Cricklewood Flowers Privacy Policy
Introduction
This Privacy Policy applies to all customers who place orders with Cricklewood Flowers, whether residing in Cricklewood or the surrounding districts. At Cricklewood Flowers, we are committed to protecting your privacy and ensuring that your personal data is handled securely and in accordance with the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018, and any other relevant data protection laws. This policy sets out how we collect, use, store, and share your personal information. It also explains your rights concerned with your data.
What Data We Collect
To fulfill your orders and provide high-quality customer service, we may collect and process the following categories of personal information:
- Contact details: Such as your name, address for delivery, telephone number, and, if you provide it, your email address.
- Order information: Details regarding your floral order, recipient address, delivery instructions, messages to accompany flowers, and payment information (though we do not store complete payment card details, only transaction references).
- Correspondence: Information arising from any queries, complaints, or feedback you communicate to us via phone or in person.
- Technical Data: Limited data such as IP address, browser type, and visit times may be collected if you use our website for order placement or browsing, primarily for security and analytics purposes.
Lawful Basis for Processing Your Data
Under the GDPR, we must have a lawful basis to process your personal information. The key lawful bases we rely on are:
- Contractual Necessity: We process your data to fulfill our contract with you, i.e., to register, process, and deliver your order and to handle associated customer service requirements.
- Legal Obligation: We may retain data for accounting and tax purposes or to respond to law enforcement requests, where legally required.
- Legitimate Interests: To improve services, maintain security, prevent fraud, and conduct basic analytics, provided these interests do not override your rights.
- Consent: If we wish to send you marketing communications, we will only do so after obtaining your explicit consent. You can withdraw consent at any time.
How We Use Your Personal Information
Your data is used for the following purposes:
- Processing, confirming, and delivering your floral orders.
- Communicating with you about your order status, delivery, or any queries you may have.
- Managing payment transactions and preventing fraud.
- Complying with legal and tax obligations.
- Improving our services and understanding customer needs (where permitted).
- Sending service updates and, only with your permission, marketing communications.
How We Share and Store Your Data
We will never sell your personal information. We may need to share your information in the following circumstances:
- Service Providers (Processors): We may use carefully selected third-party providers (such as payment processors, IT support, or delivery management services) to assist in running our operations, with appropriate data protection safeguards in place. These processors only act on our instructions and are contractually bound to protect your information.
- Legal and Regulatory Requirements: We may be required to disclose information to authorities if mandated by law or to protect our legal rights.
Your data is securely stored within the UK or European Economic Area (EEA) and is protected by appropriate technical and organisational measures against unauthorised access or loss.
How Long We Retain Your Data
We keep your personal data only for as long as is necessary for the purpose for which it was collected:
- Order records, including delivery details, are retained typically for up to 6 years to fulfill contractual, accounting, and legal requirements.
- Correspondence and feedback may be stored for up to 2 years for quality monitoring and to resolve any ongoing issues.
- If you have consented to marketing, we retain your contact details until you opt-out or withdraw consent.
- Payment card details are never stored. Only secure transaction references are kept, as required by our payment processor’s compliance standards.
>
When data is no longer required, it is securely deleted or anonymised.
Your Data Protection Rights
Under the GDPR, you have rights regarding your personal information:
- Access: You have the right to request a copy of the personal data we hold about you.
- Correction: You may ask us to correct any incomplete or inaccurate information.
- Erasure: You can request deletion of your data under certain circumstances (for example, if it is no longer necessary for us to retain it).
- Restriction: You may ask us to restrict processing in certain situations.
- Object: You may object to processing where we rely on legitimate interests.
- Portability: You have the right to request your data in a commonly used, machine-readable format, where applicable.
- Withdraw consent: Where we rely on your consent (e.g., for marketing), you have the right to withdraw this at any time.
To exercise any of these rights, please contact us in store or via your preferred contact method. You are also entitled to raise concerns with the Information Commissioner’s Office (ICO), the UK’s supervisory authority for data protection.
Updates to This Privacy Policy
We may occasionally update this Privacy Policy to reflect changes in our processes, legal requirements, or for other operational reasons. Any updates will be posted in-store and on our website, clearly stating the date of the latest revision.
Contact and Additional Information
If you have any questions about how your data is handled or wish to exercise your rights, please contact a member of our team in-store or use your usual method of contacting Cricklewood Flowers. We are committed to responding promptly and assisting you with any privacy concerns.