Westcombe Park Florist Privacy Policy
  Introduction
This Privacy Policy explains how Westcombe Park Florist ("we", "our", or "us") collects, uses, stores, and protects your personal data when you place an order with us. Our commitment is to respect your privacy and to comply with the General Data Protection Regulation (GDPR) and relevant UK data protection laws. This policy applies to all customers placing orders with Westcombe Park Florist, including those from Westcombe Park and the surrounding districts.
What Personal Data We Collect
When you interact with Westcombe Park Florist, we may collect the following categories of personal information:
  - Identity Data: Includes your full name and, if required, identification information for order verification.
- Contact Data: Includes your billing address, delivery address, and contact numbers.
- Order Information: Details about your floral orders, such as delivery instructions, recipient names and addresses, card messages, and order history.
- Payment Information: Payment card details or bank transfer data (note: these are typically processed securely by selected third-party payment processors and not retained by us).
- Communications: Records of correspondence with us, including order confirmations, queries, feedback, or complaints.
- Technical Data: Information collected through our website, such as IP addresses, browser types, and device identifiers, which help us improve our services.
Lawful Basis for Processing Your Data
We only process your personal data where there is a legal basis under GDPR. Depending on the context, this will typically include:
  - Contractual Necessity: Most of the data we collect is required to fulfill our contract with you, such as processing and delivering your order or providing customer support.
- Legal Obligations: We are required by law to retain certain information, particularly for tax and accounting purposes.
- Legitimate Interests: To improve our services, manage our relationship with you, respond to your enquiries, or send existing customers information about similar products you may be interested in. We always balance our legitimate interests against your rights and freedoms.
- Consent: Where we seek your explicit agreement (for example, to send you email newsletters or marketing not related to a previous purchase), processing will rely on your freely given consent, which you may withdraw at any time.
How We Use Your Personal Data
Your personal data is used solely for the following purposes:
  - Processing, confirming, and delivering floral orders.
- Contacting you regarding your orders, deliveries, or changes to our service.
- Responding to your enquiries or complaints promptly and effectively.
- Maintaining accurate records for our business operations, legal compliance, and customer care.
- Customising and enhancing your experience with Westcombe Park Florist online.
- Informing you of relevant offers or updates, where permitted by law.
Personal Data Retention
We retain your personal data only as long as is necessary for the original purpose for which it was collected, and in line with legal requirements:
  - Order and transactional information, including invoices, may be kept for up to seven years to comply with tax and accounting obligations.
- Customer communication records are retained for up to two years from the date of your last order, unless there is an ongoing dispute or you request earlier deletion.
- Marketing consents and opt-outs are recorded for as long as you remain a customer or until you withdraw consent.
- Website technical data is retained for up to one year for analytic and security purposes.
At the end of the retention period, your data will be securely deleted or anonymised.
Data Processors and Third Parties
We may use carefully selected third parties "processors" to support our service, including:
  - IT and website hosting providers: For managing our website and customer records.
- Payment processors: To facilitate secure payment transactions. We never store your full card details internally.
- Delivery partners: To ensure your flowers reach their destination. Only the necessary delivery details are shared.
- Professional service providers: Such as accountants and legal advisors, for necessary business functions.
All processors are required to handle your data in accordance with GDPR. We do not sell or rent your personal information to third parties for marketing purposes. Data may be disclosed if required by law, such as to government authorities or law enforcement, with suitable legal safeguards.
International Data Transfers
Generally, we store and process your data within the United Kingdom or the European Economic Area (EEA). If, on rare occasions, we need to transfer your data outside the UK/EEA (for example, if a service provider is based elsewhere), we ensure that adequate safeguards are in place, including standard contractual clauses approved under GDPR.
Your Data Protection Rights
Under GDPR, you are entitled to the following rights regarding your personal data:
  - Right to be informed: To know how your data is collected and used, as outlined in this policy.
- Right of access: To request a copy of your personal data held by us.
- Right to rectification: To have inaccurate or incomplete data corrected.
- Right to erasure: To request deletion of your data, where legally permitted.
- Right to restrict processing: To ask us to pause or limit the processing of your information.
- Right to data portability: To receive a copy of your data in a structured, common format.
- Right to object: To object to certain uses of your data, including direct marketing.
- Rights regarding automated decision-making and profiling: Westcombe Park Florist does not conduct automated decision-making with legal effects on individuals.
To exercise these rights, simply contact us using the methods provided on our website or in store. We are committed to addressing all valid requests and will respond within one month, as mandated by law.
Security Measures
We take appropriate steps to protect your data from loss, misuse, or unauthorized access. This includes the use of secure servers, encrypted payment processes, restricted access to personal information, and regular reviews of our information security practices. While we strive to protect your personal data, no method of data transmission over the internet can be guaranteed as fully secure.
Policy Updates
We may amend this Privacy Policy from time to time to reflect updated legal requirements or changes in our services. The latest version will always be available via our website or in-store. We encourage you to review it regularly, especially when you use our services.
Contact and Complaints
If you have any questions about how we use your personal data or wish to exercise your rights, please contact us via the methods shown on our website or at our shop premises. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) in the UK if you are dissatisfied with our handling of your data, but we ask that you contact us first so we can try to resolve your concerns promptly and fairly.
Thank you for trusting Westcombe Park Florist with your personal data. We are dedicated to handling your information with care, transparency, and in full accordance with GDPR.