Crayford Florist Privacy & Data Protection Policy
Introduction
This Privacy Policy explains how Crayford Florist collects, processes, stores, and protects personal information relating to our customers placing orders in Crayford and surrounding districts. We are committed to respecting your privacy and complying with the requirements of the UK General Data Protection Regulation (GDPR). This policy informs you about your rights, the types of information we collect, our purpose for collecting it, and how it is managed.
What Personal Data We Collect
When you place an order or contact Crayford Florist, we may collect and process the following types of personal data:
- Identity Data: Name, title, and, if relevant, the name of recipients for floral orders.
- Contact Data: Delivery address, billing address, telephone numbers, and postal codes.
- Order Information: Order details, delivery preferences, messages with orders, and purchase history.
- Payment Data: Payment method and transaction details (note: card details are processed via secured payment providers and are not stored by us).
- Technical Data: IP address, browser type, operating system, and device information where our website is used.
- Communication Data: Correspondence with us by phone, post, or our online forms.
The Lawful Basis for Processing Your Data
Under the GDPR, we must have a lawful basis for processing your personal data. Crayford Florist relies on the following lawful bases:
- Contractual Necessity: To fulfill our contract to supply flowers or gifts you have ordered.
- Legal Obligation: To meet legal and regulatory requirements related to financial transactions and record keeping.
- Legitimate Interest: For the management and improvement of our business, including customer service and quality control, provided that such interests are not overridden by your privacy rights.
- Consent: For marketing communications (where you have opted in). You can withdraw consent at any time for marketing uses.
How We Use Your Information
Your information may be used in the following ways:
- Processing, fulfilling, and delivering your orders.
- Sending service updates and order confirmations.
- Managing payments and refunds.
- Dealing with enquiries and handling any complaints.
- Improving website experience and customer service.
- Where you have opted in: sending marketing offers and news.
Data Retention: How Long We Keep Your Data
Crayford Florist retains your personal data only for as long as necessary to fulfill our purposes, including for satisfying legal, accounting, or reporting requirements. Typically:
- Order and transaction data is kept for up to seven years to comply with UK tax and accounting rules.
- Contact details maintained for marketing purposes are retained until you withdraw your consent or request erasure.
- General queries or correspondence not attached to any order are retained for up to one year.
After these timeframes, your data is securely erased or anonymised.
Processors and How We Share Your Information
We may engage trusted third-party service providers (data processors) to help fulfil your order, process payments, host our website, or provide delivery services. These processors act on our instructions and are contractually obliged to keep your information secure and confidential. Key examples include:
- Payment processors: Securely handle your payment transactions.
- Delivery couriers: Provided with delivery information necessary to fulfil your order.
- Website hosting companies: Ensure our site’s operation and security.
We do not sell your data or share it outside these necessary services. Where required for legal reasons (e.g., prevention of fraud or compliance with authorities), limited data may be disclosed in accordance with the law.
Your Data Protection Rights
Under GDPR, you have several rights regarding your personal data. These include:
- Right to Access: You may request details of personal data we hold about you.
- Right to Rectification: You may ask us to update or correct inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your personal data where there are no overriding legal grounds to retain it.
- Right to Restrict Processing: You may request limited use of your data in certain circumstances.
- Right to Data Portability: You can request your data be sent to you or another organisation in a structured, commonly used format.
- Right to Object: You may object to certain uses, such as direct marketing.
- Withdrawal of Consent: If you have provided consent, you may withdraw it at any time for future processing.
To exercise any of these rights, contact us using the details on our website or in-store. We endeavour to respond to all requests within one month.
Data Security
We employ a range of security measures to protect personal data, including encryption, secure processing systems, and restricted staff access to information on a need-to-know basis. All third-party service providers are vetted for GDPR compliance and required to keep your data safe.
International Data Transfers
Your data is stored within the UK or European Economic Area (EEA). If any transfer outside these regions is required, we ensure that appropriate safeguards consistent with GDPR are in place.
Children's Privacy
Our services are not targeted at children under 16. We do not knowingly collect data from children below this age. If you believe a child has provided us with their personal information, please let us know so we can remove such data.
Policy Updates
We may periodically update this Privacy Policy to reflect changes in law, best practice, or our business operations. The latest version will always be available in-store and on our website. Significant changes will be communicated clearly.
Contact and Complaints
If you have any questions, feedback, or concerns about the way we process your personal information, please contact us using the methods published on our website or in-store. If you remain dissatisfied, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection matters.
This policy applies to all customers placing orders with Crayford Florist for delivery in Crayford and surrounding districts. By placing an order with us, you acknowledge your understanding and acceptance of how we handle your personal data in accordance with this Privacy Policy.
