Norbiton Florist Privacy Policy
Scope and Purpose of this Policy
This Privacy Policy explains how Norbiton Florist collects, uses, shares, and safeguards personal data in full accordance with the General Data Protection Regulation (GDPR). It applies to all customers placing orders from Norbiton and the surrounding districts, whether online, by phone, or in-person. By placing an order or using our services, you accept the terms described herein.
What Data We Collect
When you interact with Norbiton Florist, we collect the following categories of data:
- Identification Data: Name, delivery address, and contact information (such as mobile or landline number).
- Order Details: Purchased products, delivery instructions, order history, and any gift messages.
- Billing Data: Payment method used, billing address (note: payment details are handled by our payment processor and are not stored by Norbiton Florist).
- Communications: Any correspondence between you and Norbiton Florist regarding orders, feedback, or general enquiries.
- Technical Data: Browsing activity on our website, IP address, and device information, when applicable.
Please note that we do not knowingly collect data from children under 16 without parental consent.
Lawful Basis for Processing Your Data
Norbiton Florist processes personal data only when we have a lawful basis for doing so, as outlined in the GDPR. Our lawful bases include:
- Contractual Necessity: To take steps at your request before entering into a contract and to facilitate the purchase, processing, and delivery of your floral orders.
- Legal Obligation: For complying with applicable legal obligations such as accounting, taxation, or the prevention of fraud or abuse.
- Legitimate Interests: To improve our services, manage our customer relationships, or pursue our business interests where such interests are not overridden by your rights and freedoms.
- Consent: Where you have provided explicit consent (for marketing communications, for example), which you may withdraw at any time.
Data Retention
Your personal data is retained only as long as necessary for the purposes for which it was collected, or as required by applicable laws. In general:
- Order and customer records are retained for up to seven years for accounting and auditing purposes.
- Communication logs are retained for up to two years after order completion to resolve enquiries or complaints.
- Technical or browsing data may be retained for up to one year for website analysis before being anonymised or deleted.
Once your data is no longer needed, it is securely deleted or anonymised, unless further retention is required by law.
Processors and Data Sharing
Norbiton Florist may share your data with trusted third-party processors to provide our services effectively and securely. These include:
- Payment Processors: Third parties who process card or electronic payments on our behalf. These providers are responsible for the security of their processing activities and comply with data protection requirements.
- Delivery Partners: On occasions where delivery is outsourced, we share relevant details with our trusted couriers to fulfil your order.
- IT and Web Services: Technology providers and web hosting services that enable our website and customer management systems to operate reliably and securely.
- Professional Advisers: Legal, accounting, or business consultants, as required for compliance or legitimate interests.
All third-party processors are bound by contractual obligations to protect your data, use it only for our specified purposes, and comply fully with applicable privacy legislation. Your data is not sold or made available for unrelated third-party marketing.
Your Rights under GDPR
As a data subject, you have certain rights regarding your personal data collected and processed by Norbiton Florist:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to ask for inaccurate or incomplete information to be corrected.
- Right to Erasure: You may request deletion of your data where there is no overriding lawful basis for retention.
- Right to Restrict Processing: In specific situations, you may request that we limit the processing of your data.
- Right to Data Portability: You may receive your data in a structured, commonly used, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw this at any time.
- Right to Lodge a Complaint: If you believe we have processed your data unlawfully, you have the right to lodge a complaint with the relevant supervisory authority.
Please note that some rights may be subject to preconditions or exceptions under the GDPR. Requests will be reviewed and fulfilled in accordance with applicable data protection laws.
Security Measures
Norbiton Florist employs appropriate technical and organisational measures to protect your data against unauthorised access, accidental loss, destruction, or damage. This includes secure transmission methods, access controls for staff, encrypted databases, and regular review of our data protection practices.
Policy Updates
This Privacy Policy may be revised to reflect changes in legal requirements, our services, or best practices. Material changes will be communicated clearly to customers where appropriate. The "Last Updated" date at the top of this policy indicates when it was last reviewed. We encourage you to review this policy periodically for the latest information.
Contact and Further Information
If you have any questions about your data, this Privacy Policy, or wish to exercise your rights, please contact us via our usual business contact channels or in writing at our registered office address. We will endeavour to respond to all requests promptly and in compliance with applicable law.