Florist Spitalfields Privacy Policy: Your Data and Rights
  Introduction
Florist Spitalfields is committed to protecting your privacy and handling your personal data with care and respect. This Privacy Policy explains how we collect, use, store, and safeguard information relating to customers who place orders with Florist Spitalfields from Spitalfields and the surrounding districts. We comply with the UK General Data Protection Regulation (GDPR) and other applicable data protection laws. Please read this policy carefully to understand how your information is managed.
Scope of this Policy
This policy applies to all customers who place orders with Florist Spitalfields, whether online, over the phone, or in person, when operating within Spitalfields and neighbouring districts. By placing an order, you agree to the collection and use of your personal data as outlined in this policy.
What Data We Collect
We may collect and process the following types of personal data:
- Identification Details: Name, gender (optional), and, where applicable, age for certain offers or legal compliance.
- Contact Information: Billing and delivery address, contact telephone numbers, and other forms of contact you choose to provide.
- Order Details: Details about your order, delivery preferences, gift messages, and the name and address of the recipient (if different from yourself).
- Payment Information: Payment card details or transaction references (processed securely).
- Device and Usage Information: IP address, browser type and version, time zone setting, device type, and information about your use of our website (through cookies and similar technologies, where applicable and with your consent).
- Communications: Records of your correspondence with us, including queries, feedback, or complaints.
Lawful Basis for Processing
Florist Spitalfields only processes your personal data when permitted by law. The key bases include:
- Performance of a Contract: Processing necessary for fulfilling your order (e.g., delivery of products).
- Legal Obligation: Where processing is required to comply with a legal or regulatory requirement (such as tax laws or prevention of fraud).
- Legitimate Interests: We may process your data to further our legitimate business interests, such as improving our services, marketing to existing customers (subject to your rights), or preventing fraud, provided such interests are not overridden by your fundamental rights and freedoms.
- Consent: We will seek your consent for certain data processing activities, such as sending marketing communications to new customers. You may withdraw consent at any time.
How We Use Your Personal Data
We use your personal information to:
- Process and deliver your orders to your chosen recipients;
- Communicate with you regarding your order, customer support, or updates to our services;
- Manage payments and refunds;
- Personalise your experience, including remembering preferences and order history;
- Send you marketing communications (where you have provided consent or have an existing customer relationship);
- Maintain business records and comply with laws.
Data Retention
Your personal data is retained only for as long as necessary to fulfil the purpose(s) for which it was collected, including fulfilling your orders and meeting legal, accounting, or reporting requirements. Specifically:
- Order records and associated data are generally kept for up to seven years in line with accounting and tax obligations;
- Marketing consent records are retained for as long as you remain opted in, or until you withdraw your consent;
- Basic contact and preference information may be retained for up to two years after your last order unless you request deletion or we are legally compelled not to delete it.
Third-Party Processors
To provide our services, we may share your information with trusted third-party processors who support delivery and payment operations, information technology, web hosting, analytics, and marketing (with your consent). Such processors may include:
- Payment processing companies (for secure card and online payments);
- Delivery and courier services (for fulfilling orders);
- IT and web hosting providers (to operate and maintain our website and systems);
- Marketing service providers (for email campaigns to opted-in recipients);
- Professional advisers such as accountants and legal advisors (where necessary for compliance and business functions).
All processors are bound by strict confidentiality and data security obligations, only able to process your data in accordance with our instructions and this Privacy Policy.
Your Data Rights
Under the UK GDPR, you have important rights regarding your personal data. These include:
- Right to Access: You may request a copy of any personal data we hold about you.
- Right to Rectification: Request correction of incorrect or incomplete data.
- Right to Erasure: Request deletion of your personal data, subject to certain conditions (for example, retention obligations under law).
- Right to Restrict Processing: Ask us to suspend processing of your data in certain circumstances.
- Right to Object: Object to processing carried out on the basis of legitimate interests or direct marketing.
- Right to Data Portability: Request the transfer of your data to another party where feasible.
- Right to Withdraw Consent: Where we have relied on consent, you can withdraw this at any time.
- Right to Lodge a Complaint: You may file a complaint with the UK data protection authority if you believe your data has been handled improperly.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. This includes secure storage, restricted access, employee training, and regular review of our security practices.
Changes to this Privacy Policy
We may review and update this Privacy Policy from time to time to reflect changes in how we process your data or to comply with new legal requirements. The latest version will always apply to your use of Florist Spitalfields services within Spitalfields and surrounding areas.
Contact and Queries
If you wish to exercise any of your data protection rights or have questions about this Privacy Policy or our data processing practices, please contact us using the methods detailed on our website or in your order confirmation documents. We are committed to responding promptly and to treating your concerns with seriousness and respect.