This Privacy Policy explains how Earlsfield Florist collects, uses, stores, and protects your personal information when you place orders with us. We are committed to safeguarding the privacy of all customers ordering floral arrangements and related services from Earlsfield and the surrounding districts. This Policy is designed to comply with the General Data Protection Regulation (GDPR) and outlines your rights as a data subject.
This Policy applies to all customers residing in, or placing orders from, Earlsfield and neighbouring districts who engage with Earlsfield Florist through our store, website, or telephone order service. By using our services, you acknowledge the terms set out in this Privacy Policy.
We collect the following types of personal data to process your orders and provide the best possible service:
Earlsfield Florist processes personal data only when there is a lawful basis to do so. The grounds on which we collect and process your information may include:
We use your data for the following purposes:
Your personal data will be retained only for as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting obligations. Typically, order-related data is retained for a maximum of seven years, in line with legal and regulatory guidance. Data related to marketing communications will be retained only as long as you consent to receive these communications.
Earlsfield Florist may share your data with selected third-party service providers (processors) who assist us in delivering our products and services, including payment processors, delivery partners, and IT support services. Where data is shared, we ensure that these entities adhere to strict data protection standards and only process your information on our instructions and in compliance with the GDPR.
Your data will never be sold or shared with third parties for their own direct marketing purposes.
We implement appropriate technical and organisational measures to secure your personal data against unauthorised access, accidental loss, alteration, disclosure, or destruction. These measures include secure data storage, regular data access controls, encryption where appropriate, and staff data protection training.
The GDPR grants you several rights regarding your personal data. You have the right to:
To exercise any of these rights, please contact us using the details on our website or in writing at our registered premises. We will respond to legitimate requests within one month and will inform you if more time is required.
Our services are not directed at children under the age of 16. We do not knowingly collect or process personal data from children. If we learn that we have collected such data, we will delete it promptly unless we are required to retain it by law.
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or for other operational reasons. Any significant changes will be communicated via our website. We encourage you to review this Policy periodically to stay informed about how we are protecting your data.
If you have any questions about this Privacy Policy or how we handle your personal information, please reach out to us using the contact information provided on our official website or by visiting our premises. If you are not satisfied with our response, you have the right to complain to the relevant supervisory authority for data protection.
This Privacy Policy was last updated in June 2024.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
