Balham Florist Privacy Policy

Introduction

At Balham Florist, we are committed to protecting the privacy and security of our customers’ personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information in compliance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Balham Florist in Balham and the surrounding districts.

What Data We Collect

We collect and process different types of personal data depending on how you interact with us and the nature of your orders. The types of information we may collect include:

  • Contact Information: Name, address, telephone number (optional), and delivery address details.
  • Order Details: Details of the products or services you order, delivery instructions, and messages attached to flowers.
  • Payment Information: Payment details (collected and processed securely through our chosen third-party payment processors; we do not store full card details).
  • Correspondence: Communications with us by phone, post, email, or online forms, including queries, feedback, or complaints.
  • Technical Data: IP address, browser type, and usage data where you use our website (collected via cookies or similar technologies, which you may accept or decline).

Lawful Bases for Processing

We process your personal information using one or more of the following lawful bases as provided by the GDPR:

  • Contract: To fulfil our obligations in processing and delivering your orders.
  • Legitimate Interest: To improve our products and services, handle customer queries, and prevent fraud where these interests do not override your fundamental rights and freedoms.
  • Legal Obligation: To comply with applicable laws, tax obligations, and regulatory requirements.
  • Consent: Where you have explicitly opted in to receive marketing or promotional communications, which you can withdraw at any time.

How We Use Your Information

Your personal data is used only for the purposes set out in this policy. Specifically, we use your data to:

  • Process and deliver your orders.
  • Maintain accurate internal records of orders and customer requests.
  • Respond to your queries, feedback, or complaints.
  • Comply with legal, regulatory, and tax requirements.
  • Improve our website, products, and services.
  • Send you marketing communications if you have chosen to receive them.

Data Retention

We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically, customer order information is held for up to seven years to comply with tax and financial regulations. Personal data used solely for marketing purposes is retained until you withdraw your consent or opt out.

Data Processors and Third Parties

Balham Florist may share your data with third-party service providers acting as Data Processors. Such processors act in accordance with instructions from Balham Florist and only process personal data to provide specific services on our behalf. These may include:

  • Payment processing providers to securely handle payments for your orders.
  • Delivery partners to ensure timely and accurate delivery of your flowers and gifts.
  • IT and cloud storage providers which securely store electronic data.

We ensure that all third-party processors comply with GDPR obligations regarding privacy and security. Your data will not be sold or transferred to any third party for marketing or commercial purposes independent of your transactions with us.

Your Data Protection Rights

Under GDPR, you have a range of rights regarding your personal data. These include:

  • Right to Access: You may request a copy of the personal data we hold about you.
  • Right to Rectification: You have the right to correct misinformation or inaccuracies about your data.
  • Right to Erasure: You may request the deletion of your data under certain circumstances (also known as the 'right to be forgotten').
  • Right to Restriction: You may request that we restrict how we use your personal data.
  • Right to Data Portability: You have rights to request your data in a portable format for your use elsewhere.
  • Right to Object: You may object to our use of your personal data for particular purposes, such as marketing.
  • Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw this at any time.

If you wish to exercise any of your data protection rights, please contact us in writing via the methods outlined on our official website or in your order confirmation documentation. We will respond to all requests within one month, in accordance with GDPR guidelines.

How We Protect Your Data

We take data security seriously and use a combination of technical and organisational measures to protect your personal data from unauthorised access, loss, or misuse. Access to personal data is limited to authorised staff and authorised processors only, and all data is stored securely using industry-standard safeguards.

Children's Privacy

Our services are not directed towards children under the age of 16. We do not knowingly collect or process personal data from children. If we become aware that we have inadvertently received personal data from a child, we will delete such information promptly.

Policy Changes

We may occasionally update this Privacy Policy. Any changes will be posted on our website, and, where appropriate, notified to you by other means. Your continued use of our services after any update constitutes your acceptance of the revised policy.

Contact and Complaints

If you have any questions about this Privacy Policy or your data, or if you wish to lodge a complaint, please contact us using the details provided on our website or your order documents. You also have the right to lodge a complaint with the Information Commissioner’s Office if you believe your data protection rights have been violated.