Florist Hanwell Privacy Policy – Your Data & GDPR
  Introduction
This Privacy Policy sets out how Florist Hanwell ('we', 'our', 'us') collects, uses, stores, and protects your personal data. It applies to all customers placing orders with Florist Hanwell from Hanwell and the surrounding districts. We are committed to ensuring that your privacy is protected, and we act in full compliance with the UK General Data Protection Regulation (GDPR) and other relevant data protection laws.
What Personal Data We Collect
To process your order and provide our services effectively, we may collect and process the following types of personal data:
    - Identity Data: Name, title, and relationship to the recipient.
 
    - Contact Data: Delivery address, billing address, phone number (optional), and other delivery instructions you provide.
 
    - Order Data: Details of the products you order, messages for card enclosures, and occasion details (e.g., birthday, anniversary).
 
    - Transaction Data: Payment method, purchase history, and transaction reference numbers. (Please note: we do not store credit or debit card details on our systems; payments are processed securely by our payment processors.)
 
    - Technical Data: IP address, browser type, device information, and access times collected automatically when you visit our website.
 
    - Communication Data: Records of correspondence (such as queries, complaints, or feedback), including details provided through contact forms.
 
Lawful Basis for Processing Personal Data
Florist Hanwell processes your personal data on one or more of the following lawful bases as defined by the GDPR:
    - Contractual necessity: Processing is necessary for us to fulfill your order and provide the products and services you request.
 
    - Legal obligation: We may be required to retain certain information for accounting or tax purposes, or to comply with other legal requirements.
 
    - Legitimate interests: Processing may be necessary for our legitimate business interests, such as improving our services, preventing fraud, and ensuring the security of our website. We always balance these interests with your fundamental rights and freedoms.
 
    - Consent: For marketing communications or the use of certain cookies, we rely on your explicit consent, which you may withdraw at any time.
 
How We Use Your Personal Data
Your personal data is used strictly for the purposes outlined below:
    - To process and deliver your flower orders, including communicating with you about your order status.
 
    - To manage payment and billing processes securely.
 
    - To respond to your queries, requests, or complaints.
 
    - To maintain records for accounting, auditing, and tax purposes.
 
    - To ensure the safety and security of our services and website.
 
    - To improve our services, including analyzing trends and gathering feedback.
 
    - With your consent, to send you marketing communications and special offers.
 
Data Retention Period
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, or reporting requirements. Typically, your order and account information are retained for up to six years from the date of your last transaction, unless a longer retention period is required by law. Where data is no longer needed, it is securely deleted or anonymized.
Data Processors and Third Parties
In order to operate our business efficiently, certain data processing functions may be carried out by trusted third parties ('data processors') on our behalf. These include:
    - Payment processors: To handle card and online payments securely. We do not retain your full payment card details ourselves.
 
    - IT service providers: For hosting, data storage, and website maintenance.
 
    - Delivery partners: For local and regional delivery of your orders.
 
    - Professional advisors: Such as accountants or legal professionals, where required for compliance.
 
All our processors are bound by appropriate data processing agreements to ensure your personal data is handled in compliance with the GDPR and only for the specified purposes. We do not sell or rent your personal data to third parties.
International Data Transfers
Your data is generally processed within the UK and the European Economic Area (EEA). Where it is necessary for data to be transferred outside the UK or EEA, we ensure appropriate safeguards are in place to protect your data, as required by data protection laws.
Security of Your Data
We take the security of your personal data seriously and implement strict technical and organizational measures to protect it against unauthorized access, loss, or misuse. These measures include the use of secure servers, encryption, access controls, and regular security reviews of our systems and processes.
Your Rights under GDPR
As a customer of Florist Hanwell, you have several rights regarding your personal data, including:
    - Right of access: To request a copy of the personal data we hold about you.
 
    - Right to rectification: To ask us to correct inaccurate or incomplete data.
 
    - Right to erasure: To request deletion of your personal data, where there is no good reason for us to continue processing it.
 
    - Right to restrict processing: To request a restriction on how we process your data.
 
    - Right to data portability: To receive your data in a structured, commonly used format and have it transferred to another party, where technically feasible.
 
    - Right to object: To object to our processing of your data, in certain circumstances.
 
    - Right to withdraw consent: When processing is based on your consent, you may withdraw this at any time.
 
To exercise any of these rights, please contact our data controller using the postal details available on our website or visit our shop during business hours. Please note that we may require identification to verify your request. We will respond within the legal timeframes set out in the GDPR.
Changes to This Privacy Policy
We regularly review and may update this Privacy Policy to ensure ongoing transparency and compliance with data protection laws. The date of the most recent update will be indicated at the bottom of this page. Continued use of our services after changes have been made signifies your acceptance of those changes.
Contact and Complaints
If you have any questions regarding this Policy or your data, please contact us by post or in person at our shop, where our staff will be happy to assist you. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO).
Last revised: June 2024