Florist Richmond GDPR Privacy Policy for Customers
Introduction
At Florist Richmond, we are deeply committed to protecting the privacy and personal data of our customers. This Privacy Policy explains how we collect, use, process, and safeguard your personal information under the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Florist Richmond from Richmond and the surrounding districts.
What Data We Collect
When you order flowers or related products from Florist Richmond, we collect various types of personal data that are necessary to process and fulfil your order. The categories of personal data we may collect include:
- Identification Details: Name, delivery recipient's name (if different)
- Contact Information: Phone number, delivery address, and any provided notes for delivery
- Order Details: Bouquet or product selection, customisation preferences, gift messages
- Payment Information: Transaction details (note: we do not directly store your full payment card details; these are processed securely by appointed payment processors)
- Communications: Any correspondence you have with us (such as feedback, enquiries, or complaints)
- Technical Data: IP address, browser type, device information, and interactions with our website (collected via essential cookies and analytics tools for service improvement)
Lawful Basis for Processing Your Data
Florist Richmond collects and processes your personal data based on specific lawful bases as described in Article 6 of the GDPR. These are:
- Contractual Necessity: Most of the data we collect is necessary to enter into and fulfil the contract of sale, process your order, and handle delivery.
- Legal Obligation: We may need to process your information to comply with applicable laws or regulatory requirements (for example, in relation to transaction record-keeping).
- Legitimate Interests: We may use your data for legitimate business interests such as improving our services, ensuring customer satisfaction, or handling queries and complaints, provided these do not unjustifiably infringe on your rights.
- Consent: Where we rely on consent (for example, for certain marketing communications), you will always have the option to withdraw your consent at any time.
How We Use Your Data
We use your personal information solely for the purposes for which it was provided and as otherwise permitted by law. These purposes typically include:
- Processing and fulfilling your orders, including delivery arrangements
- Providing customer support and responding to your enquiries
- Managing payments and preventing fraudulent transactions
- Improving our website, services, and customer experience
- Complying with applicable laws and regulations
Data Retention
We retain your personal data only for as long as is necessary to fulfil the purposes noted above, including for the purposes of satisfying any legal, accounting, or reporting requirements. The specific retention periods depend on the type of data and the reasons we hold it. Generally:
- Order and Transaction Data: Kept for up to 6 years to comply with legal obligations and for tax purposes.
- Customer Correspondence: Retained for up to 2 years after your last contact with us.
- Marketing Consent Records: Retained until you withdraw consent or until a reasonable period has elapsed after our last interaction.
After these retention periods, your data will be securely deleted or anonymised.
Third-Party Processors
We work with trusted third-party service providers to help us deliver our products and services. These may include:
- Payment processing companies
- Delivery and courier services
- Information technology and website hosting providers
- Professional advisers (e.g., accountants or legal professionals)
All third-party processors are contractually obliged to process your personal information only according to our instructions, to use appropriate technical and organisational measures, and not to use your data for their own purposes. Where these processors are outside of the UK or European Economic Area, we ensure appropriate safeguards are in place.
Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of Access: To request information about the personal data we hold about you.
- Right to Rectification: To require us to correct inaccurate or incomplete data.
- Right to Erasure: To request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to Restrict Processing: To ask us to temporarily stop using your data in certain circumstances.
- Right to Data Portability: To receive your personal data in a commonly used, machine-readable format or ask us to transfer it to another provider.
- Right to Object: To object to the processing of your data when we rely on legitimate interests as a lawful basis.
- Right to Withdraw Consent: Where we process your data based on consent, you can withdraw it at any time.
To exercise any of these rights, please contact us using the details provided on our main website or in your order confirmation’s documentation.
Data Security
We take data security seriously and implement technical and organisational safeguards to protect your personal information from accidental loss, unauthorised access, use, alteration, or disclosure. These measures include secure server environments, encryption of data in transit, and restricted staff access to personal data.
Policy Updates
We may occasionally update this Privacy Policy to reflect legal, regulatory, or operational changes. If we make significant changes, we will notify customers by posting a clear notice on our website prior to the changes taking effect. We encourage you to review this policy periodically to remain informed about your rights and our practices.
Contact and Complaints
If you have any questions about this Privacy Policy, our data protection practices, or if you wish to make a complaint, please use the contact details available on our website. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).