Florist Merton Privacy Policy for Customers
Introduction
This Privacy Policy explains how Florist Merton collects, uses, processes, and protects your personal information. This policy applies to all customers placing orders for products or services from Florist Merton, within the borough of Merton as well as surrounding districts. Florist Merton is committed to complying with the General Data Protection Regulation (GDPR) and ensuring transparency regarding your data.
Personal Data We Collect
When you place an order with Florist Merton—either online, by telephone, or in person—we may collect the following categories of personal data:
- Identity Information: Name, surname, and title.
- Contact Information: Delivery address, billing address, telephone number, and contact preferences.
- Order Details: Information about the products you have ordered, delivery instructions, and messages included with your order.
- Payment Information: Partial payment card information (e.g., last 4 digits), payment method, and payment status. Please note we do not store full card details.
- Customer Communications: Emails, feedback, and records of interactions with our customer service team.
- Technical Information: IP address, device type, browser information, and cookies (when using our website).
Lawful Basis for Processing
Florist Merton processes personal data under several lawful bases in accordance with the GDPR:
- Performance of a Contract: To fulfil your order, process payments, arrange deliveries, and provide after-sales support.
- Legitimate Interests: To manage and improve our services, prevent fraud, and send necessary updates about your order.
- Legal Obligation: To maintain records for taxation and other legally required purposes.
- Consent: For processing special requests, marketing communications (where you opt-in), and analytics cookies.
Purpose of Data Collection
Your data is collected for the following purposes:
- Processing and fulfilling your flower orders.
- Arranging deliveries and communicating order status.
- Providing customer service and handling enquiries.
- Improving our website and services.
- Complying with legal and regulatory requirements.
Data Retention
Florist Merton retains your personal data for as long as necessary to achieve the purposes for which it was collected or as required by law. Typically:
- Order records and communications: Retained for up to 6 years for accounting and legal purposes.
- Customer account details: Retained until you request account closure or erasure, subject to legal and contractual obligations.
- Marketing preferences: Retained until you withdraw your consent.
- Technical/cookie data: Retention periods depend on cookie settings and browser preferences.
Data Processors
Florist Merton uses trusted third-party service providers (data processors) to help deliver our products and services. These processors only access your data as necessary to perform their functions and are required by contract to keep your information confidential and secure. Processors may include:
- Payment processing providers for handling transactions securely.
- Courier and delivery companies for successful delivery of orders.
- IT and web hosting companies that support our website and infrastructure.
- Customer support platforms to manage customer relationships.
- Marketing platforms (only with your consent) for promotional emails or offers.
Florist Merton does not sell or rent your personal data to any third parties.
International Data Transfers
Your data is processed within the United Kingdom and European Economic Area (EEA) where possible. If it becomes necessary to transfer your data outside these regions, we ensure equivalent protections are in place as required under the GDPR.
Your Rights
Under the GDPR, you, as a customer of Florist Merton, have specific rights concerning your personal data:
- Right to Access: Request a copy of your personal data held by us.
- Right to Correction: Ask for incorrect or incomplete data to be corrected or updated.
- Right to Erasure ("Right to be Forgotten"): Request that we delete your personal data where there is no compelling reason for its continued processing.
- Right to Data Portability: Request transfer of your personal data to you or another service provider in a structured format.
- Right to Restrict Processing: Ask us to limit how we process your data in certain circumstances.
- Right to Object: Object to processing of your data based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time for future processing.
To exercise any of these rights, contact Florist Merton’s Data Protection Officer in writing. Please note that we may require proof of identity to process your request. We strive to respond to all requests within one month, as required by law.
Keeping Your Data Secure
We take data security seriously and use a range of technical and organizational measures to protect your information from unauthorized access, alteration, or disclosure. These include password protection, encrypted data storage, secure payment processing, and staff training. Regular reviews of security procedures and risk assessments are performed.
Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in legal requirements or business practices. The latest version will always be available through our website and in-store. Material changes will be communicated clearly to our customers.
Contacting Florist Merton
If you have any questions about this Privacy Policy or how we process your personal information, please get in touch with our team or Data Protection Officer. We are committed to addressing any concerns or complaints you may have in relation to your privacy.