supervisory authority in the United Kingdom.