Privacy Policy for Highbury Flowers Customers
Introduction
This Privacy Policy describes how Highbury Flowers collects, uses, stores, and protects personal data for customers who place orders from Highbury and surrounding districts. At Highbury Flowers, we are fully committed to maintaining your privacy and ensuring that your personal information is processed lawfully, fairly, and transparently in accordance with the General Data Protection Regulation (GDPR).
Personal Data We Collect
When you interact with Highbury Flowers, we may collect and process the following categories of personal data:
- Contact Information: Including your name, delivery address, billing address, and telephone number.
- Order Information: Details of your order such as product selections, recipient name, recipient address, delivery instructions, and any personalised messages or card inscriptions.
- Payment Information: Necessary details to process your payment (such as partial card details, payment method, and transaction ID). Full card details are processed securely by our third-party payment processors and are not stored by Highbury Flowers.
- Communication Records: Records of correspondence and communications relating to your orders, customer service queries, or feedback, whether made by phone, written form, or other means.
- Marketing Preferences: Your preferences in receiving marketing communications from us, if you have opted in to receive these.
No special categories of data (such as health data or biometric data) are collected by Highbury Flowers as part of the order process.
Lawful Basis for Processing Your Data
According to the GDPR, we must have a lawful basis to collect and use your personal data. We rely on the following legal bases:
- Performance of Contract: Most of the personal information we process is provided to us directly by you in order to fulfil your order and provide requested services.
- Legitimate Interests: Where necessary, we process your data to improve our products and services, carry out administrative functions, and protect our business interests, provided that your rights and freedoms are not overridden.
- Legal Obligation: In some cases, processing is necessary to comply with legal or regulatory obligations, such as the retention of records for tax purposes.
- Consent: Where you have given explicit permission (for example, for marketing communications), we process your data based on your consent. You may withdraw consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- To process, fulfil, and deliver your orders, including communication with you about your purchase.
- To verify your payment and manage transactions securely.
- To respond to queries, requests for information, and after-sales service matters.
- To keep accurate business records for accounting and regulatory compliance.
- If you have consented, to send you marketing and promotional communications about our products.
- To enhance and improve our products, services, and customer experience.
Data Retention
We retain your personal information only for as long as is necessary to fulfil the purposes outlined in this Privacy Policy, and to comply with our legal and regulatory obligations.
- Order data, transaction information, and associated records are typically retained for up to seven years to satisfy accounting, tax, and legal requirements.
- Basic contact and service records may be retained for reasonable periods to manage repeat orders and customer relationships.
- Personal data used for marketing purposes is retained until you withdraw consent or request deletion.
- After the relevant retention period expires, your personal data is securely deleted or anonymised.
Data Processors and Third Parties
Your information may be shared with trusted third-party service providers who act as data processors on our behalf. These include:
- Payment processing companies to securely handle transactions.
- IT service providers who supply our website, order management, and secure data storage platforms.
- Delivery partners who assist in the safe and timely delivery of your orders.
All third-party processors are contractually obligated to comply with GDPR requirements and are only permitted to process your data in accordance with our instructions. We never sell or rent your personal data to other companies or organisations.
Your Data Protection Rights
Under the GDPR, you have a range of rights in relation to your personal data. These include:
- The right to access: You can request copies of your personal data that we hold.
- The right to rectification: You are entitled to request that incorrect or incomplete information be corrected.
- The right to erasure: In certain circumstances, you can ask for your personal data to be deleted.
- The right to restriction of processing: In specific situations, you may request that we restrict the processing of your personal data.
- The right to object: You may object to our processing of your data based on legitimate interests or for direct marketing purposes.
- The right to data portability: Where applicable, you can request that we transfer your personal data to another organisation.
- The right to withdraw consent: Where processing is based on consent, you may withdraw consent at any time.
If you wish to exercise any of these rights, please contact us using the details provided in your order confirmation or via our website's contact form. You have the right to lodge a complaint with the relevant supervisory authority if you are dissatisfied with how we have handled your data.
Security of Your Personal Data
We take appropriate technical and organisational measures to safeguard your personal data against loss, theft, unauthorised access, or disclosure. These measures include restricting access to information, secure payment systems, and regular staff training in data protection principles. While we strive to protect your data, transmission over the internet is not completely secure and we cannot guarantee absolute security.
Policy Updates
This Privacy Policy may be reviewed and updated periodically to reflect changes in legal requirements, our business operations, or customer feedback. Significant updates will be communicated to you where appropriate. We encourage you to check this page regularly to remain informed about how we protect your information.
Scope of the Policy
This Privacy Policy applies to all customers placing orders with Highbury Flowers from Highbury and the surrounding districts. By placing an order, you acknowledge that you have read and understood this Privacy Policy.