Florist Norbiton Privacy Policy
Introduction
This Privacy Policy explains how Florist Norbiton collects, uses, safeguards, and shares your personal data when you place orders with us. The Policy applies to all customers placing Florist Norbiton orders in Norbiton and surrounding districts, and it outlines your rights under the General Data Protection Regulation (GDPR).
What Personal Data We Collect
When you use Florist Norbiton to place an order, we collect the following categories of personal data:
- Contact Information: Name, billing and delivery address, and telephone number.
- Order Details: Product(s) ordered, delivery instructions, card messages, and preferences related to your order.
- Payment Information: Payment method details (e.g., last four digits of card), though we do not store full payment card details. Payment is processed via third-party secure payment processors.
- Communication Records: Information relating to correspondence between you and Florist Norbiton, including customer service inquiries and feedback.
- Technical Data: Limited device, browser, or website usage information to help deliver and improve our online services; collected via cookies or similar technologies.
We only collect what is necessary to fulfil your order and to comply with legal and contractual obligations.
Lawful Basis for Processing
Florist Norbiton processes your personal data under the following lawful bases (as per Article 6 of GDPR):
- Contractual necessity: Processing your data is required to fulfil the order you placed, including confirming, preparing, and delivering your order.
- Legal obligation: We may process and retain information to comply with applicable laws (e.g., record-keeping, tax, and fraud prevention).
- Legitimate interests: We process certain data to improve customer service, ensure the security of our services, and for limited marketing of similar products. We respect your rights and balance our legitimate interests accordingly.
- Consent: Where we send you marketing communications unrelated to your specific order, we will ask for your explicit consent, which you may withdraw at any time.
How We Use Your Personal Data
Your data are used solely for:
- Processing and fulfilling your flower and gift orders;
- Providing customer support and responding to your inquiries;
- Managing payment and invoicing via secure third-party processors;
- Improving our services and website functionality;
- Complying with legal and regulatory requirements;
- Sending you information about your order or, where consented, occasional marketing (relating to Florist Norbiton’s services).
Retention of Your Personal Data
Your personal data will be stored only as long as necessary to fulfil the purposes described above, including for legal, accounting, or reporting requirements. The main periods are:
- Order information: Retained for up to 7 years after your last purchase to meet record-keeping and accounting obligations.
- Marketing data: Retained only as long as you remain subscribed, or until you withdraw your consent.
- Customer service correspondence: Usually kept no longer than 2 years after resolution, unless needed for legal reasons.
Once the retention period expires, your data will be securely deleted or anonymised.
Processors and Data Sharing
Florist Norbiton uses professional third-party service providers (processors), strictly as necessary and subject to GDPR-compliant agreements, for purposes such as:
- Payment processing (e.g., online payment gateway providers);
- Delivery and courier services to fulfil your order in Norbiton and nearby districts;
- IT hosting, data storage, and website management providers;
- Email systems for transactional communications with you.
We only share your data to the extent required to provide services, process your order, comply with the law, or if required by a lawful authority. Your data is never sold to third parties for commercial purposes.
Your Rights Under GDPR
As a customer or website user in Norbiton and the nearby areas, you have the following rights regarding your personal information:
- Access: You can request a copy of personal data we hold about you, and information about how it is processed.
- Rectification: To request correction of inaccurate or incomplete personal data.
- Erasure: To request deletion of your personal data in some circumstances, such as after withdrawal of consent or when we no longer need the data.
- Restriction: To request restriction of the way your data is processed where you contest its accuracy, or where processing is unlawful.
- Objection: To object to processing that is based on our legitimate interests, including direct marketing.
- Portability: To request transfer of your data to another data controller, where applicable.
- Withdraw consent: Where we rely on consent for processing, you can withdraw it at any time, without affecting previously lawful processing.
To exercise any of your rights, please contact us using the methods described on our website.
Data Security
Florist Norbiton takes appropriate technical and organisational measures to ensure your personal data is safeguarded from loss, misuse, unauthorised access or disclosure, alteration, or destruction. Processors are also contractually required to apply adequate security standards for any data they handle on our behalf.
Changes to This Policy
This Privacy Policy may be updated periodically to reflect changes in law or business practice. The latest version will always be clearly posted on our website and applies to all customers placing orders from Norbiton and neighbouring areas.
Contact Us
If you have questions regarding your personal data, or would like to exercise your rights, you can contact us using the methods provided on our website, or write to our address in Norbiton. We will address your request or concern promptly and in accordance with GDPR requirements.