Florist Totteridge Privacy Policy

About This Privacy Policy

This Privacy Policy explains how Florist Totteridge collects, uses, processes, and protects the personal data of customers ordering floral products and services from Totteridge and the surrounding districts. The policy follows the requirements set out under the General Data Protection Regulation (GDPR) and applies to all customers engaging with Florist Totteridge, whether online, by telephone, or in person.

What Data We Collect

Florist Totteridge collects personal information in order to fulfill orders and provide an improved customer experience. The types of data we may collect include:

  • Identity Information: Your full name and, where necessary, the recipient's name.
  • Contact Information: Delivery address, billing address, and contact preferences.
  • Order Details: The products or services ordered, personalised messages, order notes, or card inscriptions.
  • Payment Information: Details necessary to process payments (such as part of your payment card details, processed through secure third-party payment processors; we do not store full card numbers).
  • Correspondence: Any communications with us, including enquiries, feedback, or complaints.
  • Technical Data: When using our website, we may automatically collect information such as IP address, browser type, device identifiers, cookies, and other analytical data.

Lawful Basis for Processing Personal Data

Florist Totteridge only processes your personal data where there is a lawful basis. The grounds on which we rely include:

  • Contractual Necessity: To fulfill our contract with you, such as taking your order, processing payment, delivering flowers, and responding to customer service requests.
  • Legal Obligation: Where we are required to comply with legal and regulatory obligations, such as taxation and record-keeping requirements.
  • Legitimate Interests: To improve our products and services, maintain business records, prevent fraud, or conduct limited marketing communications that may be of interest to you, provided your rights and interests do not override these activities.
  • Consent: Where we send promotional communications by electronic means, we rely on your explicit consent. You may withdraw consent at any time.

How We Use Your Data

Your personal information may be used for the following purposes:

  • Processing and delivering your orders, including sending order confirmations and updates.
  • Managing payments and refunds (via secure payment processors).
  • Handling customer enquiries or complaints.
  • Complying with our legal and regulatory obligations.
  • Improving our website, products, and services through analysis of usage data.
  • Occasionally informing you of news, offers, or services (with your consent as required).

Retention of Your Data

Florist Totteridge retains your personal data only for as long as necessary for the purposes for which it was collected, or as long as required by applicable laws and regulations. Typically:

  • Order-related data is kept for up to six years to comply with legal and financial record-keeping requirements.
  • Communications and correspondence may be retained for up to two years after the resolution of your enquiry.
  • Where data is processed based on your consent, it will be deleted promptly if you withdraw your consent.
  • After the applicable retention period, your information will be securely deleted, anonymised, or destroyed.

Data Processors and Sharing of Data

Florist Totteridge only shares your data with trusted third parties who assist us in delivering our services, known as data processors. These may include:

  • Payment processing providers who manage card transactions securely.
  • Delivery partners involved in the physical delivery of orders.
  • IT and website support providers who help maintain and develop our systems.
  • Professional advisers (such as accountants) and entities as required by legal or regulatory authorities.

All processors are required to handle your information securely and only for the purposes specified. They are contractually bound not to use your data for their own purposes.

Your Rights Under GDPR

As a customer of Florist Totteridge, you have certain rights regarding your personal data. These include:

  • Right of Access: Request to see the personal data we hold about you.
  • Right to Rectification: Request corrections to your personal information if it is incomplete or inaccurate.
  • Right to Erasure ("Right to be Forgotten"): Ask us to delete your personal data in certain circumstances.
  • Right to Restrict Processing: Request limited use of your data in certain cases.
  • Right to Data Portability: Obtain your data in a commonly used electronic format.
  • Right to Object: Object to processing where we rely on legitimate interest (including for marketing purposes).
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe your data is not being processed in accordance with GDPR.

Security of Your Data

Florist Totteridge takes your privacy seriously. We implement technical and organisational measures to safeguard your personal data against loss, misuse, unauthorised access, disclosure, or alteration. These measures are regularly reviewed and updated as necessary.

International Transfers

Your personal data is principally processed within the United Kingdom and European Economic Area. In cases where information is transferred outside these areas by third-party processors, we ensure appropriate safeguards are in place as required by GDPR, such as ensuring standard contractual clauses are used, or the processor is certified under an adequate scheme.

Changes to This Privacy Policy

Florist Totteridge may update this Privacy Policy from time to time to reflect changes to our practices or legal obligations. Any significant updates will be clearly communicated to customers, where necessary. The current version of the Privacy Policy will always be available for review before placing an order.

Contacting Florist Totteridge About Privacy

If you have any questions regarding this Privacy Policy, your personal data, or wish to exercise any of your rights, please contact us in writing or visit our store during business hours. Customer service will assist you with your queries and requests regarding data protection.