Wapping Florist Privacy Policy
Introduction
This Privacy Policy describes how Wapping Florist collects, uses, stores, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). It applies to all customers who place orders with Wapping Florist, including those in Wapping and surrounding districts.
What Data We Collect
To provide exceptional floral services, Wapping Florist collects and processes the following categories of personal data from customers and recipients:
- Contact Information: This includes your name, billing and delivery address, email address, and telephone number.
- Order Details: Information relating to your flower orders, such as product selection, delivery specifications, and personal messages for recipients.
- Payment Information: Transaction data necessary for payment processing, which may be handled by trusted third-party processors.
- Communications: Records of correspondence with you, such as emails or notes on customer service interactions.
We do not intentionally collect or process sensitive personal data (special categories of data) unless you voluntarily provide it and it is required for service provision.
Lawful Basis for Processing
Under GDPR, we ensure that all processing of your data is based on a lawful basis. Our practices include:
- Contractual Necessity: Most of the data we collect is required to fulfill your order and deliver our products to you or your recipient. For example, we need your address and payment details to process and deliver your flowers.
- Legal Obligations: Some data may be processed to comply with obligations under UK or EU law, such as tax and accounting requirements.
- Legitimate Interests: Your data may be processed for legitimate interests, such as improving our services, preventing fraud, and managing our business operations, provided these interests do not override your fundamental rights and freedoms.
- Consent: If we seek to send you marketing communications or ask for information not strictly necessary for order fulfillment, we will obtain your explicit consent. You can withdraw consent at any time.
How We Use Your Information
We use your personal information solely for the following purposes:
- To process and fulfill your orders, including delivery
- To communicate order updates and address customer service inquiries
- To facilitate payment processing and fraud prevention
- To comply with relevant legal requirements
- To analyse aggregate data for operational improvements (data is anonymised or pseudonymised where possible)
Retention of Data
We only retain your personal data for as long as necessary for the purposes outlined in this policy. Typically, this means:
- Order and transaction information is stored for up to 7 years, as required by tax and accounting laws.
- Personal contact details and communications are kept for the duration needed to manage our relationship and provide after-sales support.
- Marketing consent and preferences are retained until you withdraw your consent or unsubscribe.
When information is no longer required, it is securely deleted or anonymised.
Data Processors and Sharing
To deliver our services efficiently, we may use trusted third-party processors. These partners assist with payment processing, order delivery, software and cloud platforms for managing orders, and secure data storage. We only share your information with processors who have demonstrated GDPR compliance and provided adequate security guarantees. All third parties act on our instructions and are not permitted to use your data for their own purposes.
We will never sell or rent your personal information to third parties. We will only share information when necessary to fulfill your order or when required by law.
Your Rights Under GDPR
As a customer, you have the following rights regarding your personal data:
- Right to Access: You are entitled to request details about the personal data we hold about you and receive a copy.
- Right to Rectification: You have the right to ask for correction of inaccurate or incomplete data.
- Right to Erasure: You may request the deletion of your personal data when there is no legal basis for us to continue processing it.
- Right to Restrict Processing: You can request that we limit how your data is processed in certain circumstances.
- Right to Data Portability: You can ask for your personal data in a structured, commonly used, and machine-readable format to transfer to another provider, where applicable.
- Right to Object: You have the right to object to processing that is based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw this at any time.
- Right to Lodge a Complaint: You may raise concerns with the Information Commissioner’s Office (ICO) or your local supervisory body.
To exercise your rights, please contact us and provide sufficient identification to verify your request.
How We Protect Your Data
Wapping Florist is committed to maintaining the security and confidentiality of your personal data. We employ appropriate administrative, technical, and physical safeguards designed to protect your information against unauthorised access, loss, or misuse. Regular reviews are conducted to ensure continued compliance with GDPR and to address any emerging risks.
Policy Scope and Updates
This Privacy Policy applies to all customers placing orders with Wapping Florist from Wapping and its neighbouring districts. It covers all data processing activities, whether data is collected online, by phone, or in person. As part of our commitment to transparency and data protection, we may update this Privacy Policy to reflect changes in law or our internal practices. Material changes will be communicated to affected customers as required.
Contact Us
If you have questions regarding this Privacy Policy or wish to exercise any of your rights, please reach out to Wapping Florist through our official communication channels. We are dedicated to responding to your queries in a timely and transparent manner.