Epsom Florist Customer Privacy Policy
Introduction
This Privacy Policy describes how Epsom Florist collects, uses, stores, and protects your personal data in compliance with the UK General Data Protection Regulation (GDPR). It applies to all customers who place orders with Epsom Florist from Epsom and the surrounding districts. We are committed to safeguarding your privacy and ensuring that your personal information is handled securely and transparently.
What Personal Data We Collect
At Epsom Florist, we may collect and process several types of personal data from customers, including:
- Contact Details: Full name, postal address, telephone number, and any other contact information you provide.
- Order Information: Order details, delivery recipient name and address, delivery instructions, and relevant messages or notes regarding your order.
- Payment Information: Limited payment details such as payment method. We do not store full card numbers or bank details; these are handled securely by our payment processors.
- Communication Records: Records of your communications with us, such as emails, letters, or notes from phone conversations regarding your order.
- Website Usage Data: Anonymous information related to your visits to our website, collected via cookies and analytics tools for the purpose of improving our services.
Lawful Basis for Processing Your Data
In accordance with GDPR, Epsom Florist relies on the following lawful bases to collect and process your personal data:
- Contractual necessity: Processing your information is necessary to fulfill the contract of sale, including delivering your order and providing customer service.
- Legal obligations: We are required by law to keep certain records, including transaction data for tax and accounting purposes.
- Legitimate interests: We may use your information to improve our services and for business administration, provided these uses do not override your privacy rights.
- Consent: In certain cases, such as for marketing purposes, we will seek your explicit consent before using your personal data in this way.
How We Use Your Data
Your personal data is used for the following purposes:
- To process, fulfill, and deliver floral orders as requested by you.
- To communicate with you regarding your order, including confirmations, updates, or queries.
- For customer service, ensuring any issues or requests are properly addressed.
- For payment processing and fraud prevention, handled securely by trusted third-party providers.
- To comply with legal and regulatory obligations.
- Subject to your preferences, to send marketing communications or information about promotions, only where you have given consent.
- For business improvement, analytics, and quality assurance purposes, using anonymous or aggregated data where possible.
Data Retention
Epsom Florist will retain your personal data for no longer than is necessary for the purposes for which it was collected. Typically, order and transaction records are retained for up to seven years to comply with legal and accounting requirements. Communication records and non-essential information will be securely deleted when no longer needed for business purposes or customer service. We regularly review our retention periods and ensure that data is deleted or anonymised in a timely manner.
Third-Party Processors
To operate our services efficiently, we may share necessary personal data with trusted third parties (data processors), including:
- Payment processing providers: To securely manage payments and transactions on our behalf.
- Delivery couriers: To deliver floral orders to you or your chosen recipients.
- IT service providers: Supporting our website, communications, and order management systems.
All third-party processors are carefully selected and contractually required to only use personal data for the purposes specified by Epsom Florist and to comply with the GDPR.
Your Rights as a Customer
Under the GDPR, you have the following rights with regard to your personal data:
- The right to access: You may request information about the personal data we hold about you.
- The right to rectification: If your data is inaccurate or incomplete, you have the right to request correction.
- The right to erasure: You may request we delete your personal data in certain circumstances ("right to be forgotten").
- The right to restrict processing: You may ask us to restrict processing in specific situations.
- The right to data portability: You can request your data in a commonly used, machine-readable format for transfer to another provider.
- The right to object: You may object to how we use your personal data for direct marketing or legitimate interest grounds.
- Rights in relation to automated decision-making and profiling: Epsom Florist does not use automated decision-making or profiling in processing your data.
To exercise your rights, please contact us using the details provided in your order confirmation or visit our shop. We may need to verify your identity before fulfilling some requests, especially where data security is a concern.
International Transfers
In general, Epsom Florist stores and processes your personal data within the United Kingdom and the European Economic Area (EEA). If it becomes necessary to transfer data outside the EEA, we will ensure appropriate safeguards are in place to protect your information and uphold your rights under GDPR.
Securing Your Data
Epsom Florist is committed to maintaining the security of your personal data. We implement appropriate technical and organisational measures, including secure storage, limited data access, staff training, and regular reviews of our processes and policies to minimise the risk of unauthorised disclosure or misuse.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time in response to changes in our services, operations, or legal obligations. We encourage you to review this policy periodically so you remain informed about how we protect your personal data. Any significant changes will be communicated to customers by appropriate means.
Contacting Epsom Florist
If you have any questions or concerns about this Privacy Policy, or wish to exercise your data protection rights, please reach out to us via the contact details found in your order confirmation or by visiting our shop in Epsom. We are committed to addressing your concerns promptly and transparently.