Privacy Policy for Florist Isle of Dogs Orders
  Introduction
This Privacy Policy describes how Florist Isle of Dogs, serving customers in the Isle of Dogs and surrounding districts, collects, processes, and protects your personal information when you place an order with us. We are committed to safeguarding your privacy and ensuring your personal data is handled in accordance with the UK General Data Protection Regulation (GDPR).
Scope of This Policy
This policy applies to all customers who place orders with Florist Isle of Dogs from the Isle of Dogs and adjacent areas. By placing an order or engaging with our services, you acknowledge and agree to the terms outlined in this Privacy Policy.
What Data We Collect
To fulfill your orders and provide our services, we may collect and process the following categories of personal data:
  - Contact Information: Such as your name, delivery address, billing address, phone number, and (where provided) other relevant contact details.
 
  - Order Details: Information about products or arrangements you order, requested delivery dates and times, and recipient details (name and delivery address).
 
  - Payment Information: Details necessary to process payments, such as payment card information provided through secure payment processors. (Note: We do not store your full payment card details.)
 
  - Communications: Records of your communications with us, including inquiries, feedback, and order updates.
 
  - Website Usage Data: Technical information such as IP addresses, browser types, and browsing activity if you use our website to place orders or make inquiries.
 
Lawful Basis for Processing
We process your personal data only where there is a lawful basis under GDPR. These may include:
  - Contract Performance: To process and deliver orders, and to fulfil our contractual obligations to you as our customer.
 
  - Legitimate Interests: To improve our services, communicate with you regarding your order or account, or to protect our business from fraud or misuse, provided such interests are not overridden by your rights.
 
  - Legal Obligations: To comply with UK laws, such as recordkeeping or responding to legal requests.
 
  - Consent: Where required, such as for direct marketing communications, we will seek your explicit consent, and you have the right to withdraw this at any time.
 
How We Use Your Data
Your personal data may be used for the following purposes:
  - Processing and delivering your flower orders.
 
  - Communicating with you regarding your order status, delivery, or any changes.
 
  - Providing customer support and handling complaints or feedback.
 
  - Maintaining business records and managing accounts.
 
  - Improving and personalising our services based on customer preferences and usage patterns.
 
  - Meeting legal and regulatory obligations.
 
  - With your consent, sending occasional marketing communications (you may opt out at any time).
 
Data Retention
We retain personal data only for as long as is necessary to fulfill the purposes set out in this policy and to meet our legal and business obligations. Once data is no longer required, we securely delete or anonymise it. In general:
  - Order and account information may be retained for up to six years for accounting and tax purposes.
 
  - Communication records are typically retained for up to two years from the date of your last interaction with us.
 
  - Where consent is withdrawn, data that is no longer required will be deleted or anonymised as soon as practical.
 
Processors and Data Sharing
We may engage carefully selected third-party processors to support our operations, such as:
  - Payment Processors: To securely handle card or online payments (only the necessary payment details are shared; we do not store full card details).
 
  - Delivery Providers: To fulfill and deliver your orders, recipient names and addresses may be shared as necessary.
 
  - IT and Cloud Service Providers: For secure data storage and support of our business operations.
 
All processors operate in accordance with GDPR requirements and may process your personal data only on our instructions, subject to appropriate confidentiality and security obligations.
We do not sell your personal data to third parties. Data is only shared with other parties where required by law or if necessary for the establishment, exercise, or defence of legal claims.
User Rights
Under GDPR, you have the following rights regarding your personal data:
  - Right to Access: You can request access to your personal data and receive information about how it is processed.
 
  - Right to Rectification: You can ask us to correct inaccurate or incomplete personal data we hold about you.
 
  - Right to Erasure: You may request deletion of your personal data where there is no compelling reason for us to continue processing it.
 
  - Right to Restrict Processing: You have the right to request that we limit the processing of your personal data under certain circumstances.
 
  - Right to Data Portability: You can request the transfer of your data to another organisation, where applicable.
 
  - Right to Object: You may object to our processing of your personal data where such processing is based on legitimate interests or is used for direct marketing.
 
  - Right to Withdraw Consent: If processing is based on your consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
 
If you wish to exercise any of these rights, please contact us using the details provided on our website or by post. We will respond to your requests as required by GDPR.
Data Security
We implement appropriate organisational and technical measures to protect personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption, access controls, and secure storage of records.
Policy Updates
We may update this Privacy Policy to reflect changes in legal or regulatory requirements, our data processing practices, or service offerings. The most recent version will always be available on our website. Customers will be notified of any material changes where appropriate.
Contact and Complaints
If you have any questions about this policy, how we process your personal data, or if you would like to make a complaint, please reach out to us using the contact details on our website. If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.