St John’s Wood Flowers GDPR-Compliant Privacy Policy
Introduction
This Privacy Policy outlines how St John’s Wood Flowers ('we', 'our', or 'us') collects, uses, stores, and protects your personal information in compliance with the EU General Data Protection Regulation (GDPR). This policy applies to all individuals placing orders with St John’s Wood Flowers from St John’s Wood and its surrounding districts.
What Information We Collect
We collect a range of personal data to facilitate your order and provide high-quality service. The specific information collected may include:
- Identity Data: Full name, delivery recipient name, and title.
- Contact Data: Address, delivery address, telephone number (where provided), and other contact details given during the order process.
- Order Details: Details of your order, special instructions, and any personalised messages.
- Payment Data: Payment information (such as payment card details), processed securely through our trusted payment processors (we do not store card details ourselves).
- Correspondence Data: Communications with us, including queries, feedback, and complaints.
We do not knowingly collect or process special categories of personal data (such as health information or data revealing racial or ethnic origin) unless supplied voluntarily within order instructions. If such data is provided, we will handle it with heightened care and protection.
Our Lawful Basis for Processing Data
Under GDPR, we must have a lawful basis for processing your personal information. Our activities rely on the following bases:
- Contractual Necessity: Most data processing is necessary for the performance of the contract with you – for instance, to fulfil your flower order or deliver items as requested.
- Legal Obligations: We may retain and process information to comply with applicable legal and regulatory obligations, including tax and record-keeping requirements.
- Legitimate Interests: We may process certain data for our legitimate business interests, such as record-keeping, monitoring customer satisfaction, improving our services, and handling feedback, provided that these interests are not overridden by your rights and interests.
- Consent: Where required, for example, for direct marketing or where you provide special category data, we obtain your explicit consent before processing.
How We Use Your Data
Your personal data is used to facilitate ordering, fulfil and deliver your purchase, respond to queries, process payments, and improve our services. We may also keep internal records for administrative purposes. Where necessary, we use your data to:
- Process and deliver your order
- Respond to service enquiries or complaints
- Manage payments and refunds
- Monitor service quality and customer satisfaction
- Retain invoice and transaction data for legal compliance
Who Processes Your Data
In order to provide our services, we may share your data with trusted third-party processors. All processors are contractually bound by data protection obligations and GDPR compliance and act only on our instructions. Processors may include:
- Payment service providers for secure payment transaction processing
- Delivery partners or couriers to complete your order
- IT service providers for secure data hosting and website maintenance
- Accountants or legal professionals, as required, for record-keeping or compliance reasons
We do not sell, rent, or otherwise provide your personal data to unrelated third parties for marketing purposes.
Data Retention Periods
We only retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, to meet legal obligations, and to resolve disputes. Data retention periods are as follows:
- Order and transaction information: retained for up to seven years to comply with accounting and tax regulations.
- Customer queries and correspondence: typically retained for up to three years from last contact unless a longer period is required under law.
- Marketing data: retained only until you withdraw your consent or unsubscribe, after which it will be securely deleted.
Once retention periods expire, your personal data will be securely deleted or anonymised.
Your Rights Under GDPR
You have specific rights regarding your personal data under GDPR. These include:
- Right of Access: Request a copy of personal data we hold about you.
- Right to Rectification: Request corrections to any inaccurate or incomplete data.
- Right to Erasure: Ask us to delete your data under certain conditions (“the right to be forgotten”).
- Right to Restriction: Request we limit processing of your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used, machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where we rely on your consent to process data, you may withdraw it at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe we have not complied with data protection regulations.
To exercise these rights, contact us using the details provided on our website or by post. We will respond within one month, as required by law.
Children’s Privacy
Our services are not directed at children under 16 years of age. We do not knowingly collect or process data from children unless provided by a parent or legal guardian for order purposes. If we become aware that such data has been provided unintentionally, we will promptly delete it.
Security Measures
We treat your personal data with the utmost care, employing technical and organisational measures to safeguard it against unauthorised access, loss, or misuse. This includes:
- Encryption of data during transmission and storage where possible
- Access controls restricting who within St John’s Wood Flowers may view personal data
- Secure physical premises and IT infrastructures
- Regular review of data protection practices
Policy Changes
This Privacy Policy may be updated from time to time to reflect updates in legal requirements or our business practices. We encourage you to review this policy periodically. Substantial changes will be communicated to customers via appropriate channels.
Contact and Queries
If you have any questions, concerns, or requests concerning your personal data or this Privacy Policy, please contact St John’s Wood Flowers using the contact information provided on our website or send a written enquiry to our address.