Tolworth Florist Privacy Policy for Customers
  Introduction
This Privacy Policy explains how Tolworth Florist (“we”, “us”, “our”) collects, uses, protects, and retains personal data relating to customers placing orders from Tolworth and the surrounding districts. We are committed to protecting your privacy and handling your data in compliance with the General Data Protection Regulation (GDPR). This policy details your rights and how you can exercise them.
Scope of the Policy
This policy applies to all personal information obtained from customers placing an order with Tolworth Florist, whether through our in-store service, telephone ordering, or other direct means. It covers customers residing in Tolworth and neighbouring areas.
What Personal Data We Collect
When you interact with Tolworth Florist, we may collect and process the following categories of personal data:
- Contact Details: Name, delivery address, telephone number (if provided).
- Order Information: Details of purchased products (such as bouquets, arrangements), messages provided for cards, and delivery instructions.
- Payment Information: Payment method and transaction amount. Please note, we do not directly process or store credit/debit card numbers if you pay by card; this data is handled securely by our payment processor.
- Communications: Records of correspondence if you contact us about your order, give feedback, or make a complaint.
- Technical Information: If you use our website, we may collect technical data such as IP address, browser type and version, and device information, collected via cookies and similar technologies (for website analytics and site security).
Lawful Basis for Data Processing
Your personal data is processed on the following lawful bases as permitted by GDPR:
- Contractual Necessity: We require your name, address and order information in order to fulfill your order and deliver our products as per your request.
- Legal Obligations: We may process data as necessary to comply with applicable laws (e.g. tax regulations and business record-keeping obligations).
- Legitimate Interests: We may use your details to respond to your queries, ensure delivery quality, or enhance our customer service, provided your interests and rights do not override these purposes.
- Consent: We only use your personal data to send you marketing materials if you have explicitly opted-in. You can withdraw your consent any time.
How We Use Your Data
Your data is used for the following purposes:
- To process and deliver your floral orders
- To communicate with you regarding your order (including order confirmation, delivery updates, and queries)
- If you have provided consent, to send you promotional offers and updates
- To comply with legal requirements or resolve disputes
- To improve the performance and functionality of our services, including for internal analytics and security purposes
Data Retention Periods
Your personal data is retained only for as long as necessary to fulfill the purposes for which it was collected:
- Order Data: Kept for a maximum of seven years to comply with legal requirements for business and financial records.
- Correspondence: Retained for up to two years after your last communication, unless related to an ongoing service issue.
- Marketing Preferences: Kept until you withdraw your consent or request erasure, whichever is sooner.
- Technical Data: Retained according to our cookie and analytics policy (typically up to 26 months for website usage data).
At the end of these periods, your data will be securely deleted or anonymised.
Data Processors and Sharing Your Personal Data
We may engage trusted third-party service providers (“processors”) for activities that support our business, such as payment processing, IT hosting, and delivery partners. We require these processors to apply appropriate security measures and process your data only for specified purposes on our behalf. Personal data is not shared with third parties for their own marketing or commercial purposes.
Where required by law, your data may be shared with regulatory authorities or law enforcement agencies.
Your Rights Under GDPR
As a customer residing in Tolworth and surrounding districts, you have the following GDPR rights over your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete information.
- Right to Erasure: You may request deletion of your data in certain circumstances, such as when it is no longer needed for the purpose collected.
- Right to Restrict Processing: You can ask us to limit how we use your data in certain situations.
- Right to Data Portability: You can request a transfer of your personal data to another organisation where technically feasible.
- Right to Object: You may object to us processing your data based on legitimate interests or for direct marketing purposes at any time.
- Right to Withdraw Consent: Where we rely on your consent (for example, to send marketing communications), you can withdraw this consent at any time.
To exercise any of these rights, please contact us in-store or via the written channels provided at the point of order. We may need to verify your identity before responding to your request.
Data Security
We implement appropriate technical and organisational measures to safeguard your personal data against accidental loss, theft, or unauthorised access. This includes secure storage, restricting access to authorised staff, and ensuring our payment processors meet appropriate security standards.
Changes to This Privacy Policy
We may update this Privacy Policy as necessary to reflect changes in our practices, legal requirements, or operational needs. If significant changes occur, we will notify customers by displaying an updated notice in our shop or prior to accepting new orders.
Contact and Complaints
If you have any questions about this policy or believe your data has not been handled in accordance with GDPR, you can contact us in-store for more information or to raise a complaint. You also have the right to lodge a complaint with the UK Information Commissioner's Office if you are not satisfied with our response.