Your Privacy & Data Security at Deptford Florist

Introduction

This Privacy Policy outlines how Deptford Florist collects, uses, discloses, and protects your personal data in accordance with the requirements of the UK General Data Protection Regulation (GDPR). This policy applies to all customers who place orders with Deptford Florist for delivery in Deptford and surrounding districts. By placing an order with us, you agree to the terms described in this Privacy Policy.

What Data We Collect

To provide our services, we collect and process various types of data:

  • Personal Identification Data: Your full name, billing and delivery addresses.
  • Contact Details: Telephone number, and if provided, an email address.
  • Order Information: Details of the floral products or gifts purchased, messages to recipients, and transaction details.
  • Payment Information: Depending on your payment method, payment information may be processed by an external payment provider, and Deptford Florist only receives confirmation of payment status (never your card or banking details directly).
  • Communication Records: Any correspondence or feedback you send us, including customer service requests.

We do not knowingly collect any data from children under 16 years of age.

Lawful Bases for Processing

Deptford Florist processes your personal data on the following lawful bases in accordance with GDPR:

  • Contractual necessity: When you provide your data to place an order and to enable us to fulfil our contract with you (processing and delivering your order, processing payments, resolving issues).
  • Legitimate interests: For purposes such as improving our products and services, preventing fraud, and maintaining the security of our systems, as long as these do not override your individual rights and freedoms.
  • Legal obligations: To comply with legal and regulatory requirements, such as accounting and tax obligations.
  • Consent: In certain cases, where required by law, we will obtain your consent (such as for marketing communications). You may withdraw your consent at any time.

How We Use Your Data

Your personal data may be used by Deptford Florist for the following purposes:

  • Processing and delivering your orders, including contacting you or your recipient if needed for delivery purposes.
  • Managing your customer account, if applicable.
  • Responding to your queries, feedback and customer service requests.
  • Complying with our legal and regulatory obligations.
  • Preventing fraudulent transactions, ensuring the security of our website and operations.
  • (Where you have opted in) Sending you marketing information about our products or special offers.

Data Retention

Deptford Florist retains your personal data only as long as necessary for the purposes for which it was collected, to comply with legal obligations, or to resolve disputes. The main retention periods are as follows:

  • Order Data: Typically retained for six (6) years after the end of the relevant financial year, as required by accounting and tax regulations.
  • Communications: Kept as long as necessary to address your enquiries and maintain our business records.
  • Marketing Data: If you have opted in, we will keep your preferences until you unsubscribe or request deletion.

When your data is no longer needed, it will be securely deleted or anonymised.

Data Processors and Sharing

We may share your data with trusted third parties ('processors') for the purpose of fulfilling orders, processing payments, or supporting our business operations. These can include:

  • Payment service providers who process your payment information securely.
  • IT service providers who host our order and customer management systems.
  • Delivery and courier companies to ensure your orders reach the intended recipients.
  • Professional advisers (accountants, auditors) where legally required.

All processors are contractually bound to process your data only on our behalf, using appropriate security measures, and in line with GDPR. We do not sell or rent your data to any third parties.

Your personal data will not be transferred outside the United Kingdom or the European Economic Area (EEA) unless sufficient safeguards are in place and in compliance with GDPR requirements.

Your Data Protection Rights

Under GDPR, you have several important rights:

  • Right to Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: Request correction of incomplete or inaccurate data.
  • Right to Erasure: Ask for deletion of your data, where legally permitted.
  • Right to Restrict Processing: You can request that we restrict the processing of your data in certain circumstances.
  • Right to Data Portability: Obtain your data in a structured, commonly used, machine-readable format and transmit it to another controller.
  • Right to Object: Object to our processing of your personal data on grounds relating to your particular situation. You can also object to receiving marketing communications at any time.
  • Right to Withdraw Consent: Where processing is based on consent, withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.

To exercise any of these rights, please contact us in writing. Verification of your identity may be required before processing your request.

Security of Your Data

Deptford Florist takes the security of your information seriously. We implement appropriate technical and organisational measures to protect your data against loss, misuse, unauthorised access, disclosure, alteration, and destruction. Access to your personal data is strictly limited on a need-to-know basis.

Updates to This Privacy Policy

This Privacy Policy is kept under regular review to reflect changes to our practices or legal requirements. Significant updates will be communicated appropriately. We encourage you to review this policy periodically to stay informed about how we process your personal data.

Contact and Queries

If you have questions about this Privacy Policy or your rights under GDPR, please contact us using the details provided on our website or at our shop premises.