Harrow Florist Customer Privacy Policy
Introduction
This Privacy Policy sets out how Harrow Florist collects, uses, stores, and safeguards your personal data in accordance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. This policy applies to all customers placing orders with Harrow Florist, whether you are located in Harrow or neighbouring districts. We are committed to protecting your privacy and ensuring your personal information is handled responsibly and transparently.
What Personal Data We Collect
When you place an order or interact with Harrow Florist, we may collect and process the following categories of personal data:
- Identity Data: Name, title, and occasionally, information provided in messages accompanying your order (such as greeting card messages).
- Contact Data: Billing and delivery addresses, phone numbers, and other contact details necessary for order fulfillment.
- Order Information: Details about orders placed, including product selection, delivery instructions, and order history.
- Payment Data: Partial payment card information or other payment details, as processed by our payment service providers.
- Technical Data: IP address, browser type, and information collected via cookies or similar technologies, when you use our website.
We do not collect special categories of sensitive personal data unless required for specific delivery instructions provided by you.
Our Lawful Basis for Processing Your Data
Harrow Florist processes personal data under these GDPR-recognised lawful bases:
- Contractual Necessity: We need your personal data to fulfill your order, take payment, deliver flowers to the recipient, and communicate with you regarding your order.
- Legitimate Interests: We may use your data to review and improve our products and services, prevent fraud, or manage our business operations, provided our interests do not override your rights.
- Legal Obligation: We may be required to retain certain information for tax, accounting, or legal reasons.
- Consent: If we ever use your data for marketing activities, we will only do so with your explicit consent, which you can withdraw at any time.
How We Use and Share Your Personal Data
Harrow Florist uses your personal data exclusively for the purposes described in this policy. The main uses include:
- Processing and fulfilling your flower order, including any delivery or collection requirements.
- Communicating with you regarding your order, customer service, or feedback.
- Internal administration, business improvement, and analytics.
We may share your personal data with trusted third-party service providers (known as "processors") strictly as necessary to provide our services. This may include:
- Payment processors for handling card or electronic payments.
- Delivery partners or couriers to ensure your flowers reach the correct address.
- Professional service providers such as website hosting, IT support, and data analytics services.
All third-party processors are contractually obligated to handle your data securely and in compliance with GDPR. We do not sell or rent your personal data to any third parties.
Data Retention: How Long We Keep Your Information
We will not retain your personal data for longer than is necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements.
- Order-related data is kept for up to seven years to comply with taxation and financial reporting obligations.
- Customer account and address book information (where applicable) is retained while you remain an active customer, or until you request deletion.
- Technical and website data may be retained for a shorter period to support analytics and website functionality.
After these periods, your data will be securely archived or deleted.
Your Rights Under GDPR
As a customer of Harrow Florist, you have the following rights under the GDPR:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You may correct inaccurate or incomplete personal data on request.
- Right to Erasure: You may request deletion of your personal data where there is no legal or contractual reason for us to keep it.
- Right to Restrict Processing: You may request that we restrict how we use your personal data in certain circumstances.
- Right to Data Portability: Where applicable, you can request your data in a structured, commonly used format, and ask us to transmit it to another controller.
- Right to Object: You can object to processing based on legitimate interests or direct marketing, at any time.
If you wish to exercise any of these rights, please contact us using the details provided on our website or at our place of business in Harrow.
Data Security and Storage
We implement a range of technical and organisational measures to protect your data against loss, misuse, unauthorised access, disclosure, or alteration. Access to your personal data is limited to employees or agents with a recognised business need.
Personal data is stored securely within the United Kingdom or European Economic Area (EEA), and we do not transfer data outside these areas without ensuring appropriate safeguards are in place.
Updates to this Policy
We reserve the right to update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The latest version will always be published at our business premises and on our website. Please review this policy regularly to stay informed of how we protect your privacy.
Contact and Complaints
If you have any questions regarding this Privacy Policy or your personal data, please contact Harrow Florist via the details provided on our website. You also have the right to lodge a complaint with the UK Information Commissioner’s Office if you believe your data protection rights have not been upheld.