Privacy Policy for West Kensington Flowers Customers
Introduction
This Privacy Policy explains how West Kensington Flowers ('we', 'our', or 'us') collects, uses, processes, and protects your personal data in compliance with the General Data Protection Regulation (GDPR) and other applicable UK data protection laws. This policy is intended for all customers who place orders from West Kensington and the surrounding districts. We are committed to safeguarding your privacy and ensuring transparency in our practices.
Scope of This Policy
This Privacy Policy applies to all personal data collected from individuals placing orders for flower arrangements, products, or related services with West Kensington Flowers. It covers data collected via our website, over the phone, and in person at our physical location.
What Data We Collect
When you place an order or interact with us, we may collect the following categories of personal data:
- Identity Data: Name, title.
- Contact Data: Billing address, delivery address, contact telephone number(s).
- Order Data: Details of products and services you have purchased, order notes, recipient details (for delivery), and delivery instructions.
- Payment Data: Payment card details (processed securely via payment processors; we do not store full payment card information).
- Communications Data: Records of communications, including queries, feedback, and complaints.
- Technical Data: IP address, browser type, and device information (when using our website).
We collect data either directly from you (when you provide it for an order or inquiry), automatically as you interact with our website, or from third-party sources (for verification or payment processing).
Lawful Basis for Processing Your Data
Under GDPR, we must have a lawful basis to collect and use personal data. For West Kensington Flowers customers, we rely on the following legal grounds:
- Contractual necessity: Processing your data is necessary for fulfilling the contract of sale when you place an order with us, including contacting you and delivering your products.
- Legal obligation: We may need to retain certain information to comply with legal and regulatory requirements (e.g., accounting, tax laws).
- Legitimate interests: We may use your data to improve our products, manage our business, or handle customer queries, provided those interests do not override your rights and freedoms.
- Consent: Where required (for example, for marketing communications), we will obtain your explicit consent before processing your data for that specific purpose. You may withdraw consent at any time.
How We Use Your Data
We use the personal data we collect for the following purposes:
- To process and fulfil your order, including arranging delivery to the intended recipient.
- To communicate with you about your order, answer your questions, and provide customer support.
- To meet our legal or regulatory obligations (such as record-keeping and tax compliance).
- To improve our services and enhance your customer experience.
- For analytical purposes to understand trends and improve our website or product offerings (using aggregated and anonymised data where possible).
- With your consent, to send you marketing communications about our products or promotions.
Data Retention
We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting obligations.
- Customer order data is generally retained for up to 7 years to comply with regulatory requirements and to address any future questions or disputes regarding purchases.
- Marketing preferences are kept as long as you remain subscribed or until you opt out.
- Payment card details are not stored beyond the immediate transaction, as per PCI DSS compliance.
After the relevant retention periods, we will securely delete or anonymise your personal data.
Data Processors and Third Parties
We may share your personal data with selected third-party service providers (data processors) strictly for the operation of our business and to fulfil your orders. These may include:
- Payment processing companies to securely handle your transactions.
- Delivery partners to ensure accurate and timely receipt of products.
- IT and website hosting providers for secure data storage and website functionality.
- Professional advisors, such as accountants or auditors, to meet our legal obligations.
All third-party processors are contractually required to keep your information confidential and to use it only for the purposes specified by us, in line with GDPR requirements. We do not sell or rent your data to third parties for marketing purposes.
Your Data Protection Rights
Under GDPR, you have a number of rights regarding your personal data:
- Right of access: Request access to your personal data and obtain a copy.
- Right to rectification: Request correction of inaccurate or incomplete data.
- Right to erasure: Request the deletion of your personal data where there is no good reason for us to continue processing it.
- Right to restrict processing: Ask us to suspend processing of your personal data in certain circumstances.
- Right to data portability: Receive your data in a structured format or request its transfer to another provider.
- Right to object: Object to our processing of your data where we are relying on legitimate interests, or for direct marketing purposes.
- Right to withdraw consent: Where consent is the lawful basis, you may withdraw your consent at any time without affecting the lawfulness of processing before its withdrawal.
- Right to lodge a complaint: Lodge a complaint with the UK Information Commissioner's Office if you believe your data rights have not been upheld.
To exercise any of these rights, you may contact us using the methods described in our customer communications or at our physical premises.
Data Security
We take the security of your personal information seriously. We have put in place suitable physical, electronic, and managerial procedures to safeguard and secure the data we process, including secure payment gateways and regular review of our data protection measures.
International Transfers
Your data is stored and processed within the United Kingdom or the European Economic Area (EEA). Where data is transferred outside these areas, we ensure that appropriate safeguards are in place in accordance with GDPR requirements.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. Any changes will be posted prominently, and where appropriate, notified to you directly.
Contact and Further Information
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us via the details provided in your order confirmation or at our shop premises in West Kensington. We are committed to dealing with your requests and concerns promptly and transparently.