This Privacy Policy explains how Florist Wandsworth collects, uses, stores, and protects your personal data when you place an order with us. This policy is designed to meet the requirements of the General Data Protection Regulation (EU 2016/679) ("GDPR"). It applies to all customers placing orders in Wandsworth and the surrounding districts. We are committed to ensuring the privacy and security of your information, and to providing transparency in how your data is handled.
Florist Wandsworth collects personal data necessary to process your order and provide our services effectively. The types of data we may collect include:
Under the GDPR, we must have lawful grounds to collect and process your personal data. Florist Wandsworth relies on the following lawful bases:
Florist Wandsworth uses your personal information for the following purposes:
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically, we will keep your data for up to seven years from the date of your last transaction or as long as required by law. After this period, your data will be securely deleted or anonymised.
To provide our services, we may engage third-party service providers (known as processors) that process data on our behalf. These include, but are not limited to, payment gateways, IT service providers, delivery partners, and website hosting companies. We ensure that all processors adhere to strong data protection standards and are contractually obligated to process your personal data securely and only as instructed by Florist Wandsworth. We do not sell or rent your data to third parties.
We may also share your data when required by law, such as in response to a court order or regulatory request, but only to the extent necessary and permitted by law.
Your privacy and security are important to us. Florist Wandsworth implements appropriate technical and organisational security measures to prevent unauthorised access, disclosure, alteration, or destruction of your personal data. These include:
As a data subject under the GDPR, you have the following rights regarding your personal data:
Your personal data is primarily stored and processed within the United Kingdom and the European Economic Area (EEA). If we transfer your data outside the EEA, we ensure that suitable safeguards are in place to protect your information in accordance with GDPR requirements.
We may update this Privacy Policy from time to time to reflect changes in technology, legal requirements, or our business operations. The latest version will always be available on our website. We encourage you to review this policy periodically for any updates.
If you have any questions about this Privacy Policy or your personal data, please get in touch with us through our website. We are committed to responding promptly to your requests and concerns regarding your privacy.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
