Privacy Commitment for Flowers Hampstead Garden Suburb Customers
  Introduction
This Privacy Policy explains how Flowers Hampstead Garden Suburb collects, uses, stores, processes, and protects your personal data when you place an order with us. It applies to all customers ordering flowers from Hampstead Garden Suburb and its surrounding districts, ensuring compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
What Data We Collect
When you place an order or interact with Flowers Hampstead Garden Suburb, we may collect the following types of personal data:
  - Contact Information: Such as your name, delivery address, and billing address.
- Order Details: Information about your purchase, including product selections and gift messages.
- Payment Information: Payment method details (e.g., payment card type), processed securely through our payment service providers. We do not store full card numbers or CVV codes.
- Communication Records: Records and content of your communications with us, such as order instructions or customer support requests.
- Technical Data: Such as IP address, browser type, and device information when you visit our website. This may be collected through cookies and analytics tools.
Lawful Basis for Processing Your Data
We process your personal data only when we have a lawful basis to do so under GDPR. These are the primary legal grounds:
  - Contractual Necessity: We process your data to fulfill our contract with you, such as processing your order and organizing delivery.
- Legal Obligation: We may need to process your data for compliance with applicable laws, such as tax regulations and record-keeping requirements.
- Legitimate Interests: We may use your data to improve customer service, manage business operations, or prevent fraud, provided these interests do not override your rights and interests.
- Consent: Where required, we ask for your explicit consent (for instance, if you opt to receive marketing or promotional communications). You may withdraw consent at any time.
How We Use Your Data
We use your personal information for the following purposes:
  - To process and deliver your flower orders and personalised messages.
- To communicate with you about your order and provide customer support.
- To process payments securely via trusted payment processors.
- To improve our products, services, and website user experience.
- For internal record-keeping, auditing, and compliance with legal obligations.
- To address and resolve any disputes or queries related to your purchase.
How We Share Your Data
We may share your personal data only where necessary and with trusted third parties that act as data processors, including:
  - Payment Service Providers: To facilitate secure online payments and prevent fraud.
- Courier or Delivery Partners: For the purpose of delivering your order to the correct address.
- IT Service Providers: Who assist with secure hosting, website analytics, and support.
- Accountants or Legal Advisors: As part of legitimate business processes and to comply with law.
All third-party service providers are required to process your data in accordance with the GDPR, following strict confidentiality and security measures. We never sell your information to third parties.
How We Protect Your Data
We take your privacy seriously. Flowers Hampstead Garden Suburb employs appropriate technical and organisational security measures to safeguard your information against accidental loss, misuse, unauthorised access, disclosure, alteration, or destruction. These safeguards include secure databases, encrypted connections, and strict access controls within our business.
Data Retention
We retain your personal data only as long as necessary to fulfill the purposes described in this policy:
  - Order and Delivery Data: Retained for up to 6 years to comply with tax, accounting, and audit requirements.
- Customer Communications: Retained as needed for customer service, typically not exceeding 3 years.
- Marketing Consents: Kept for as long as you consent to receive such communications.
After these periods, your data will be securely deleted or anonymised as appropriate.
Your Rights Under GDPR
As a customer, you have certain rights regarding your personal information:
  - Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You may ask us to correct incorrect or incomplete information.
- Right to Erasure: Also known as “the right to be forgotten,” you may request your data be erased, subject to legal requirements.
- Right to Restriction: You have the right to request the restriction or suppression of your personal data under certain circumstances.
- Right to Data Portability: You can obtain your personal data from us in a machine-readable format to transfer elsewhere.
- Right to Object: You may object to processing if you believe it is not in your legitimate interest.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw this at any time.
To exercise any of your rights, you can contact us using the details provided on our website. If you are dissatisfied with our response, you may contact the UK Information Commissioner's Office (ICO).
Updates to This Policy
We may update this Privacy Policy from time to time to reflect legal updates, operational needs, or to enhance clarity. The date of the last update will always be displayed at the end of this document. Please review this page periodically for the latest information on our privacy practices.
Contact Information
If you have any questions, concerns, or wish to exercise your rights, please refer to the contact methods listed on our website. We are committed to protecting your privacy and ensuring your data is handled responsibly and securely.
Last updated: June 2024