Surrey Quays Florist Customer Privacy Policy
  Introduction
This Privacy Policy describes how Surrey Quays Florist collects, uses, stores, and protects the personal data of our customers. Our policy is designed to reflect our obligations under the UK General Data Protection Regulation (GDPR) and applies to all individuals placing orders with Surrey Quays Florist from Surrey Quays and surrounding districts.
Scope of the Policy
This policy covers personal information collected through interactions related to the placing and fulfilment of flower orders, whether in person, by telephone, or through our website, by customers ordering from Surrey Quays and neighbouring areas.
Personal Data We Collect
We collect the following categories of personal data to provide our services:
- Identification and Contact Data: Name, delivery address, billing address, and telephone number.
 - Order Information: Details of your floral order, including product selection, recipient details (name, delivery address, and any message content), and payment confirmation (no payment card details are stored by Surrey Quays Florist).
 - Communication Data: Correspondence via forms, telephone, or recorded conversations for order verification or customer service.
 - Website Usage Data: When you use our website, certain technical data such as your IP address, browser type, and usage patterns may be collected through cookies and analytics tools (subject to your consent where required).
 
Lawful Basis for Processing
Our legal bases for processing your data under GDPR include:
- Contractual Necessity: Processing necessary for the fulfilment of your order and provision of related customer service.
 - Legal Obligation: To comply with legal and tax requirements (such as maintaining records of transactions).
 - Legitimate Interests: To improve our services, prevent fraud, and ensure network and information security, provided such interests do not override your fundamental rights.
 - Consent: Where we are required by law (for example, marketing communications if you opt in), we will seek your explicit consent. You can withdraw your consent at any time.
 
How We Use Your Data
We use your data to:
- Process, confirm and deliver your flower orders.
 - Contact you regarding your order status or to resolve any issues related to your requests.
 - Process payments and record orders for tax and accounting purposes.
 - Improve our service and customer experience through data analysis (in anonymised or pseudonymised form where possible).
 - Send you service-related communications and, if you have consented, occasional marketing updates or promotions.
 
Data Retention
Your personal data will be retained only as long as necessary for the purpose of fulfilling orders, meeting legal and accounting obligations, and resolving any customer service issues. Specifically:
- Order records and correspondence are retained for up to six years to comply with UK accounting and tax legislation.
 - If you have consented to receive marketing, your contact details are held until you withdraw consent or request deletion.
 - If you request data erasure and there is no overriding legal requirement to retain, your data will be securely deleted.
 
Data Processors and Sharing
Where necessary, your data may be processed by trusted third parties who act as data processors on our behalf, always under contractual obligations to handle your data in compliance with GDPR:
- Payment service providers: For the processing of online or card payments.
 - IT service providers: For website hosting, email, order management systems, and secure storage solutions.
 - Delivery agents: Where required to facilitate the delivery of your order to addresses in Surrey Quays and surrounding districts.
 
We do not sell or share your data with external third parties for marketing purposes. Data will only be transferred outside the UK or EEA if required, and in such cases, we will ensure appropriate safeguards are in place as mandated by GDPR.
Your Data Protection Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of your personal information held by us.
 - Right to Rectification: Request corrections to inaccurate or incomplete data.
 - Right to Erasure: Request deletion of your data where legally permissible.
 - Right to Restrict Processing: Ask us to restrict the processing of your data in certain circumstances.
 - Right to Data Portability: Obtain your data in a structured, commonly used format where processing is based on consent or contract.
 - Right to Object: Object to processing of your personal data for direct marketing or where our legitimate interests are invoked.
 - Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.
 - Right to Lodge a Complaint: You have the right to raise concerns with the Information Commissioner's Office (ICO) if you believe your data rights are not being respected.
 
Data Security
We implement appropriate physical, technical, and organisational measures to safeguard your data from loss, misuse, unauthorised access, alteration, or disclosure. Access to your personal data is limited to staff and processors who require it for legitimate business purposes and who are subject to contractual confidentiality obligations.
Updates to This Policy
This Privacy Policy may be updated periodically to reflect changes in legal requirements or our data processing practices. Substantial changes will be communicated where appropriate. We recommend reviewing this policy periodically to stay informed of any changes.
Contact Information
If you have questions about this Privacy Policy or your personal data, or wish to exercise your rights under GDPR, please contact us through our in-store or online channels. We are committed to addressing your concerns in a timely and transparent manner.