Bow Florist GDPR Privacy Policy
Introduction
At Bow Florist, we are committed to protecting the privacy and security of our customers in Bow and the surrounding districts. We understand the importance of safeguarding your personal data and maintaining your trust. This Privacy Policy explains how we collect, use, store, and process your information under the General Data Protection Regulation (GDPR), and outlines your rights as a data subject. This policy applies to all customers who place orders with Bow Florist, either online, by phone, or in person.
What Data We Collect
To process your flower orders and provide a seamless experience, we collect the following types of personal data:
- Contact Information: Your name, address, phone number, and delivery address (if different from your billing address).
- Order Details: Information about your purchases, including product selection, message cards, delivery date and time, and recipient details.
- Payment Details: Partial payment information. Payment is processed via secure, third-party payment processors; we do not store full card details.
- Communication Data: Records of any correspondence with us, for example, enquiries or complaints.
- Technical Data: When you use our website, we may collect data such as your device type, browser type, IP address, and anonymised usage statistics through cookies.
Lawful Basis for Processing
We process your personal data on one or more of the following lawful bases as set out by the GDPR:
- Contractual Necessity: To process your orders and supply you with products or services you request, including delivering flowers and related items.
- Legal Obligation: To comply with legal and regulatory requirements, such as accounting and tax regulations.
- Legitimate Interests: To improve our services, handle enquiries, and maintain accurate business records. We always balance our legitimate interests with your rights and freedoms.
- Consent: Where required, for example, to send you marketing emails or newsletters, we will only do so if you have provided your consent, which you can withdraw at any time.
How We Use Your Data
Your personal data is used solely for the purposes for which it was collected. This includes:
- Processing and fulfilling your orders, including communicating order status and arranging deliveries.
- Handling customer enquiries, complaints, or requests for information.
- Improving our services by analysing usage and customer feedback (using aggregated data where possible).
- Complying with our legal and regulatory obligations.
- Providing you with information about special offers only if you have opted in to receive such updates.
Data Retention
We retain your personal data for no longer than is necessary for the purposes for which it was collected. As a guideline:
- Order and Transaction Data: Kept for up to 7 years to meet legal, tax, and accounting requirements.
- Customer Correspondence: Retained for up to 3 years after last contact to address queries or complaints.
- Marketing Data: Stored until you withdraw consent or unsubscribe.
- Website Usage Data: Anonymised and retained for website analytics purposes for up to 2 years.
After these periods, your data will be securely deleted or anonymised so that it can no longer be linked directly to you.
Processors and Third Parties
We will never sell your data to third parties. Your information is shared only with trusted third-party processors who assist us in delivering our services or fulfilling our legal obligations. These include:
- Payment Service Providers: To process your payments securely.
- Delivery Partners: Trusted couriers or delivery services, to ensure your flowers arrive safely and on time.
- IT and Hosting Providers: For the secure management and maintenance of our website and order processing systems.
- Professional Advisors: Accountants or legal advisors, when needed for compliance or in relation to legal claims.
These processors act only on our instructions, and we require them to respect the security and confidentiality of your data to GDPR standards.
Your Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct or update any inaccurate or incomplete information.
- Right to Erasure: You may request deletion of your data where it is no longer required for the purposes for which it was collected.
- Right to Restrict Processing: You can request we limit our use of your personal data in certain circumstances.
- Right to Object: You can object to certain types of processing, such as direct marketing at any time.
- Right to Data Portability: You may request to receive your data in a commonly used, machine-readable format, or have it transferred to another controller.
To exercise any of these rights, please contact our data protection representative using the details provided in store or on our official website. We will respond within one month as required by law.
Data Security
We take your data security seriously. We have implemented appropriate technical and organisational measures to protect your personal data from loss, misuse, unauthorised access, alteration, or disclosure. These include regular staff training, secure password policies, encrypted payment processing, and limited data access controls.
International Data Transfers
Your personal data is stored and processed within the UK and European Economic Area (EEA) wherever possible. If we are required to transfer data outside the EEA for IT or delivery partners, we ensure adequate protection through standard contractual clauses or equivalent safeguards.
Updates to this Policy
We may update this Privacy Policy from time to time to reflect legal, technological, or operational changes. The date of the latest revision will be indicated at the top of the policy. We encourage you to review this page regularly to stay informed of how we are protecting your information.
Contact and Complaints
If you have any questions about how we handle your personal data, or if you wish to make a complaint, you can contact our data protection representative in store or via our official website. You also have the right to lodge a complaint with the UK Information Commissioner's Office if you are dissatisfied with our response.
This Privacy Policy applies to all customers placing Bow Florist orders from Bow and surrounding districts.