Privacy Policy for Florist Surrey Customers
  Introduction
This Privacy Policy describes how Florist Surrey (“we”, “our”, “us”) collects, processes, and protects your personal data when you place orders for floral arrangements and related products and services. This policy is intended for all customers who place orders with Florist Surrey from Surrey and the surrounding districts, ensuring transparency in how personal information is handled in compliance with the UK General Data Protection Regulation (GDPR).
What Data We Collect
When you interact with Florist Surrey, we collect relevant personal data necessary to fulfill your order and provide a positive customer experience. The types of personal information we may collect include:
  - Contact Information: Such as your full name, delivery address, billing address, and telephone number.
 
  - Order Details: Information about the products you order, recipient details (name and delivery address), card messages, and any special instructions.
 
  - Payment Information: Such as payment card details (processed via a secure payment processor; we do not directly store your card information).
 
  - Communication Records: Details of your correspondence with us, including queries, feedback, and complaints.
 
  - Technical Data: Like IP address, browser type, and device identifiers when you use our website, which may be collected via cookies or analytics tools to improve our services.
 
Lawful Basis for Processing
Florist Surrey processes your personal data only when there is a valid lawful basis under GDPR. The primary grounds under which we handle your data include:
  - Contractual Necessity: Processing your personal data is necessary to fulfill the contract of sale when you place an order with us, including communication, payment processing, and delivery.
 
  - Legal Obligation: In some circumstances, we must retain certain records to comply with applicable UK law, including accounting and tax regulations.
 
  - Legitimate Interests: To manage and improve our service, prevent fraud, or respond to your enquiries. When relying on legitimate interests, we consider the impact on your privacy and take steps to respect your rights.
 
  - Consent: For certain types of direct marketing communications, we will obtain your explicit consent, which you can withdraw at any time.
 
How We Use Your Data
Your personal data is used solely for the purposes for which it was collected, which may include:
  - Fulfilling, dispatching, and delivering orders to you or your chosen recipients.
 
  - Processing payments via secure payment service providers.
 
  - Managing your account or past order history if applicable.
 
  - Responding to inquiries, special requests, or feedback.
 
  - Sending service-related communications, such as order confirmations or delivery updates.
 
  - Complying with legal and regulatory obligations.
 
  - Improving our website, customer experience, and the relevance of products we offer, using technical and analytical data.
 
Data Retention
We will only retain your personal data for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including for the purposes of satisfying legal, accounting, or regulatory requirements.
In most cases, we retain order and account information for up to six years after your last transaction or enquiry, in accordance with UK tax and contract laws. After this period, personal data is securely deleted or anonymised unless there is a legitimate reason to keep it longer, such as ongoing legal proceedings.
Data Processors and Sharing
Your information may be shared with trusted third parties (“processors”) under strict contractual controls, solely for the following reasons:
  - Payment Processing: To process payments securely.
 
  - Delivery Partners: To fulfill and deliver your floral orders to the correct address.
 
  - IT and Cloud Service Providers: For secure hosting, data storage, and system support.
 
  - Professional Advisors: For necessary business management, such as accounting and legal advice.
 
  - Regulatory Compliance: If required by law or valid government authority.
 
All third-party processors are required to protect your information, act only on our instructions, and comply with data protection legislation. Florist Surrey will not sell or rent your personal data to any third party for marketing purposes.
Your Data Protection Rights
You have a number of rights under the UK GDPR in relation to your personal data, including:
  - Right to Access: Request a copy of the personal data we hold about you.
 
  - Right to Rectification: Correct any inaccurate or incomplete data.
 
  - Right to Erasure: Ask for your data to be deleted, where it is no longer necessary for the purpose collected, or where consent has been withdrawn and there are no other legal grounds for processing.
 
  - Right to Restriction: Request restriction of processing under certain circumstances.
 
  - Right to Data Portability: Receive your data in a common format or have it transferred to another provider.
 
  - Right to Object: Object to processing based on our legitimate interests or direct marketing.
 
  - Right to Withdraw Consent: Where processing is based on consent, you may withdraw this at any time.
 
You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your rights have not been properly observed.
Data Security
We have implemented appropriate security measures, both technical and organisational, to prevent your personal information from being accidentally lost, accessed, or used in an unauthorised way. Access to your data is strictly limited to those staff, agents, and processors who have a business need to know.
Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or for other operational reasons. Any significant changes will be communicated clearly, and the date of the last revision will always be indicated at the start of the policy.
Contact and Further Information
If you have any questions, concerns, or requests regarding this privacy policy or your personal data, please contact us using the details provided on our website.
This version of the Florist Surrey Privacy Policy applies to all customers placing orders from Surrey and the surrounding districts and is effective as of June 2024.