This Privacy Policy explains how Florist West Drayton ("we", "us", or "our") collects, uses, stores, and protects the personal data of our customers. This policy applies to all individuals who place orders with Florist West Drayton, whether located in West Drayton or the surrounding districts. We are committed to protecting your privacy in compliance with the UK General Data Protection Regulation (UK GDPR) and all relevant legislation.
When you interact with Florist West Drayton, notably when you place an order for flowers or related products, we collect and process certain personal data required to fulfil your order, communicate with you, and improve our services. The types of personal data we may collect include:
We process your personal data only where we have a lawful basis to do so under the UK GDPR. The lawful bases we rely on include:
Your data is used exclusively for the stated purposes, which may include:
To fulfil your order and operate our business, it may be necessary to share your personal data with carefully selected third-party service providers, also known as processors. These may include:
All third-party service providers are contractually required to handle your data securely, act only on our instructions, and comply with data protection legislation. We do not sell or otherwise share your personal data with any third party outside of the purposes stated above.
Your personal data is retained only for as long as is necessary to fulfil the purposes for which it was collected, including fulfilling contractual obligations, complying with legal requirements, and resolving disputes. As a general rule, we retain order, invoicing, and customer communication records for seven (7) years from the fulfilment of each order, in line with HMRC and accounting requirements. After this period, your data will be securely deleted or anonymised, unless a longer retention period is required by law.
We take the security of your personal information seriously and have implemented appropriate technical and organisational measures to protect it against unauthorised access, disclosure, alteration, or destruction. These measures include secure servers, encryption of sensitive data, regular security reviews, and staff training on data protection requirements.
Under the UK GDPR, you have the following rights over your personal data:
To exercise any of these rights, please contact us using the details available on our website or in-store. We will respond to your requests in accordance with legal requirements and within statutory timeframes.
Our services are not intended for children under the age of 16. We do not knowingly collect or process personal data of children under this age. If we learn that we have mistakenly collected personal information from a child under 16, we will take steps to delete the information as soon as possible.
We reserve the right to update this Privacy Policy from time to time to reflect changes in legal requirements, our processing practices, or operational needs. The latest version will always be available on our website, and significant changes will be notified to you where appropriate.
If you have questions regarding this Privacy Policy, concerns about your data, or wish to exercise your rights, please contact us using the information provided on our official contact page or instore. If you are not satisfied with our response, you may refer your concerns to the Information Commissioner’s Office (ICO).
Please fill out the form below to send us an email and we will get back to you as soon as possible.
