Florist Berrylands Privacy Policy
Introduction
Florist Berrylands is committed to protecting the privacy and personal data of its customers. This Privacy Policy explains how we collect, use, store, and safeguard your personal information in compliance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Florist Berrylands from Berrylands and surrounding districts.
What Data We Collect
When you place an order or interact with Florist Berrylands, we may collect the following categories of data:
- Identification details: Name, address, and contact information (such as delivery address, and billing address).
- Order information: Details of your order (recipient’s name and address, order notes, delivery preferences).
- Payment details: Payment confirmation and transaction details (we do not store full credit or debit card numbers; payment data is processed securely through our payment processor).
- Communication records: Any messages, feedback, or communications you send to us.
- Technical data: IP address, browser type, operating system, and access times when you visit our website, for functionality and security purposes.
Lawful Basis for Processing Personal Data
We only collect and process personal data where there is a legal basis to do so under the GDPR, including:
- Contractual necessity: The information we collect directly from you allows us to fulfill your order and deliver products and services you have requested.
- Legal obligation: Certain data must be kept to comply with tax, accounting, and other legal requirements.
- Legitimate interests: We may process your data for our legitimate business interests, such as improving our services, preventing fraud, and maintaining website security, provided these interests do not override your rights and freedoms.
- Consent: In cases where we require your consent (for example, subscribing to marketing communications), we will seek your clear and explicit permission and you may withdraw this consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing and fulfilling your flower orders.
- Contacting you regarding your order, delivery status, or any issues relating to your purchase.
- Improving our services, including analyzing trends and customer preferences.
- Legal compliance and protecting our business against fraud or misuse.
- Sending you service-related communications. Marketing communications are only sent with your explicit consent.
Data Retention
We retain your personal data only for as long as necessary for the purposes outlined in this policy. In particular:
- Order and transaction data is kept for up to seven years to satisfy tax and accounting requirements.
- Customer account data is retained for as long as your account is active or until you request deletion.
- Data used for marketing purposes is kept only until you withdraw your consent.
- Anonymous or aggregated data that cannot be linked to an individual may be kept indefinitely for analytics and business purposes.
Third-Party Processors
We may share your personal data with trusted third-party service providers, also known as data processors, who act on our behalf to deliver certain services. These can include:
- Payment service providers for secure payment processing.
- Delivery partners to fulfill and deliver your order.
- IT and hosting service providers to support our website and systems.
- Professional advisors, such as accountants or legal advisors, when required.
All third-party processors only have access to the data necessary to perform their functions and are obligated to protect your data under contracts compliant with GDPR standards.
How We Protect Your Data
We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration, or disclosure. This includes secure servers, encryption for payment processing, regular security reviews, staff training, and restricted access to data based on roles and necessity.
Your Rights
As a customer of Florist Berrylands, you have a number of rights under the GDPR. These include:
- Right to access: You may request a copy of the personal data we hold about you.
- Right to rectification: You have the right to ask us to correct any inaccuracies or update incomplete information.
- Right to erasure: Also known as ‘the right to be forgotten’, you can ask us to delete your personal information in certain circumstances.
- Right to restrict processing: You may request that we restrict or suppress the processing of your data in certain situations.
- Right to data portability: You can ask for your personal data to be supplied to you or to another controller in a machine-readable format.
- Right to object: You have the right to object to processing where our lawful basis is legitimate interest or where your data is used for direct marketing.
- Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time.
- Right to complain: You also have the right to lodge a complaint with a supervisory authority if you believe your rights have been infringed.
Children’s Data
Our services are not intended for children under 16. We do not knowingly collect personal data from individuals under this age. If we become aware that such data has been collected, we will take appropriate steps to delete it.
Changes to This Policy
This Privacy Policy may be updated from time to time to reflect changes in legislation, technology, or our business practices. Updates will be published on our website, and significant changes will be notified to customers as appropriate.
Contact and Further Information
If you have any questions about this Privacy Policy, your data, or wish to exercise any of your rights, please contact us through the methods provided on our website. We are committed to responding to all requests and concerns promptly and transparently.