Malden Rushett Florist Privacy Policy Compliance with GDPR
Introduction
This Privacy Policy outlines how Malden Rushett Florist collects, uses, stores, and protects personal data of all customers who place orders with us in Malden Rushett and the surrounding districts. We are fully committed to complying with the General Data Protection Regulation (GDPR) and any applicable UK data protection laws. This policy explains the nature of personal information we process, our lawful reasons for processing such information, how long we retain it, with whom we share data, and your rights as a data subject.
Scope of the Policy
This policy applies to all individuals who place orders with Malden Rushett Florist, whether online, by phone, or in person, across Malden Rushett and neighboring districts. By placing an order or using our services, you acknowledge your understanding of this policy and consent to the data practices described herein.
Personal Data We Collect
We collect the following categories of personal data in order to fulfill our services and support our business operations:
- Identity Data: Name, title, and contact details (such as address and phone number).
- Order Data: Order details including delivery address, recipient and sender information.
- Payment Data: Payment method (such as card type, though we do not store card numbers), payment status, and transaction references.
- Correspondence: Any communications, enquiries or feedback you provide directly to us.
- Technical Data (for online users): IP address, browser type, usage data (such as pages visited and order history), only as necessary to maintain our website and services.
Lawful Basis for Processing
Under the GDPR, we are required to have a lawful basis for processing your personal data. We process your data under the following bases:
- Contractual Necessity: Most information we collect is necessary to fulfill your order, deliver flowers, and process payment (Article 6(1)(b)).
- Legal Obligation: We may process your data to comply with legal requirements, such as tax and business record keeping (Article 6(1)(c)).
- Legitimate Interests: We have a legitimate interest in maintaining our customer records, improving our services, and ensuring the security of our operations (Article 6(1)(f)).
- Consent: In limited cases, where required by law, we ask for your consent (for example, for marketing communications). You can withdraw your consent at any time.
How We Use Your Data
Your data is used solely for the purposes specified at the time of collection or as set out in this policy. Typical uses include:
- Processing your flower order from creation to completion
- Managing delivery logistics for orders in Malden Rushett and surrounding districts
- Processing payments and issuing receipts
- Communicating order status, resolving queries, and providing customer service
- Fulfilling legal or regulatory obligations
- Processing feedback or complaints for service improvement
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically:
- Order and billing information is retained for up to seven years, in line with tax and accounting rules.
- Contact and correspondence data are retained for up to two years after your most recent order unless you request deletion.
- Data retained for marketing purposes by consent will be held until you withdraw your consent or unsubscribe.
Upon expiration of retention periods, data is securely deleted or anonymized.
Data Processors and Third Parties
We may share your personal data with trusted third parties ("processors") to facilitate our business operations. These may include:
- Payment processing providers (for secure transactions)
- Third-party delivery agents (to deliver your order)
- IT and system providers that support our ordering and record-keeping processes
- Professional advisors (such as auditors and legal counsel, where required)
All such third parties are required to process your data in compliance with GDPR, only for the purposes we specify, and are prohibited from using it for their own purposes.
Data Security
We implement suitable technical and organizational measures to safeguard your personal data against unauthorized access, alteration, disclosure, or destruction. This includes secure storage systems, training for staff, and restricted access protocols. While no system is completely immune from risk, we are committed to maintaining a high level of security for all data entrusted to us.
Your Rights Under GDPR
As a data subject, you have several key rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data where justified (the "right to be forgotten").
- Right to Restrict Processing: Ask us to limit how we use your data in certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used format or have it transferred to another provider.
- Right to Object: Object to specific types of processing, such as direct marketing.
- Right to Withdraw Consent: If processing is based on consent, you may withdraw at any time.
- Right to Complain: Lodge a complaint with a supervisory authority if you believe your rights have been violated.
Policy Updates
This Privacy Policy may be updated from time to time to reflect changes in our practices or legal requirements. Any updated policy will apply from the date of publication. Please review this policy regularly to remain informed about how your data is handled.
Contact and Further Information
If you have any questions or concerns concerning your personal data or this Privacy Policy, please contact us using the details provided on our website or in your order confirmation documents.