Florist Eltham Privacy Policy
Our Commitment to Your Privacy
Florist Eltham values your trust and is committed to protecting your personal data. We adhere to the General Data Protection Regulation (GDPR) and local data protection laws to ensure your privacy is respected whenever you place an order with us. This Privacy Policy details how we collect, process, and retain your information, and outlines your rights as a customer. It applies to all customers placing Florist Eltham orders from Eltham and the surrounding districts.
What Personal Data We Collect
To provide our services effectively and efficiently, we collect the following types of personal data from you:
- Contact Information: Name, address (including delivery address), and telephone number.
- Order Details: Information about the products you order, any delivery instructions, messages for recipients, and transaction data.
- Payment Information: Payment card details (processed securely via third-party providers – we do not store card numbers ourselves).
- Customer Correspondence: Any communications you have with Florist Eltham for customer service or order-related queries.
- Technical Data: Your IP address, browser type, and device information when you use our website to place an order.
We do not collect special categories of personal data unless explicitly provided by you and where necessary (for instance, accessibility requirements for deliveries).
Lawful Basis for Processing Your Data
GDPR requires that we have a valid lawful basis to process your personal data. Florist Eltham processes your data using the following bases:
- Contractual Necessity: Processing is necessary to perform our contract with you, such as fulfilling your flower order and arranging delivery.
- Legal Obligation: We may need to process your data to comply with legal requirements, such as accounting and tax regulations.
- Legitimate Interests: We may process your information for purposes such as customer service, quality assurance, and service improvement, where these are not outweighed by your rights and interests.
- Consent: Where applicable, we rely on your explicit consent, such as when you opt in to receive promotional communications. You may withdraw consent at any time.
How We Use Your Data
Your information is used for the following purposes:
- Processing and fulfilling flower and gift orders
- Contacting you regarding your order or delivery
- Processing payments
- Managing returns, complaints, and customer queries
- Improving our service quality and customer experience
- Complying with our legal and financial obligations
We do not sell your data to third parties. Your information is only shared as necessary for the purposes stated above.
Third-Party Processors
Florist Eltham engages third-party companies ("processors") to support our services. These processors are contractually bound to handle your data in compliance with GDPR and are not permitted to use your data for their own purposes. Examples include:
- Payment Service Providers: Securely process your payment information.
- Delivery Partners: Ensure successful delivery of your orders.
- IT and Website Support: Companies that assist in managing our website and email communications.
We conduct appropriate due diligence and only work with trusted processors. A list of our current processors is available upon request. We do not transfer your data outside the European Economic Area (EEA) without ensuring adequate safeguards.
Data Retention Policy
We retain your personal data only for as long as is necessary to fulfil the purposes for which we collected it, including for satisfying legal, accounting, and reporting requirements. In general:
- Order information and transactions: Kept for up to seven years for legal and tax purposes.
- Customer communications: Retained for up to two years after your last order to assist with service follow-up and complaint management.
- Marketing preferences: Retained until you unsubscribe or withdraw consent.
After these periods, your personal information will be securely deleted or anonymised.
Your Rights Under GDPR
You, as a data subject, have a number of rights under the GDPR relating to your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: If your information is inaccurate or incomplete, you can ask us to correct it.
- Right to Erasure: Also known as "the right to be forgotten", you can ask us to delete your personal data where there is no legitimate reason for us to continue processing it.
- Right to Restrict Processing: You may ask us to limit how we use your data.
- Right to Data Portability: You have the right to receive your data in a structured, commonly used electronic format and request that it be transferred to another provider where feasible.
- Right to Object: You may object to processing based on legitimate interests or direct marketing at any time.
- Right to Withdraw Consent: When processing is based on your consent, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us using your preferred contact method. We will respond to your request within one month in accordance with GDPR requirements.
Security of Your Personal Data
We employ appropriate technical and organisational security measures to protect your data against unauthorised access, loss, or misuse. These include secure payment processing, data encryption, access controls, and staff training on data protection.
Policy Scope and Changes
This Privacy Policy covers all personal data collected and processed by Florist Eltham from customers placing orders in Eltham and the surrounding districts. We may update this policy periodically to reflect service changes or legal requirements. Substantial changes will be communicated via our website or upon request. We encourage you to review this Privacy Policy regularly.
Contact and Further Information
If you have questions about this Privacy Policy, your data, or wish to exercise your rights, please contact Florist Eltham directly. We are happy to assist with any queries, concerns, or requests regarding your personal information and privacy.