Privacy Policy Statement for Harold Park Florist
Introduction
This Privacy Policy outlines how Harold Park Florist collects, uses, stores, and protects the personal information of its customers. This policy is compliant with the General Data Protection Regulation (GDPR) and applies to everyone placing orders with Harold Park Florist, whether you are based in Harold Park or in the surrounding districts. We are committed to ensuring your privacy is safeguarded and that your personal data is handled responsibly and transparently.
What Data We Collect
To fulfill our service and deliver floral products, we may collect and process the following categories of personal data:
- Identity Data: Your full name, and if applicable, recipient's name.
- Contact Data: Billing and delivery address, phone numbers, and, where needed, email addresses.
- Order Information: Details of the products you purchase, delivery instructions, order history, payment status, and occasion details (e.g., birthdays, anniversaries, funerals).
- Payment Data: Transaction information (note: we do not store or process complete bank or credit card details ourselves, but our payment processors do).
- Marketing Preferences: Your consent regarding promotional communications where relevant.
- Technical Data: If you use our website, your IP address, browser type, device, and browsing activity may also be collected through cookies or similar technologies.
Lawful Basis for Processing
We process your personal data lawfully on one or more of the following grounds as required by GDPR:
- Contract: Data is processed to fulfill our contract with you, such as accepting and delivering your floral orders.
- Legal Obligation: In certain situations, we must process your data to comply with legal requirements, including tax and bookkeeping laws.
- Legitimate Interests: We may process your data to enhance our services, manage orders, prevent fraud, and handle customer service queries, provided your interests and rights do not override ours.
- Consent: For optional marketing communications and, where required, for cookies on our website, we rely on your consent, which you may withdraw at any time.
How We Use Your Data
Your personal data will be used exclusively for:
- Processing and delivering your orders, including communications relating to your order or its status.
- Managing payments and refunds.
- Responding to your queries and requests.
- Improving our products and services based on customer feedback.
- Sending marketing materials, offers, or updates (only if you have opted in).
- Fulfilling our legal and regulatory obligations.
We do not use your personal data for automated decision making or profiling.
Data Retention
Your personal information is retained only for as long as necessary to fulfill the purposes for which it was collected, including:
- Order Fulfilment: For the duration required to process, deliver, and provide after-sales support.
- Legal and Tax Purposes: We retain order and transaction records for up to 7 years as required by tax laws and business regulations.
- Marketing: Data used for marketing purposes is retained until you withdraw consent or opt-out.
Once your data is no longer needed, it will be securely deleted or anonymised.
Processors and Data Sharing
To provide our services, we may share your data with trusted third parties (processors) who work on our behalf. These include:
- Payment service providers for secure payment processing.
- Delivery partners or local couriers for order delivery.
- Technology providers supporting website hosting, order management, and marketing tools.
- Accountants or auditors where required by law.
All processors act under our instructions and are obligated to safeguard your data and not use it for their own purposes. We do not sell or rent your data to third parties. Data is not transferred outside the European Economic Area unless adequate protections are in place and in line with GDPR.
Your Rights as a Data Subject
Under GDPR, you have the following rights over your personal data:
- Right of Access: Request a copy of the personal information we hold about you.
- Right to Rectification: Request correction of any inaccurate or incomplete data.
- Right to Erasure: Ask for your data to be deleted when it is no longer required, or if processing is unlawful.
- Right to Restrict Processing: Request limitation on how your data is processed in certain circumstances.
- Right to Data Portability: Receive your data in a commonly used format or have it transmitted to another controller.
- Right to Object: Object to processing where our lawful basis is legitimate interests or direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time without consequence to services provided up until that point.
- Right to Lodge a Complaint: You may file a complaint with the UK Information Commissioner’s Office if you believe your data rights are infringed.
Policy Updates
We review our Privacy Policy periodically, and any changes will be updated in this document. Please review this policy regularly for updates to understand how your data is protected.
Contact and Concerns
If you have questions about how your data is handled or wish to exercise your rights, please contact us using the means provided on our main website, by post, or by visiting our shop. We take all privacy queries seriously and aim to respond promptly and transparently.