Hampstead Flowers GDPR Privacy Policy
Introduction to Our Privacy Commitment
This Privacy Policy outlines how Hampstead Flowers ('we', 'us', 'our') collects, uses, stores, and protects your personal information. It applies to all customers who place orders for products and services from Hampstead Flowers in Hampstead and the surrounding districts. We are devoted to maintaining your privacy and handling your personal data transparently, fairly, and in accordance with the General Data Protection Regulation (GDPR).
Personal Data We Collect
When you place an order or interact with us, we collect the following types of personal data:
- Identity Data: Your name, and where relevant, the recipient’s name.
- Contact Data: Delivery address, billing address, and contact details such as telephone number.
- Order Details: Information about the products and services you have purchased.
- Payment Data: Transaction details (note: we do not store full card details; these are processed securely by our payment providers).
- Communication Data: Correspondence between you and Hampstead Flowers, including queries or feedback.
- Technical Data: IP addresses, browser type, and other data received through cookies and similar tracking technologies (please refer to our separate Cookie Policy for more details).
The Lawful Basis for Processing Your Data
We only use your personal data where legally allowed under GDPR. Our processing activities rely on the following lawful bases:
- Performance of Contract: Processing data necessary for fulfilling your orders and providing customer service.
- Legal Obligation: Retaining records required by law, such as invoicing and tax documentation.
- Legitimate Interests: Using data to improve our services, prevent fraud, and manage business operations, provided these do not override your privacy rights.
- Consent: For specific situations, such as sending you marketing communications, we will obtain your explicit consent, and you have the right to withdraw this consent at any time.
How We Use Your Data
Your data is used for the following purposes:
- Processing and delivering your orders, including arranging delivery to addresses in Hampstead and surrounding districts.
- Providing customer support and responding to your enquiries.
- Managing and improving our services, including service delivery, website optimisation, and internal business processes.
- Meeting our legal and regulatory obligations.
- With your consent, sending you updates, invitations, and special offers relevant to Hampstead Flowers.
Data Retention Periods
Hampstead Flowers will retain your personal data only as long as necessary to fulfill the purposes for which we collected it, including for satisfying legal, accounting, or reporting requirements:
- Order Data: Retained for up to 7 years to comply with legal and financial requirements.
- Marketing Data: Retained until you withdraw consent or request erasure.
- Correspondence Data: Retained for up to 2 years after your inquiry or feedback.
When data is no longer required, it will be securely deleted or anonymised.
Data Sharing and Processors
To deliver the best possible experience and fulfill your orders, we may share your data with trusted third-party processors. These include, but are not limited to:
- Payment service providers for secure processing of transactions.
- Delivery partners to ensure your flowers reach their intended recipients in Hampstead and nearby districts.
- IT and website support providers who assist in maintaining our systems and website security.
All third-party processors are contractually required to respect the security of your personal data and to process it in accordance with GDPR.
International Data Transfers
Your personal data is processed within the UK or European Economic Area (EEA) wherever possible. Should we ever need to transfer your data outside these regions, appropriate safeguards will be implemented to ensure the continued protection of your data.
Your Rights Under GDPR
Under data protection laws, you have several rights over your personal data. These include:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any incomplete or inaccurate data.
- Right to Erasure: Request deletion of your data where there is no legal basis for its continued processing.
- Right to Restrict Processing: Ask us to suspend processing while questions on accuracy or use are resolved.
- Right to Data Portability: Request the transfer of your data to another service provider.
- Right to Object: Object to processing where we are relying on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Withdraw consent at any time where we rely on it for processing.
How We Protect Your Data
We employ technical and organisational measures to keep your data secure. These include secure servers, restricted access, encrypted communications, and regular security reviews. Only authorised staff and trusted processors have access to your data, and all are bound by strict confidentiality obligations.
Policy Updates
We review and update this Privacy Policy as necessary to remain compliant with regulations and best practices. Any significant changes will be communicated to our customers, and updated versions will be available upon request.
Contact and Complaints
If you have questions about this Privacy Policy, how we process your data, or wish to exercise your rights, please contact Hampstead Flowers through our contact form or in writing to our registered address. If you are not satisfied with our response, you also have the right to lodge a complaint with your local supervisory authority for data protection.