South Kensington Flowers GDPR Privacy Policy
Introduction
At South Kensington Flowers, respecting and protecting your personal information is a priority. This Privacy Policy explains how we collect, use, and protect your personal data in compliance with the General Data Protection Regulation (GDPR). This document applies to all customers placing orders for floral arrangements and related products in South Kensington and the surrounding districts.
What Personal Data We Collect
To fulfil your order and provide the best possible service, we collect several types of personal data depending on how you interact with us. The types of data we may collect include:
- Identification Data: Your name and surname.
- Contact Information: Your delivery address, billing address (if different), telephone number, and postal code.
- Order Information: Details about what you purchase, intended recipient, and recipient’s address as required for delivery.
- Payment Details: Payment method information (please note we do not store full card details; payment is processed securely via our payment providers).
- Communications: Any messages, feedback, or complaints you send us, and your communication preferences.
- Technical Data: Information about how you access our website, such as IP address, browser type, operating system, and usage data through cookies and analytics, where you have consented.
Lawful Basis for Processing Your Data
We process your personal data only when permitted by law and when necessary for specific purposes. The lawful bases on which we rely include:
- Contractual Necessity: Most processing is required to fulfil your order or to take steps at your request before entering into a contract (such as answering enquiries).
- Legal Compliance: We may be obligated to process certain data to comply with laws and regulations, including record-keeping and tax obligations.
- Legitimate Interests: We may process your data for our legitimate business purposes, such as improving products, services, and website security, provided these activities do not override your fundamental rights and freedoms.
- Consent: Where we rely on your consent for optional processing (such as marketing communications), you have the right to withdraw this consent at any time.
How We Use Your Personal Data
Your personal details enable us to:
- Process, fulfil, and deliver your flower orders accurately and efficiently.
- Provide customer service and support, including responding to your enquiries or complaints.
- Process payments via secure, third-party payment systems.
- Monitor and enhance our service and website performance through analytics.
- Where permitted, send you updates or marketing about our services (with the ability to opt-out at any time).
- Comply with legal obligations or respond to requests from official authorities when required.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes we collected it for, including satisfying any legal, accounting, or reporting requirements. Typically, order-related data is retained for up to seven years after your transaction to comply with tax and business regulations. Non-transactional data such as general correspondence is kept for a shorter period unless otherwise required by law. After these periods, data is securely deleted or anonymised.
Third-Party Processors
South Kensington Flowers may share personal data with trusted third-party service providers (data processors) who assist us in operating our business. Types of processors we engage with include:
- Payment Service Providers: Handle payment transactions on our behalf. These companies process data securely and in compliance with applicable laws; no full card details are stored by us.
- Delivery Partners: Third-party couriers or drivers may receive delivery details solely to fulfil your order as instructed.
- IT and Hosting Providers: Facilitate the hosting of our website and enable email and communication services.
- Analytical Providers: Supply aggregated website traffic and usage data through cookies and analytics tools, only with your consent as appropriate.
All third-party processors are contractually obliged to use your data only as instructed, keep it secure, and comply with GDPR or equivalent standards. We do not sell or rent your personal data to other organisations for marketing or commercial purposes.
Your Data Protection Rights
Under the GDPR, you have a number of rights in relation to your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure: You can request the deletion of your data in certain circumstances (e.g., where it is no longer needed for the purpose collected).
- Right to Restrict Processing: You can ask us to limit processing where you contest the accuracy or where processing is unlawful, but you oppose erasure.
- Right to Data Portability: You can request a copy of your data in a machine-readable format and may transfer it to another provider.
- Right to Object: You may object to processing based on our legitimate interests or for direct marketing at any time.
- Right to Withdraw Consent: Where you have provided consent to certain processing, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, please contact us using the details provided on our website. We may ask for additional information to verify your identity for your security.
Data Security
We take security seriously and implement appropriate organisational and technical measures to protect your personal data. This includes secure storage of electronic data, staff training, restricted access, and encrypted payment processing. Our website uses industry-standard security protocols to safeguard your information during transmission.
International Transfers
Your personal data is predominantly processed and stored within the United Kingdom or the European Economic Area. If we ever need to transfer data outside these areas, we will ensure that such transfers are subject to adequate safeguards as required by law.
Policy Application and Updates
This Privacy Policy applies to all individuals placing orders with South Kensington Flowers in South Kensington and its surrounding districts. We may occasionally update this policy to reflect legal, regulatory, or business changes. The latest version will always be available on our website with the date of the most recent revision indicated. If material changes occur, we will provide appropriate notice where required.
Contacting Us
If you have any questions or concerns about this Privacy Policy or how we use your personal data, please contact us using the contact details available on our website. We are committed to handling your enquiry efficiently and transparently.