Florist Chalk Farm Customer Privacy Policy
Introduction
Your privacy is important to us at Florist Chalk Farm. This Privacy Policy explains how we collect, use, and protect the personal information of customers placing orders with us in Chalk Farm and surrounding districts. Our commitment is to comply fully with the General Data Protection Regulation (GDPR), ensuring your information is handled respectfully and transparently at every stage.
Scope of Policy
This Privacy Policy applies to all customers who place orders with Florist Chalk Farm, whether online, by phone, or in person, for delivery or collection in Chalk Farm and adjacent districts. It covers all aspects of data collection and processing associated with our floral products and services.
What Personal Data We Collect
When you place an order with Florist Chalk Farm, we may collect the following types of personal data:
- Identity Data: Your name and sometimes the recipient’s name.
- Contact Data: Address, delivery address, phone number (where applicable), and sometimes email address, to process your order and for communication purposes.
- Order Details: Information regarding the products you request, special delivery instructions, and card messages to accompany your order.
- Payment Data: Partial payment details (such as the type of payment method used and transaction confirmation from our payment processor — we do not store full card details).
- Communication Data: Any information you provide during communications with us, including order inquiries, feedback, or complaints.
- Technical Data: For online orders, your IP address, browser type, and visit information may be collected for security and analytics purposes.
Lawful Basis for Processing
Florist Chalk Farm adheres to the lawful bases for processing personal data as outlined by the GDPR. The primary purposes and appropriate lawful bases include:
- Performance of a Contract: Most of the data we collect is necessary to execute your purchase, process payment, deliver flowers, or fulfil other requests relating to your order.
- Legal Obligation: We may be required by law to retain invoice or transaction data for accounting, tax, or regulatory reasons.
- Legitimate Interests: Where it does not override your rights, we use data to improve services, respond to inquiries, or send follow-up messages related to your recent order.
- Consent: In certain cases, such as direct marketing communications (for instance, newsletters or special offers), we will ask for your explicit consent before processing your data for these purposes. You may withdraw consent at any time.
Data Retention
Your personal data is stored only for as long as necessary to fulfil the purpose for which it was collected. The retention periods we commonly apply are:
- Order Fulfilment: Data relating to orders is stored for up to 24 months after fulfilment, allowing us to address any inquiries or disputes and comply with accounting requirements.
- Customer Accounts: If you register for an account, minimum necessary data will be retained until you request your account to be deleted or after a period of inactivity, usually 24 months.
- Legal and Regulatory: Invoice and transaction information required by law may be kept for up to 7 years.
- Marketing Consent: If you have opted into marketing communications, we will retain your contact information until you opt out or withdraw consent.
Data Processors and Third Parties
To provide our services, Florist Chalk Farm may engage trusted third-party processors. Each processor is selected carefully and required to comply with GDPR and our privacy standards:
- Payment Processors: Secure payment providers process your payment data through encrypted transactions. Only confirmation of completed payment reaches us; full card or payment details are not stored by Florist Chalk Farm.
- IT and Website Service Providers: Third-parties may provide hosting, order management, analytics, and email systems to enable us to operate our online services securely and efficiently.
- Delivery Partners: In some instances, your contact and delivery details may be shared with reputable couriers to complete your flower delivery as requested.
Personal data is not sold or shared with any unauthorized parties or for unrelated commercial purposes. Where relevant, data transfers take place only in compliance with legal safeguards required under GDPR, including data processing agreements and secure data handling standards.
User Rights Under GDPR
As a data subject under GDPR, you have several important rights relating to your personal information:
- Right to Access: You can request a copy of any personal data we hold about you.
- Right to Rectification: You have the right to ask that we correct or complete inaccurate or incomplete data.
- Right to Erasure: Also known as the ‘right to be forgotten’, you can ask for the deletion of your personal data, subject to legal or legitimate business needs.
- Right to Restrict Processing: You can request that the processing of your personal data is limited in certain circumstances.
- Right to Data Portability: You can request that your personal data is provided to you or to another controller, in a commonly used and machine-readable format, where technically feasible.
- Right to Object: You may object to the processing of your personal data where we rely on legitimate interests.
- Right to Withdraw Consent: Where you have provided consent, this can be withdrawn at any time.
To exercise any of these rights, please contact us using the channels outlined at the end of this policy.
Security and Data Protection Measures
We are committed to securing your information. Appropriate organisational and technical measures are implemented to prevent unauthorized access, loss, or misuse of your data, including encryption, secure systems, and access control within our business and service providers.
Updates and Changes to This Policy
This Privacy Policy may be updated periodically to reflect changes in law, best practices, or our services. Significant changes will be notified clearly to affected customers. We encourage you to review this policy regularly to remain informed about how we protect your privacy.
Contact and Complaints
If you have any questions or concerns about this Privacy Policy or wish to exercise your GDPR rights, please contact us through the communication channels provided on our website or in-store. If you are not satisfied with our response, you have the right to lodge a complaint with the relevant data protection authority.