Bromley Common Florist GDPR Privacy Policy
Who We Are
Bromley Common Florist is dedicated to providing beautiful floral arrangements to residents and businesses within Bromley Common and neighboring districts. This Privacy Policy describes how we collect, use, share, and protect your data in compliance with the UK General Data Protection Regulation (GDPR) and applies to all individuals placing orders with us.
What Data We Collect
For the purpose of processing your order, communicating with you, and fulfilling our service commitments, the personal data that Bromley Common Florist may collect includes:
- Identity Information: Your name and, where provided, names of recipients.
- Contact Details: Address, delivery address (if different), and contact telephone number.
- Order Details: Information about your order, such as required products, messages included with your floral gift, and order value.
- Payment Data: Relevant payment information, excluding full payment card details which are handled securely by selected payment processors.
- Communications: Records of correspondence, enquiries, requests, and any feedback you provide to us.
- Technical Data: Through our website, anonymised data such as device type, operating system, browser type, and browsing actions, which help improve our online service (using cookies and analytics tools).
We do not collect or process special categories of sensitive personal data (e.g., health or ethnicity) without explicit consent.
Lawful Basis for Processing Your Data
Under the GDPR, we must have a valid lawful basis to process your data. Bromley Common Florist relies on the following lawful grounds:
- Contract: Processing your data is necessary to fulfil our contract with you (for example, to process and deliver your order or handle your requests).
- Legal Obligation: We may process personal information where required to comply with laws (e.g., for accounting and tax records).
- Legitimate Interests: To provide the best possible products and service, we process certain data for business improvement, fraud prevention, and direct marketing (where permitted by law and you have not opted out).
- Consent: In situations where we are not relying on the above conditions, we will seek your explicit consent, such as for marketing communications.
How We Use Your Data
We use your personal data for the following purposes:
- To process and deliver your order, including messaging recipients as requested
- To communicate with you about your order (confirmation, delivery, queries)
- For customer service and resolving any problems
- To keep proper business records and meet our legal obligations
- When permitted, to inform you about our products, offers, and updates
- To analyse how our website and services are used for improvements
Data Retention: How Long We Keep Your Data
Your personal information is retained only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically,:
- Order and transaction data: Retained for up to 7 years in line with accounting and tax purposes.
- Customer communications: Retained for up to 3 years after your last interaction.
- Marketing preferences: Retained until you withdraw your consent or opt-out.
When your data is no longer required, we securely delete or anonymise it in accordance with best practices.
Our Data Processors
Bromley Common Florist may use trusted third-party service providers (data processors) to help us run our business and deliver services to you. Examples include:
- Payment processors to securely handle transactions (we never store full card details ourselves)
- IT hosting companies for secure web and data storage
- Website developers and analytics providers, who may process anonymised or aggregate data
All data processors act strictly on our instructions, only process data as necessary, and are required to maintain confidentiality and security of your data as per our processor agreements and GDPR standards. We never sell your data to any third party.
International Data Transfers
Bromley Common Florist generally stores data within the UK or European Economic Area (EEA). If data may be processed outside these areas, we ensure adequate safeguards are in place to protect your rights and interests as required by GDPR.
Your Rights Under GDPR
You have important rights over your personal data held by Bromley Common Florist. These include:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: If the information we have is inaccurate or incomplete, you can request correction.
- Right to Erasure ("Right to be Forgotten"): In certain circumstances, you may ask us to delete your data.
- Right to Restrict Processing: You can request the restriction or suppression of your data in specific situations.
- Right to Data Portability: You may request a machine-readable copy of your data or for it to be transferred to another service provider.
- Right to Object: You can object to processing carried out for legitimate interests, including for direct marketing purposes.
- Right to Withdraw Consent: Where we are relying on consent, you may withdraw this at any time.
To exercise your rights, please contact us using the contact methods detailed on our website. We will respond to all requests in accordance with GDPR timeframes.
How We Keep Your Data Secure
Bromley Common Florist takes data security seriously. We use technical and organisational measures to protect your personal data, including:
- Secure storage and restricted access to personal data
- Secure payment processing using encrypted technologies
- Staff training and clear data security policies
- Regular review of our systems, processors, and procedures
Policy Scope and Updates
This Privacy Policy is applicable to all Bromley Common Florist customers placing orders from Bromley Common and surrounding districts. We reserve the right to update this policy as required to reflect changes in our practices or legal requirements. Please refer to this page for the most current information.
Questions or Concerns
If you have any queries regarding your personal data or wish to make a complaint, please contact us using the details provided on our website. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe your data protection rights have not been upheld.