Harringay Flowers GDPR Privacy Policy
Our Commitment to Your Privacy
At Harringay Flowers, we value the trust you place in us when ordering floral arrangements. This Privacy Policy outlines how we collect, use, store, and protect personal data received from customers who place orders for delivery in Harringay and surrounding districts. We are committed to handling your information lawfully, transparently, and securely in accordance with the General Data Protection Regulation (GDPR).
Scope of This Policy
This policy applies to all individual customers placing orders with Harringay Flowers, whether in-store, via telephone, or online, for deliveries in Harringay and the neighbouring areas. By placing an order, you acknowledge and agree to the terms set out in this Privacy Policy.
What Personal Data We Collect
We collect and process the following categories of personal data in connection with the delivery of our products and services:
- Identification Data: Name and, where necessary, proof of identity if collecting in-store
- Contact Data: Email address, contact phone number, and delivery address
- Order Information: Details of your order, instructions for delivery, and any other notes you provide
- Payment Data: Limited details necessary for processing your payment (such as payment method and transaction reference; sensitive card details are processed securely by our payment processor and never stored by us)
- Correspondence: Any feedback, queries, or communications directly related to your order
Lawful Basis for Processing
We process your personal data under one or more of the following lawful bases, as defined in Article 6 of the GDPR:
- Contractual Obligation: The data is required to fulfil our agreement with you, such as processing and delivering your order
- Legal Obligation: Certain records must be kept to comply with applicable laws, including financial and transactional records
- Legitimate Interests: To provide the best possible service, respond to your queries, and improve our business, provided these interests are not overridden by your rights and interests
- Consent: Where you specifically agree to receive marketing communications or promotional offers from us
How We Use Your Personal Data
Your data is used for the following purposes:
- To process, confirm, and deliver your flower order
- To communicate with you regarding your purchase or related queries
- To manage customer relationships, resolve issues, and improve our services
- To comply with legal and financial obligations
- Where applicable, to send promotional communications if you have opted in to receive marketing
Sharing and Processing of Your Data
We limit the sharing of your data to the minimum required for order fulfilment and compliance. Your data may be shared with:
- Payment Processors: Secure payment service providers handle your payments and transaction processing
- Delivery Partners: Couriers or delivery staff who require access to your name and address in order to deliver your order
- Technical Service Providers: Providers who enable the operation, hosting, and security of our website and order management systems
All third-party processors are contractually bound to safeguard your data and are not permitted to use it for purposes beyond fulfilling their obligations to us. We do not sell or rent your personal data to any external organisation.
How We Store and Protect Your Data
We implement appropriate technical and organisational measures designed to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include secure servers, encrypted payment gateways, and access restrictions for staff members who handle your data. Our processes are regularly reviewed to ensure ongoing compliance with GDPR obligations.
Data Retention: How Long We Keep Your Information
Your personal data is retained only for as long as necessary to fulfil the purposes described above. In particular:
- Order and Transaction Records: Kept for up to seven years to comply with applicable legal, tax, and accounting requirements
- Contact and Correspondence: Retained for up to two years to address any order-related queries or disputes
- Marketing Preferences: If you withdraw consent to marketing communications, we promptly update or delete your information as required
After the relevant periods, your data is securely deleted or anonymised to prevent further identification.
Your Rights Under GDPR
As a customer, you have specific rights with respect to your personal data under GDPR. These include:
- Access: The right to request and receive a copy of the personal data we hold about you
- Rectification: The right to have inaccurate or incomplete data corrected
- Erasure (“Right to be Forgotten”): The right to request deletion of your personal data under certain circumstances
- Restriction: The right to request a restriction on how your data is processed in specific cases
- Objection: The right to object to processing based on our legitimate interests or direct marketing
- Data Portability: The right to receive your personal data in a structured, commonly used, and machine-readable format and to request its transfer to another data controller
Requests in relation to your rights can be made at any time. We will respond to such requests within one calendar month, subject to any applicable legal exceptions.
International Data Transfers
All personal data is stored and processed within the UK or the European Economic Area (EEA). If any data processing takes place outside these areas, we ensure that relevant safeguards and protections are in place in accordance with GDPR requirements.
Policy Updates
We may review and update this Privacy Policy from time to time to reflect changes in law or our practices. The latest version will always be available to customers prior to order completion. We encourage you to review the policy whenever you place an order.
Contacting Us
If you have questions or concerns about how we handle your personal data or require any further information about your rights, please contact us using the details provided on our website or in-store. We are committed to protecting your privacy and addressing your concerns promptly.
