Millbank Florist Privacy Policy
Introduction
This Privacy Policy describes how Millbank Florist collects, uses, stores, and protects your personal information in accordance with the General Data Protection Regulation (GDPR). The Policy applies to all customers placing orders with Millbank Florist from Millbank and surrounding districts, whether orders are placed online, over the phone, or in-person.
What Personal Data We Collect
We collect personal data necessary to fulfill your order and provide our services. The types of information we collect include:
- Contact Information: Name, delivery address, billing address, telephone number.
- Order Details: Products and services ordered, specific instructions, recipient name and delivery address if purchasing for someone else.
- Payment Information: Payment method details (we do not store full card details; only necessary transaction identifiers provided securely by payment processors).
- Communications: Correspondence related to your order, including feedback, delivery queries, and customer service interactions.
- Device and Usage Data: IP address, browser type, device identifiers, and data on website interactions, collected via necessary cookies for functionality and security.
Lawful Basis for Processing Your Data
The GDPR requires that we have a lawful basis to process your personal data. Millbank Florist processes your data for the following legal bases:
- Contractual Necessity: We process your data to enter into and fulfil our contract with you when you place an order for products or services.
- Legal Obligation: We may process certain information to comply with legal or regulatory requirements, such as tax or accounting rules.
- Legitimate Interests: We may process your data for legitimate business purposes such as improving our services or responding to your feedback, provided these interests do not override your data subject rights.
- Consent: Where required, for example in relation to optional marketing communications, we will ask for and rely on your consent.
How We Use Your Personal Data
We only use your information as necessary to provide a high-quality service, including:
- Processing and fulfilling your flower orders.
- Managing payments and issuing receipts.
- Delivering products to your chosen address.
- Answering your queries and providing updates regarding your order.
- Meeting our legal and regulatory requirements.
- Improving our website and customer experience.
How Long We Retain Your Data
Your personal data is kept only as long as necessary to fulfill the purposes set out in this policy, or as required by law. Typically, we retain:
- Order and transaction records for up to 7 years, to comply with tax and legal obligations.
- Customer communications for up to 2 years, unless you request erasure sooner and we are not obliged by law to retain them longer.
- Website usage data for up to 26 months, unless aggregated and anonymised for analytical purposes.
After these periods, your information will be securely deleted or anonymised so it can no longer be associated with you.
Our Data Processors
In some cases, we share your data with trusted third-party service providers ("processors") who assist us in providing our services, subject to strict contractual obligations. These may include:
- Payment processing providers, to handle secure credit/debit card transactions and fraud detection.
- Delivery partners or courier services for delivering your order to the recipient's address.
- IT service providers for secure data hosting, website functionality, and system support.
Our processors may only use your data as instructed by us and for no other purpose. We ensure all processors maintain strong security and privacy standards in compliance with the GDPR.
Your Data Protection Rights
Under the GDPR, you have the following rights with respect to your personal data:
- Right to Access: You can request information about the data we hold about you and how it is used.
- Right to Rectification: You can ask us to correct any inaccurate or incomplete data.
- Right to Erasure: In certain circumstances, you may request the deletion of your data ("the right to be forgotten").
- Right to Restrict Processing: You can ask us to restrict or suspend processing of your data in certain situations.
- Right to Data Portability: You may request a copy of your data in a common, machine-readable format for transfer to another service provider.
- Right to Object: You may object to our processing of your data for certain purposes, such as direct marketing.
- Right to Withdraw Consent: Where we rely on your consent to process data, you may withdraw your consent at any time.
To exercise any of these rights, please contact us using the details provided on our website or in your customer materials. We will respond to requests in accordance with GDPR requirements, usually within one month.
Children's Privacy
Our services are not intended for children under the age of 16. We do not knowingly collect or process data belonging to children.
Data Security Measures
We are committed to protecting your data with appropriate technical and organisational measures. These include secure payment systems, restricted access to personal information, encrypted data storage, and regular staff training in data protection.
Policy Updates
We may update this Privacy Policy from time to time to ensure ongoing compliance with the law or to reflect changes in our business practices. We encourage you to review the Privacy Policy whenever you place an order or visit our website. Significant changes will be highlighted in your customer materials or on our website.
Contact & Complaints
If you have any questions, concerns, or complaints about this Privacy Policy or the way we handle your data, please contact us using the details available on our website or printed materials. You also have the right to lodge a complaint with the supervisory authority for data protection if you believe your rights have been infringed.