Eastcote Flowers Privacy Policy
Introduction
This Privacy Policy outlines how Eastcote Flowers collects, uses, stores, and protects the personal data of customers placing orders from Eastcote and the surrounding districts. In line with the General Data Protection Regulation (GDPR), we are committed to ensuring the privacy and security of our customers' personal information. By placing an order with Eastcote Flowers, you agree to the practices described in this policy.
Scope of this Privacy Policy
This policy applies to all customers who purchase or inquire about products and services offered by Eastcote Flowers, whether through our website, by phone, or in-person within Eastcote and neighboring districts. We aim to be transparent about our data practices and your rights under GDPR.
Personal Data We Collect
Eastcote Flowers may collect and process the following personal data from you:
- Contact Information: Name, address, delivery address, postcode, and contact preferences.
- Communication Data: Correspondence between you and Eastcote Flowers regarding orders, queries, or complaints.
- Order Information: Details of products ordered, delivery instructions, and any specific notes provided to personalize your order.
- Payment Information: Limited payment information necessary for processing transactions; payment card data is managed securely and may be processed by designated payment providers.
- Technical Data: Log data or device information may be collected through our website to ensure functionality and enhance your experience.
Lawful Basis for Processing
Eastcote Flowers processes your personal data only where there is a lawful basis to do so, as required under GDPR. These include:
- Performance of a Contract: To fulfill your flower order, manage payments, and provide customer service.
- Legal Obligation: To comply with applicable laws and regulatory requirements (e.g., record-keeping for financial reporting).
- Legitimate Interests: To improve our services, handle inquiries or complaints, and ensure the security of our website and operations. We consider and balance any potential impact on your rights before processing data under this basis.
- Consent: Where you have provided explicit consent (e.g., for marketing communications), we will process your data for that purpose. You may withdraw consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing your orders, delivering flowers, and managing payments;
- Communicating with you regarding order status, delivery, and customer support inquiries;
- Improving our products and services based on feedback and usage patterns;
- Complying with legal and regulatory obligations;
- Informing you about promotions or updates, if you have consented to receive such communications.
Retention of Your Data
Eastcote Flowers retains your personal data only for as long as necessary to fulfill the purposes outlined in this policy, including for satisfying any legal, accounting, or reporting requirements. Typically, order and transaction records are retained for a minimum of six years to comply with tax and legal obligations. Communication and marketing data will be retained until you withdraw consent or opt out.
Once your personal data is no longer required, it will be securely deleted or anonymized, unless retention is required for legal purposes.
Data Processors and Third Parties
To deliver our services efficiently, Eastcote Flowers engages selected third parties ("processors") who may process your personal data under our instructions. These may include:
- Payment Processors: Secure third-party providers handle card payments and financial transactions. We do not store your full payment card details.
- Delivery Partners: Couriers or local delivery services may receive details necessary to deliver your order.
- IT and Website Providers: Technical service providers assist in hosting our website and managing data security.
All processors are contractually obligated to process personal data securely and only for the specified purposes related to service delivery. We do not sell or share your data with third parties for their own marketing purposes.
Your Rights Under GDPR
As a customer placing orders with Eastcote Flowers, you are entitled to the following rights concerning your personal data:
- Right to Access: You may request a copy of personal data Eastcote Flowers holds about you.
- Right to Rectification: You may ask to correct or update your data if it is inaccurate or incomplete.
- Right to Erasure: Also known as the "right to be forgotten", you may request the deletion of your personal data, subject to certain legal obligations.
- Right to Restrict Processing: You may ask us to limit the processing of your data under certain circumstances.
- Right to Data Portability: You may request to receive your data in a commonly used and machine-readable format to transfer it to another provider.
- Right to Object: You may object to certain types of data processing, such as direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to Lodge a Complaint: You have the right to complain to a data protection authority if you are dissatisfied with how your data is handled.
Security of Your Data
We have implemented appropriate technical and organizational measures to safeguard your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Our staff and approved processors adhere to strict confidentiality and data protection standards.
Changes to This Policy
Eastcote Flowers may review and update this Privacy Policy periodically to reflect changes in our practices or legal obligations. Any substantial amendments will be made available through our usual communication channels. Customers are encouraged to check this policy regularly to stay informed.
Contact and Further Information
If you have any questions regarding this Privacy Policy or wish to exercise your GDPR rights, please contact us using the details provided through our official channels. We are dedicated to responding promptly and ensuring your data rights are respected.
