Barnsbury Florist Data Protection Policy
Privacy Policy Overview
This Privacy Policy explains how Barnsbury Florist collects, uses, and safeguards your personal data when you place orders with us, either in-store, online, or by phone. The policy applies to all customers ordering from Barnsbury Florist within Barnsbury and surrounding districts. We are committed to handling your data responsibly, transparently, and in full compliance with the General Data Protection Regulation (GDPR) and other relevant data protection laws.
What Data We Collect
When you place an order with Barnsbury Florist, we may collect the following types of personal information:
- Contact Details: Your name, delivery address, billing address, telephone number, and (if ordering online) email address.
- Order Information: Details of the products purchased, delivery instructions, gift messages, and any preferences you provide.
- Payment Information: Card or payment method details (processed securely; we do not store your full payment card details).
- Correspondence: Records of communications with us, including queries, feedback, or complaints.
- Website Data: If ordering online, technical information such as IP address, browser type, and usage data (through essential cookies and analytics services).
Lawful Basis for Processing
We process your personal data on the following lawful bases, as required by GDPR:
- Contractual Necessity: We process your data when it is necessary for performing a contract with you — for example, to process and deliver your order or to contact you about your purchase.
- Legitimate Interests: We may use your data to improve our services, monitor customer satisfaction, handle complaints, or detect fraudulent activity. We ensure these interests are balanced against your rights and freedoms.
- Legal Obligations: We may process your data when required by law, such as maintaining accurate financial records or responding to lawful requests from authorities.
- Consent: In some situations, such as direct marketing, we will ask for your consent before processing your personal data for these purposes. You can withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing and fulfilling your flower order and any associated services.
- Contacting you about your order, delivery, or any issues that may arise.
- Ensuring payment processing is completed securely.
- Responding to your queries, feedback, or complaints regarding our services.
- Improving our website and customer service based on aggregated and anonymised data.
- Complying with legal and regulatory requirements.
Data Retention
We retain your personal data only as long as necessary for the purposes set out in this policy and in line with our legal obligations. Typically, customer order records are kept for up to seven years in order to comply with tax and accounting regulations. Where personal data is no longer required, it is securely deleted or anonymised. Data used for marketing purposes is retained only until you withdraw consent or request removal.
External Data Processors
In order to deliver our services to you, we may share your data with carefully selected third-party processors who provide certain services on our behalf. These may include:
- Payment processing providers to securely handle your payments.
- Delivery couriers to ensure your order reaches your desired recipient.
- Website hosting and technical support providers enabling our online ordering system.
- Professional advisors, such as accountants or legal representatives, if necessary for business compliance.
All third-party processors are required to comply with GDPR and process your data only as instructed by Barnsbury Florist. We do not sell your data to third parties or allow them to use it for their own purposes. Where necessary, we ensure data is transferred and stored securely, and only within countries that provide adequate data protection standards.
Your Rights as a Data Subject
Under GDPR, you have the following rights regarding your personal data:
- Access: You can request a copy of the data we hold about you.
- Correction: You may ask us to correct or update any inaccurate or incomplete data.
- Deletion: You can request that we erase your personal data where it is no longer necessary for us to retain it, subject to legal exceptions.
- Restriction: You have the right to restrict processing of your data in certain circumstances (e.g., while we resolve a query about its accuracy).
- Objection: You may object to processing based on legitimate interests, or to your data being used for direct marketing.
- Portability: You can request that your data be provided to you, or to another data controller, in a structured, commonly used electronic format.
- Withdraw Consent: If processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise your rights, or if you have questions or complaints about how we handle your data, please contact our store in writing or in person. If you have unresolved concerns, you also have the right to lodge a complaint with the UK Information Commissioner's Office.
Security of Your Personal Data
Barnsbury Florist implements appropriate security measures to protect your personal data from loss, misuse, unauthorised access, disclosure, alteration, or destruction. These measures include secure storage, access controls, limited staff access, and regular review of data processing practices to ensure ongoing security.
Policy Updates
We may revise this Privacy Policy from time to time to reflect changes in our practices or regulatory requirements. The updated policy will apply to all orders placed from the date of revision onward. Please check this policy regularly for updates.
Contacting Us
If you have any questions about this Privacy Policy or how your data is handled by Barnsbury Florist, please contact us using the details provided on our official store materials or by visiting our store. We are dedicated to protecting your privacy and ensuring your rights are respected.