Bellingham Florist Customer Privacy Policy
Introduction
This Privacy Policy describes how Bellingham Florist ("we", "us", or "our") collects, uses, stores, and processes your personal data when you place an order with us. It also explains your rights regarding your personal data. This Policy applies to all customers who place orders with Bellingham Florist from Bellingham and the surrounding districts and is in full compliance with the EU General Data Protection Regulation (GDPR).
What Personal Data We Collect
When you place an order with Bellingham Florist, we may collect the following categories of personal data:
- Contact Information: Name, address, and phone number of both the customer (the sender) and the recipient of the order.
- Order Details: Order content, delivery address, preferred delivery/pick-up times, messages for cards, and any special delivery instructions.
- Payment Information: We collect payment information as required to process your purchase (e.g., billing address, payment method). However, note that we do not store your full card details; these are processed securely by our payment processors.
- Communication Data: Records of emails, phone conversations, or written correspondence pertaining to your order or enquiries.
- Website Usage Information: If you use our website to place your order or browse, we may collect IP address, browser type, and usage statistics through cookies (for functionality, not for personalized advertising).
Lawful Basis for Processing
Under the GDPR, we rely on the following lawful bases to process your personal data:
- Contractual Necessity: Processing your information is necessary to perform the contract of sale and delivery with you, for example, to create, confirm, and deliver your flower order.
- Legal Obligations: We may retain data as required by law for tax, accounting, or regulatory purposes.
- Legitimate Interests: We may process your information for legitimate business reasons, such as improving our services, responding to enquiries, and preventing fraud, provided these interests are not overridden by your rights.
- Consent: If we ever use your data for purposes not described here, such as direct marketing, we will seek your explicit consent first, and you may withdraw it at any time.
How We Use Your Data
Your personal data is used strictly to:
- Process and fulfill your flower orders.
- Communicate with you regarding your order or to respond to your enquiries.
- Ensure delivery is made accurately and on time.
- Maintain financial and transaction records as required by accounting laws.
- Improve the safety, quality, and performance of our service.
Disclosure to Data Processors and Third Parties
We may share your personal data with trusted third parties for the fulfilment of your order and to provide our services. These include:
- Payment Processors: To handle your transactions securely.
- Delivery Partners: To deliver your order to the intended recipient.
- IT Service Providers: To maintain our website, order management, and communication systems.
- Professional Advisors: For legal, tax, or accounting support as required.
All processors are contractually bound by confidentiality and obliged to process your data in accordance with GDPR regulations.
We do not sell or rent your personal data to third parties for any purpose.
Data Retention
Your personal data will be retained only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. In general, order information and associated personal data are retained for up to seven years to comply with legal obligations regarding financial records. After this period, your data will be securely deleted or anonymised.
Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to have incorrect or incomplete data corrected.
- Right to Erasure: You may request that we delete your personal data, subject to legal and contractual obligations.
- Right to Restrict Processing: You can ask us to restrict how your data is processed in certain circumstances.
- Right to Object: You may object to certain types of processing, such as direct marketing, at any time.
- Right to Data Portability: Where applicable, you can request a copy of your data in a commonly used, machine-readable format.
- Right to Withdraw Consent: If processing is based on consent, you may withdraw your consent at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe your rights have been infringed.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Only authorised personnel and processors have access to your personal data for the fulfilment of legitimate business purposes.
Policy Updates
This Privacy Policy may be updated from time to time to reflect changes in the way we process your data or to comply with legal requirements. When substantial changes are made, a notice will be placed on our website or you will be informed by other appropriate means.
Contact Us
If you have any questions about this Privacy Policy, wish to exercise your rights, or need more information about how we handle your data, please contact us directly using the contact details provided on our website or by visiting our shop.