Lea Bridge Florist GDPR-Compliant Privacy Policy
Introduction
This Privacy Policy explains how Lea Bridge Florist collects, uses, stores, and protects your personal information when you place flower orders through our services within Lea Bridge and surrounding districts. Safeguarding your privacy is our priority, and we adhere strictly to the requirements of the General Data Protection Regulation (GDPR). This document informs you of your rights and explains how you can access and manage your information.
Scope of this Policy
This Privacy Policy applies to all customers who place orders with Lea Bridge Florist. It governs the collection and use of your personal data whenever you contact us, browse our website, or make purchases from Lea Bridge and neighbouring areas.
Personal Data We Collect
We collect personal data to fulfill your orders and improve your experience with us. The types of data we gather include:
- Identification Information: Full name, delivery recipient name (if different).
- Contact Details: Delivery address, billing address, and contact telephone number.
- Order Details: Products ordered, delivery instructions, order messages, and purchase history.
- Payment Information: Limited financial data necessary to process payments (please note, all payment information is handled securely by our payment processors; we do not store card data ourselves).
- Communication Data: Details from queries, feedback, complaints, or other communications between you and Lea Bridge Florist.
Lawful Basis for Processing Your Data
Our processing of your personal data is justified on several lawful bases as required under GDPR:
- Contractual Necessity: Most of your personal information is processed to fulfill our contractual obligations to you, such as processing and delivering your order.
- Legal Obligations: We are sometimes required by law to keep certain records, such as for tax purposes.
- Legitimate Interests: We may process data for our legitimate business interests, including improving customer service, managing records, and preventing fraud.
- Consent: We only send marketing communications where you have actively provided consent to receive them. You can withdraw consent at any time.
How We Use Your Personal Data
Your information is used to:
- Process and track your orders, including delivery and customer support.
- Improve and personalise our services based on purchasing habits and feedback.
- Comply with applicable legal and financial regulations.
- Contact you regarding your order or to respond to your inquiries.
- Send you updates or promotional materials if you have provided consent.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. Typically, we keep order and related information for up to 7 years to comply with tax, accounting, and legal reporting obligations. After this period, your information is securely deleted or anonymised.
Third-Party Data Processors
In order to operate efficiently and provide you with the best possible service, we may share your information with trusted third-party data processors, such as:
- Payment processing providers (for secure card transactions).
- Delivery service partners (to ensure your order reaches its destination).
- IT support providers and data backup services.
- Accountants and legal advisors for compliance purposes.
All our processors are carefully selected and required to comply with GDPR standards. They only process data necessary to provide their contracted services to Lea Bridge Florist.
How We Secure Your Data
We implement appropriate technical and organisational measures to safeguard your personal data against unauthorised access, loss, or misuse. These include secure storage systems, encrypted transactions, restricted access, and ongoing staff training in data protection.
Your Rights Under GDPR
You have significant rights concerning your personal data under GDPR, including:
- Right to Access: You can request access to your personal information we hold.
- Right to Rectification: You can have inaccurate or incomplete data corrected.
- Right to Erasure: You can request the deletion of your data in certain circumstances.
- Right to Restrict Processing: You may ask us to restrict how we use your data.
- Right to Data Portability: You can request your data in a structured, commonly used digital format.
- Right to Object: You may object to our use of your personal information when operated on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where you have given consent for a particular use of your data, you may withdraw it at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the relevant data protection supervisory authority if you feel your rights are not being respected.
Children's Privacy
We do not knowingly collect or process personal data for children under the age of 16. If you believe we have inadvertently obtained such information, please notify us promptly so we can take appropriate action.
Policy Reviews and Updates
We may revise this policy from time to time to reflect changes in the law, our operations, or industry standards. Please review it periodically to remain informed about how your data is managed and protected.
Contact Us
If you have any questions, wish to exercise your data rights, or require further information about this Privacy Policy, please contact Lea Bridge Florist by your preferred means. We aim to respond promptly and address your query effectively.