Fortis Green Florist Privacy Policy
Introduction
This Privacy Policy sets out how Fortis Green Florist collects, processes, stores, and protects your personal information when you place an order with us. It applies to customers in Fortis Green and surrounding districts who interact with our florist services. We are committed to being transparent about how we handle your information, complying with the General Data Protection Regulation (GDPR) and relevant UK data protection legislation.
Information We Collect
When you place an order or contact Fortis Green Florist, we may collect the following types of personal data:
- Identification Data: Your full name.
- Contact Details: Delivery address, billing address, phone number, and, when necessary, your email address.
- Order Information: Details of the products and services you have ordered from us, any personal message to accompany your flowers, preferences, and instructions related to your order.
- Payment Data: Details relating to your order's payment (e.g., payment confirmation, but not your card number or full payment card details, as these are handled securely by payment processors).
- Communications: Records of your correspondence with us, including queries, compliments, or complaints.
- Website Usage Data: Non-identifying technical data collected through cookies or analytics to help us improve our website experience. You will be notified about the use of cookies and may consent as is lawful under GDPR requirements.
Lawful Bases for Processing Your Data
Under GDPR, our lawful bases for collecting and processing your personal data include:
- Contractual Necessity: Processing your data is required to fulfil your order, process payments, and deliver products and services as requested.
- Legal Obligation: We may need to retain certain data for tax, accounting, or legal purposes.
- Legitimate Interests: Certain information is processed to improve our services, communicate with you about your order, or to ensure our website works efficiently, provided our interests do not override your rights.
- Consent: Where consent is needed (for example, for optional marketing communications), it will be clearly obtained, and you have the right to withdraw your consent at any time.
How We Use Your Information
We use your personal data for the following purposes:
- To process and fulfil your floral orders, including arranging delivery and providing customer support.
- To process payments via secure third-party payment processors.
- To communicate with you about your order status, manage your preferences, resolve issues, or respond to your queries.
- To comply with applicable legal and tax obligations.
- To improve our products, customer experience, and website operations via analytics and customer feedback.
- If separately consented, to keep you informed about special offers and new products through occasional marketing communications.
Retention of Your Personal Data
Your personal data is only kept for as long as necessary to fulfil the purposes outlined above, or as required by law. In general:
- Order and Transaction Records: Retained for a minimum of six years to comply with UK tax and accounting requirements.
- Customer Correspondence: Retained for up to two years after your last interaction to provide continuity and support.
- Marketing Consent Data: If you opt-in to receive marketing communications, we will retain your preference until you unsubscribe or request erasure.
- Technical/Analytical Data: Aggregated and anonymised data may be kept for longer to inform business improvements, but this cannot be used to identify you personally.
Data Processors and Sharing
We may share your personal data with trusted third party service providers that help us deliver our services. These may include:
- Payment Processors: To securely process and validate payment transactions for your orders.
- Delivery/Courier Services: To ensure prompt and accurate delivery of your order.
- IT and Website Support Providers: For hosting, analytics, and technical maintenance of our online presence.
All third-party processors comply with GDPR or equivalent data protection standards, and only process your data based on our instructions. We do not sell or trade your personal information to any third parties for their own marketing or commercial purposes. Where legally required, data may also be disclosed to law enforcement or regulatory bodies.
Your Rights Under GDPR
You have various rights regarding your personal data as provided by GDPR, including:
- Right of Access: Request a copy of personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data, where there is no legal basis for continued processing.
- Right to Restrict Processing: Request limits on how we use your data in certain circumstances.
- Right to Data Portability: Request transfer of your data to another provider in a commonly used format.
- Right to Object: Object to processing of your data where our lawful basis is legitimate interest or direct marketing.
- Right to Withdraw Consent: Withdraw your consent at any time when processing is based solely on consent.
To exercise your rights, please contact us in writing. We will respond within one calendar month and honour valid requests where possible. Please note that some rights may be limited by legal or regulatory requirements.
Security of Your Data
Fortis Green Florist takes all reasonable technical and organisational measures to ensure your personal information is kept safe and secure. This includes protecting against unauthorised access, accidental loss, or disclosure. Access is restricted to those employees or providers who need your data for valid business purposes.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or for other operational reasons. We recommend reviewing this policy periodically for any updates. Changes take effect as soon as they are posted on this page.
Contact and Complaints
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us in writing. If you are not satisfied with our response, you have the right to lodge a complaint with the UK’s Information Commissioner’s Office (ICO).