Privacy Policy for Customers of Flowers Friern Barnet
Introduction
This Privacy Policy explains how Flowers Friern Barnet collects, processes, stores, and safeguards your personal data when you place orders with us from Friern Barnet and the surrounding districts. We are committed to full compliance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers who interact with our products and services.
What Data We Collect
When you place an order with Flowers Friern Barnet, we collect and process the following categories of personal data:
- Identity Data: Your full name, and if applicable, the name of the recipient (for gift deliveries).
- Contact Data: Your address, delivery address, and any other relevant location details for delivery; telephone number for communication regarding orders; and optional contact information such as special delivery notes.
- Transactional Data: Details regarding your orders and purchases, such as products selected, payment method used (note: we do not store card details), and purchase history.
- Correspondence Data: Records of any communications you have with us regarding customer support, feedback, or complaints.
- Technical Data: Information about how you interact with our website or digital ordering platforms, including your IP address, browser type, device information, and cookie preferences.
Lawful Basis for Processing Your Data
Under GDPR, we must have a lawful basis to process your personal data. Flowers Friern Barnet processes data based on the following grounds:
- Contractual Necessity: Most personal data collected is necessary to fulfill our contract with you, such as processing and delivering your flower orders.
- Legal Compliance: We may process data to comply with our legal obligations, such as record keeping for tax laws and regulations.
- Legitimate Interests: Where we have a legitimate business interest, such as improving our services, ensuring safety and security, or managing and defending legal claims. When relying on this basis, we ensure that your interests and fundamental rights are not overridden.
- Consent: For email marketing or promotions, we will only use your data where we have obtained your explicit consent, which you may withdraw at any time.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, and to meet legal, regulatory, or reporting requirements. The standard retention periods are as follows:
- Customer Order Records: Retained for seven years from the date of your latest transaction to comply with tax and accounting obligations.
- Marketing Preferences: Retained until you withdraw your consent or unsubscribe from communications.
- Website Analytics Data: Retained for up to 24 months for analysis and service improvement, after which it is either deleted or anonymised.
After the relevant retention period concludes, your data will be securely deleted or anonymised so it can no longer identify you.
Data Processors and Sharing Information
Flowers Friern Barnet does not sell your personal data to third parties. However, we may share your data with trusted service providers or processors, who support us in delivering your orders and managing our business operations. These include:
- Payment processors (for secure transaction processing)
- Delivery and courier partners (for order fulfillment within Friern Barnet and nearby districts)
- IT service providers (for website hosting, maintenance, and data security)
- Professional advisors and accountants (for legal and regulatory compliance)
All third-party processors are vetted to ensure they uphold the standards of data protection required under the GDPR and our contractual agreements ensure they only process your information for the specified purposes.
Data Security
Protecting your personal data is a priority. We implement a combination of physical, administrative, and technical safeguards to prevent unauthorised access, loss, misuse, or alteration. This includes encrypted digital storage, limited and role-based staff access, regular security reviews, and staff training on data protection.
Despite these safeguards, no system can guarantee complete security. If we detect any breach that might impact your rights or freedoms, we will notify you and the relevant authorities as required by law.
Your Rights Under GDPR
You have the following rights regarding your personal data, which you may exercise at any time:
- Right to Access: You can ask to see the personal data we hold about you and receive a copy.
- Right to Rectification: If any data we hold is inaccurate or incomplete, you may request that it be corrected or supplemented.
- Right to Erasure: Also known as the "right to be forgotten," you can ask us to delete your personal data where there is no lawful reason for us to continue processing it.
- Right to Restrict Processing: You may request that the processing of your data be restricted under certain circumstances.
- Right to Data Portability: You can request that we provide your data to you or another data controller in a structured, commonly used, and machine-readable format.
- Right to Object: You may object to the processing of your data where we rely on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw consent at any time, without affecting prior processing.
- Right to Lodge a Complaint: If you believe your data protection rights have been violated, you can lodge a complaint with the relevant supervisory authority.
To exercise any of your rights, please contact us using the details provided at the end of this policy. We may need to verify your identity before fulfilling your request to protect your privacy.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements, industry practice, or our services. The updated policy will be effective from the date of publication. Your continued use of our services indicates your acceptance of the latest policy version.
Contact and Further Information
If you have any questions about this Privacy Policy or how your personal data is handled by Flowers Friern Barnet, you can contact us directly. We are committed to assisting you with any queries or concerns regarding your privacy and ensuring your data protection rights are respected at all times.