Holloway Florist GDPR-Compliant Privacy Policy
Introduction
This Privacy Policy explains how Holloway Florist collects, uses, stores, and protects the personal data of customers placing orders from Holloway and surrounding districts. Our commitment to your privacy is paramount and our practices comply with the General Data Protection Regulation (GDPR).
Scope of This Policy
This policy applies to all customers who use our services to place orders from Holloway and adjacent localities. It covers all data processing activities associated with floral purchases, delivery, and related communications.
What Personal Data We Collect
When you place an order with Holloway Florist, we may collect the following personal data:
- Identity and Contact Information: Name, address, delivery address, postcode, and contact phone number.
- Order Details: Information relating to your chosen products, delivery instructions, and recipient information (such as the name and address of the flower recipient).
- Payment Data: Payment method details (such as card information processed by our payment processors), transaction details, and billing address.
- Communication Data: Correspondence with customer service, feedback, and any communication you send to us via web forms or other provided channels.
- Technical Data: IP address, device type, browser type, and site interaction data to enhance your online experience and maintain security.
Lawful Basis for Processing Personal Data
We process your personal data lawfully in accordance with one or more of the following GDPR grounds:
- Contractual Necessity: Processing your data is required to fulfill the order you place and to provide requested services.
- Legal Obligation: To comply with relevant laws, such as tax and accounting regulations.
- Legitimate Interests: For day-to-day business operations, customer support, service improvements, and fraud prevention, provided these do not override your rights.
- Consent: Where expressly requested and provided, such as for marketing communications. Consent can be withdrawn at any time.
How We Use Your Data
Your personal data is used solely for the following purposes:
- Processing and fulfilling flower orders to the designated recipient.
- Communicating order updates, confirmations, and delivery notifications.
- Managing payment and invoicing.
- Improving our services and user experience.
- Responding to your enquiries and providing customer support.
- Meeting legal and regulatory requirements.
Data Retention
Holloway Florist retains your personal information only as long as necessary to fulfill the purposes for which it was collected, and as required by law. Specifically:
- Order and transaction information is typically retained for up to 7 years to comply with tax and accounting obligations.
- Customer service records are stored for a maximum of 3 years after resolution.
- Technical data may be kept for a shorter period, usually no longer than 12 months, unless required for security or legal purposes.
Data Processors and Third Parties
To deliver our services, we may share your personal data with selected third-party processors who act on our instructions, including:
- Payment Service Providers: For secure payment processing; we do not store your full card details.
- Delivery partners: To ensure efficient and accurate delivery of your order in Holloway and nearby districts.
- IT and Hosting Providers: To maintain our website infrastructure, data storage, and technical support.
All processors are contractually bound to comply with GDPR and to treat your data with strict confidentiality. No data is transferred outside the UK or European Economic Area unless adequate safeguards are in place.
Data Security
We employ reasonable technical and organizational measures to protect your personal data from unauthorized access, loss, or misuse. These measures include secure data storage, restricted access controls, and regular reviews of our data protection protocols.
Your Rights Under GDPR
As a customer whose data is processed by Holloway Florist, you have the following rights:
- Right to Access: You may request a copy of your personal data we hold.
- Right to Rectification: You have the right to correct incomplete or inaccurate information.
- Right to Erasure: You can request the deletion of your personal data, subject to legal retention requirements.
- Right to Restrict Processing: You may ask us to limit the processing of your data in certain circumstances.
- Right to Data Portability: Where applicable, you may request that your data be provided in a common electronic format.
- Right to Object: You may object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where consent has been given, it can be withdrawn at any time without affecting the lawfulness of previous processing.
To exercise any of these rights, please contact us via the communication methods indicated on our official platforms.
Policy Updates
This policy will be reviewed periodically and updated where necessary to reflect changes in our practices or legal requirements. Changes will be communicated through our website and will take effect once published.
Contact and Complaints
If you have any questions or concerns regarding your personal data and privacy rights with Holloway Florist, or if you wish to make a complaint, you may contact us through our official website or written correspondence. If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
Summary
Your privacy is important to us. Holloway Florist is committed to protecting your personal data in line with GDPR and delivering an open, transparent service to all customers throughout Holloway and surrounding districts.