This Privacy Policy explains how Florist Epsom ('we', 'us', 'our') collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Florist Epsom in Epsom and surrounding districts. Please read this policy to understand how your information is handled, your legal rights, and how you can exercise those rights.
Florist Epsom collects personal data when you interact with us, especially when you place an order for our products and services. The information we collect includes:
Under the GDPR, we are required to have a lawful basis for processing your personal data. Florist Epsom processes your data for the following reasons:
Your personal data is only used for the purposes specified above. Specifically, this includes processing your orders, arranging delivery, managing payments, and addressing your enquiries or complaints. We may analyze order and communication patterns to improve our business operations, but do not engage in profiling or automated decision-making regarding your personal data.
Florist Epsom will retain your personal data only as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Typically, we will retain order records, communications, and essential contact information for up to seven years in line with legal obligations. After this period, personal data is securely deleted or anonymised.
We may share your personal data with trusted third-party service providers (also known as data processors) who assist us in delivering our services. Examples of processors include:
All data processors engaged by Florist Epsom are contractually obliged to safeguard your personal data and act only under our instructions. We do not sell or share personal information with third parties for their marketing purposes.
Your data is processed and stored within the United Kingdom or the European Economic Area (EEA). If, in the future, your personal data needs to be transferred outside this area, we will ensure that appropriate safeguards are in place as required by GDPR.
You have clear rights regarding the processing of your personal data under the GDPR. These rights include:
If you would like to exercise these rights, please contact us directly. We will respond to your request in accordance with GDPR requirements.
Florist Epsom does not knowingly collect personal data from children under the age of 16 without parental consent. If we become aware that such information has been collected, we will take steps to remove it from our records.
We employ appropriate technical and organisational measures to safeguard your data against loss, theft, and unauthorised access. This includes secure payment processing, encryption where appropriate, staff training, and limited access measures. In the unlikely event of a data breach affecting your data, we will notify you and the relevant authorities as required by law.
We reserve the right to update or amend this privacy policy from time to time to align with changes in legal requirements or our business practices. The latest version will always be available on our website. We encourage you to review this policy periodically.
If you have questions about this Privacy Policy or your personal data, please use the contact details provided on our website. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your local data protection authority if you believe your rights under GDPR have been infringed.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
