Privacy Policy for Bloomsbury Flowers Customers
Introduction
At Bloomsbury Flowers, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, store, and share your data when you place an order with us, either as an individual or as a business customer, in Bloomsbury and the surrounding districts. We process personal data in compliance with the General Data Protection Regulation (GDPR) and all relevant UK legislation.
Scope of This Policy
This Privacy Policy applies to all customers who place orders with Bloomsbury Flowers for delivery or collection in Bloomsbury and its surrounding districts. By using our services and providing your personal information, you agree to the practices described in this policy.
What Personal Data We Collect
We collect and use different types of personal information depending on the circumstances of your order. The personal data we may collect includes:
- Contact Information: Name, address, telephone number, and (when applicable) delivery instructions.
- Transaction Details: Details about the products you order, delivery address, and billing address.
- Payment Information: Card details are processed securely via our payment processors and are not stored by Bloomsbury Flowers.
- Communications: Records of your interactions with us, such as emails, notes from telephone calls, and messages relating to your order.
- Preferences: Any preferences you indicate for flower arrangements, delivery options, or special requests through our order forms.
- Website Usage Data: Information collected through cookies and similar technologies (where applicable), such as your IP address, device type, and browsing activity on our site.
Lawful Basis for Processing
Under GDPR, we are required to identify the legal basis on which we process your personal data. Our lawful bases for processing your data include:
- Contractual Necessity: We process your information to perform our contract with you, such as processing and fulfilling your orders, and handling payments.
- Legal Obligation: We may process and retain certain data to comply with tax, accounting, or other legal obligations.
- Legitimate Interests: We may process your data for the legitimate interests of enhancing our service, preventing fraud, managing enquiries, and improving your customer experience. We always balance these interests against your rights and freedoms.
- Consent: Where required, we will ask for your explicit consent to process certain categories of data, such as special requests or marketing communications (if offered).
How We Use Your Data
We use your personal information for the following purposes:
- To process and fulfill your orders
- To manage payment transactions
- To communicate with you about your orders, deliveries, and related enquiries
- To handle any complaints or feedback you provide
- To comply with financial and legal record-keeping requirements
- To improve our services and offerings
Retention of Your Data
We retain personal data for as long as necessary to fulfil the purposes for which it was collected, and in line with statutory and regulatory requirements. This generally means we will retain data associated with orders for up to 7 years to comply with tax and accounting obligations. After this period, your data is securely deleted or anonymised.
Processors and Third Parties
To provide our services efficiently, we may share limited personal data with trusted third-party processors who act on our behalf. These processors include:
- Payment processing providers
- IT and hosting service providers
- Delivery partners (if used for local deliveries)
All processors are bound by contracts requiring them to handle your personal data securely and in compliance with GDPR. Your information is never sold to third parties, nor used for any purposes outside of fulfilling your service with us.
Your Rights Under GDPR
You have certain rights under the GDPR regarding your personal information. These include:
- Right of Access: You have the right to request access to the personal data we hold about you.
- Right to Rectification: You can request that any inaccurate or incomplete information is corrected.
- Right to Erasure: You may request that your personal data be deleted where appropriate.
- Right to Restrict Processing: You can ask us to stop processing your data in certain circumstances.
- Right to Data Portability: Where applicable, you can request your data in a structured, commonly used machine-readable format.
- Right to Object: You have the right to object to the processing of your data in certain situations, such as for direct marketing purposes.
If you wish to exercise any of your rights, please contact us using the details provided on our website or written correspondence to our registered address.
Data Security
We implement appropriate technical and organisational measures to hold your personal data securely and protect it from unauthorised access, loss, or misuse. Access to customer data is restricted to trained staff and trusted parties who need it to perform their duties.
Cookies and Website Analytics
Our website may use cookies to enhance your shopping experience and monitor site usage for improvement purposes. You may set your web browser to refuse cookies or alert you when cookies are being sent. Please note that some parts of the website may function differently if you disable cookies.
Policy Updates
We may update this Privacy Policy to reflect changes in our data processing practices or in response to legal requirements. The updated policy will be made available on our website with the latest revision date highlighted. We encourage you to review this policy regularly when placing new orders with us.
Contact for Privacy Enquiries
If you have any questions about this Privacy Policy or how we handle your personal information, please reach out to us via the contact information shown on our website or by writing to our business address.
This policy is effective as of 1 June 2024.
