Florist Cricklewood GDPR-Compliant Privacy Policy
  Introduction
This Privacy Policy explains how Florist Cricklewood (“we”, “our”, “us”) collects, uses, protects, and manages your personal data when you place orders with us from Cricklewood and the surrounding districts. We are committed to complying with the General Data Protection Regulation (GDPR) and local data protection laws to ensure the privacy and security of your information. Please read this policy carefully to understand your rights and how we handle your data.
Scope of Policy
This policy applies to all customers who place orders with Florist Cricklewood from Cricklewood and the surrounding districts. It covers data collected through our website, by phone, or in person at our physical locations.
What Data We Collect
Depending on the nature of your interaction with Florist Cricklewood, we may collect the following categories of personal data:
  - Contact Details: Your name, delivery address, billing address, email address, and phone number.
- Order Information: Details of flowers or products ordered, order dates, occasion information (e.g., birthdays or anniversaries), and delivery instructions.
- Payment Data: Payment method details (we do not store full credit/debit card numbers; payments may be processed securely via third-party payment processors).
- Recipient Information: If you order on behalf of someone else, we may collect recipient names, addresses, and any personalised messages provided for deliveries.
- Technical Data: Information about your device, browser type, IP address, and interactions with our website (e.g., pages visited), collected via cookies and analytics tools.
- Communication History: Records of correspondence, queries, feedback, and complaints when you contact us.
Lawful Bases for Processing Your Data
Under the GDPR, we are required to have lawful grounds to collect and use your personal data. Florist Cricklewood processes your data on the following bases:
  - Contractual Necessity: To process and fulfil your orders, take payment, arrange delivery, and provide customer service.
- Legal Obligation: To fulfil tax, accounting, and record-keeping obligations required by law.
- Legitimate Interests: To improve our products and services, ensure the security of our website, manage and respond to your queries, and for fraud prevention. We only process personal data where our interests do not override your fundamental rights and freedoms.
- Consent: Where you provide explicit permission, such as opting in to receive marketing communications. You can withdraw your consent at any time.
Retention of Your Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically, we will retain:
  - Order details and associated personal data for up to 7 years, as required by tax and accounting laws.
- Marketing consent and communication preferences until you withdraw consent or unsubscribe.
- Technical data for a shorter period (up to 2 years), except where required for security or troubleshooting purposes.
Once retention periods expire, we securely delete or anonymise your data.
Data Processors and Third Parties
Florist Cricklewood may share your personal data with third-party service providers (“processors”) who assist us in operating our business and delivering your orders. These processors include:
  - Payment processing services (to handle and authorise transactions securely)
- Delivery couriers or postal services (to enable accurate and prompt delivery of your orders)
- IT support and website hosting providers (for the functioning and security of our website and systems)
- Marketing or customer communication platforms (only where you have opted-in for such communications)
- Professional advisers (such as accountants or legal advisers, where necessary for compliance)
All processors are required to protect your data and are not permitted to use it for their own purposes. We do not share your data with third parties for their direct marketing purposes.
Your personal data may be transferred and stored outside the European Economic Area (EEA), strictly where processors provide appropriate safeguards, such as approved data protection measures.
Your Data Protection Rights
Under the GDPR, you have several important rights regarding your personal data, including:
  - Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Ask for your personal data to be deleted when it is no longer necessary for processing.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Restrict Processing: Request that we limit the processing of your personal data in certain circumstances.
- Right to Data Portability: Obtain your data in a structured, commonly used, and machine-readable format, or have it transferred to another controller.
- Right to Withdraw Consent: Withdraw your consent at any time, for example, to stop receiving marketing communications.
- Right to Lodge a Complaint: Complain to the data protection authority if you believe your rights have been infringed.
To exercise these rights, please contact us using our standard communication channels. We may need to verify your identity before responding to your request. We aim to respond within one month.
Security of Your Data
We take the security of your personal data seriously and implement technical and organisational measures to protect it. These measures include secure servers, encryption of sensitive information during transmission, and restrictions on access to your personal data to authorised employees and processors only.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any updates will be posted on our website, and, where appropriate, notified to you directly. We encourage you to review this policy regularly.
Contacting Us
If you have questions about this Privacy Policy, your data, or how we process it, please contact us through our contact page or using the communication methods available on our website or in-store. We are committed to resolving any issues promptly and transparently.
Last updated: June 2024.