Florist Manor House Privacy Policy – Customer Data and Rights

About This Privacy Policy

This Privacy Policy explains how Florist Manor House collects, uses, stores, and protects your personal data when you place an order with us from Manor House and surrounding districts. It also outlines your rights under the General Data Protection Regulation (GDPR). We are committed to ensuring your privacy is protected and that your information is handled in a lawful, transparent, and respectful manner.

Scope of Policy

This policy applies to all customers and individuals who place orders with Florist Manor House for delivery or pickup within Manor House and the surrounding districts. By engaging with our services, you acknowledge the data practices described in this policy.

What Data We Collect

We collect personal data only where necessary for the provision of our services. Information we may collect includes:

  • Identity Data: Your name and, if applicable, the recipient's name.
  • Contact Data: Postal addresses, delivery addresses, and, if provided, other relevant address details.
  • Order Data: Information about items ordered, delivery instructions, and special requests.
  • Transaction Data: Details about payments and purchases (note that payment card data is processed securely by our payment provider, not stored by Florist Manor House).
  • Communication Data: Records of correspondence, instructions, queries, or feedback regarding your order.
  • Technical Data: Limited information related to use of our website, such as IP address and browser type, for performance and security.

Lawful Basis for Data Processing

We only process your personal data where we have a lawful basis under GDPR, including:

  • Contract: To fulfil our contract with you when you place an order (processing and delivering your flowers or related services).
  • Legal Obligation: To comply with applicable laws and accounting or taxation rules.
  • Legitimate Interests: For administrative purposes, record keeping, quality assurance, and improving our services, provided these interests are not overridden by your rights.
  • Consent: If you provide explicit consent for certain optional uses, such as occasional marketing (if offered).

How We Use and Share Your Data

Your personal data is used to process your floral orders, manage your customer relationship, and communicate with you about your order. We may use aggregated and anonymised information for business analysis but not in a way that can identify individuals.

We do not sell or rent your personal data. Information may be shared with trusted third parties, known as data processors, strictly for the purposes outlined below.

Data Retention Periods

Your personal data is retained for as long as necessary to fulfil the purposes for which it was collected:

  • Order and Transaction Records: Retained for up to seven years to comply with accounting, tax, and legal requirements.
  • Communication Records: Retained for up to two years for quality, training, and dispute resolution, unless required longer by law.
  • Technical Data: Retained for security and performance up to twelve months.

Once the relevant retention period has expired, your personal data will be securely deleted or anonymised.

Processors and Data Security

Florist Manor House uses carefully selected third-party providers (processors) to support our operations. These include payment processing services, IT systems, and delivery couriers. We ensure that all processors are GDPR-compliant and process your data only on our behalf, following strict confidentiality and security measures.

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration, or disclosure. Access to personal data is restricted to staff and processors on a need-to-know basis for the purposes described in this policy.

Your Data Protection Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right to Access: You may request a copy of your personal data we hold.
  • Right to Rectification: You may ask us to correct any inaccurate or incomplete data.
  • Right to Erasure: You may ask us to delete your data where there is no compelling reason for its continued processing (unless legal obligations require retention).
  • Right to Restrict Processing: You can ask us to suspend the processing of personal data in certain circumstances.
  • Right to Data Portability: You may request your personal data in a machine-readable format to transfer to another provider.
  • Right to Object: You may object to processing based on legitimate interests or direct marketing (should this occur).
  • Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw your consent at any time.

How to Exercise Your Rights

You may exercise your data protection rights by making a written request to Florist Manor House. Before fulfilling your request, we may need to verify your identity to protect your data security. We endeavour to respond to requests within one month as provided by GDPR requirements.

Updating This Policy

Florist Manor House reviews and updates this Privacy Policy periodically to reflect changes in our practices or legal obligations. We encourage customers to revisit this page regularly to stay informed about how we handle personal data.

Contact and Complaints

If you have any concerns about how your personal data is handled, you have the right to lodge a complaint with the relevant supervisory authority. We encourage you to contact us directly as we aim to resolve privacy concerns promptly and comprehensively.