Westminster Florist Privacy Policy
Introduction
This Privacy Policy describes how Westminster Florist, as a data controller, collects, uses, stores, and safeguards your personal information in accordance with the General Data Protection Regulation (GDPR). This Policy applies to all customers placing orders with Westminster Florist in Westminster and surrounding districts. We are committed to ensuring the privacy and security of your personal data and explain below how your information is handled.
What Data We Collect
When you place an order with Westminster Florist, we collect and process certain categories of personal data, which may include:
- Identification Data: such as your full name, billing address, and delivery address;
- Contact Information: such as telephone numbers and, if provided, email addresses for communication purposes;
- Order Details: items purchased, delivery instructions, gift card messages, delivery dates, and payment information (note: we do not store card details, but these are processed securely through third-party payment processors);
- Correspondence: records of your communication with us, including customer service queries and feedback;
- Technical Data: your IP address, browser type, and access times, collected via our website to ensure security and optimize our service.
Lawful Basis for Processing Your Data
According to the GDPR, we must have a lawful basis for each instance in which we process your personal information. Westminster Florist relies on the following lawful bases:
- Contractual Necessity: We process most personal data because it is necessary for fulfilling your order, delivering products, and providing customer service.
- Legitimate Interests: We may process your information for our legitimate interest in managing and improving our services, preventing fraud, and ensuring security. Where we rely on this basis, we balance our interests against your rights and freedoms.
- Legal Obligation: We may process your data to comply with applicable laws, tax requirements, and to respond to lawful requests by public authorities.
- Consent: In some cases (such as marketing communications), we process your personal data based on your explicit consent, which you may withdraw at any time.
How We Use Your Personal Information
Your personal data is used for the following purposes:
- To process and deliver your orders, including arranging delivery to the address provided;
- To communicate order confirmations, delivery updates, and handle inquiries or support requests;
- To process payments securely via trusted third-party payment services;
- To personalize your experience and provide relevant products and promotional offers, with your consent where required;
- To ensure the security and integrity of our website and services;
- To comply with legal, regulatory, and tax obligations.
Retention of Personal Data
We retain your personal information only as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Typically, order and transaction records are held for up to seven years, in line with tax and accounting obligations. Customer correspondence and information provided via our online services may be stored for a shorter period unless a longer retention is required by law. Once your data is no longer required, it is securely deleted or anonymized.
Data Processors and Third Parties
Westminster Florist occasionally engages third-party service providers who act as data processors on our behalf. These include:
- Payment processors: to facilitate secure payment transactions;
- Delivery partners: to ensure timely and accurate order delivery;
- IT and hosting services: to securely store and manage data supporting our website functionality;
- Customer service providers: assisting with inquiries or support on our behalf.
All third-party processors are contractually obligated to process your data securely and only according to our instructions. Your data is not shared with third parties for their own direct marketing purposes, nor is it sold. Information may be disclosed to authorities if required by law.
Your Rights Under the GDPR
Under GDPR, you have several important data rights, which Westminster Florist respects and upholds:
- Right of Access: You may request information about what personal data we hold about you and how it is processed.
- Right to Rectification: You can ask us to correct or update your information if it is incomplete or inaccurate.
- Right to Erasure: You can request that we delete your personal information under certain circumstances (for example, if data is no longer required for its original purpose).
- Right to Restrict Processing: You can ask us to limit the way your personal data is used in specific cases.
- Right to Data Portability: Where processing is based on consent or contract, you have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.
- Right to Object: You may object to the processing of your personal data where processing is based on legitimate interests or direct marketing.
- Right to Withdraw Consent: If we process your data based on your consent, you may withdraw that consent at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise your rights, please contact us directly via the methods provided on our website or in your order confirmation documents. We may need to request some information to verify your identity and, where applicable, to help us locate your data.
Security of Your Data
We take the protection of your data seriously. Westminster Florist employs appropriate technical and organizational measures to safeguard personal data from unauthorized access, disclosure, alteration, or destruction. Access to your data is limited to personnel and partners who require it to perform their duties.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time in response to legal, technical, or business developments. The updated Policy will be posted on our website with the date of the last revision. We encourage you to review it periodically to stay informed about our data practices.
Contact and Complaints
If you have any questions, concerns, or wish to exercise your GDPR data rights, please use the contact methods provided on our website or within your order documentation. If you believe that your data protection rights have not been respected, you have the right to lodge a complaint with the relevant supervisory authority.