Paddington Florist Privacy Policy
  Our Commitment to Your Privacy
At Paddington Florist, we understand that your privacy and the security of your personal information are extremely important. This Privacy Policy explains how we collect, use, store, and protect your personal data in accordance with the General Data Protection Regulation (GDPR). By placing an order with Paddington Florist from Paddington and the surrounding districts, you agree to the terms described in this policy.
Scope of This Policy
This Privacy Policy applies to all customers purchasing goods or services from Paddington Florist, whether through our website, over the phone, or in-person, within Paddington and the surrounding districts.
What Personal Data We Collect
We collect and process the following categories of personal data:
- Identification Information: Your name and, if you provide it, the recipient's name for floral deliveries.
- Contact Details: Address, email address, and telephone number for order processing and delivery purposes.
- Order Information: Details about your purchase, delivery instructions, payment method (note: we do not store full card details), and order history.
- Marketing Preferences: Your preferences regarding promotional communications, if you choose to receive these.
- Technical Data: Internet protocol (IP) address, browser type and version, time zone setting, operating system and platform, and other technology on the devices you use to access our website.
Lawful Bases for Processing Your Data
Paddington Florist only collects and processes your data under the following legal grounds permitted by the GDPR:
- Contractual necessity: We process your personal data to fulfil and deliver your order. Without this information, we cannot process your purchase.
- Legitimate interests: For the improvement of our services, customer queries, and resolving disputes, provided our interests do not override your fundamental rights.
- Legal obligation: On occasion, we may be legally required to process your data, for example, for tax records.
- Consent: For optional marketing communications, we only collect and use your data with your explicit consent. You may withdraw consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing your orders and delivering your flowers or gifts.
- Communicating with you about your order status, questions, or follow-ups.
- Responding to your customer service queries and requests.
- Improving our website, products, and services through anonymised analysis.
- Complying with legal and regulatory obligations.
- Sending you marketing communications, if you have given permission.
Retention of Your Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for satisfying any legal, accounting, or reporting requirements. In summary:
- Order Records: We retain order-related data for up to six years, in line with tax and accounting laws.
- Marketing Data: If you opt in to receive marketing communications, we keep this data until you unsubscribe or withdraw your consent.
- Technical Data: Browsing and analytical data are retained for up to two years.
Once data is no longer needed, it will be securely deleted or anonymised.
Processors and Data Sharing
Paddington Florist only shares your personal data with trusted third-party service providers (“processors”) when this is necessary to process and deliver your order, or as required by law. These processors may include:
- Payment service providers who process your payment securely
- IT and system administration providers who support our website and operations
- Delivery partners responsible for delivering your flowers or gifts
- Professional advisors including accountants, auditors, and legal advisors, where necessary
Our contracts with each processor require them to respect the security of your data and to treat it according to the law. We do not allow our third-party service providers to use your personal data for their own purposes and only permit them to process your data for specific purposes and in accordance with our instructions.
Data Security
We take the security of your personal information very seriously and have implemented appropriate physical, electronic, and managerial procedures to safeguard and secure the information we collect. Access to your personal data is restricted to those employees, agents, and third-party processors who need it for processing your order or supporting our business operations.
Your Rights Under GDPR
Under the GDPR, you have several important rights in relation to your personal data. These include:
- The Right to Access: You can request a copy of your personal information we hold.
- The Right to Rectification: You can request correction of any inaccurate or incomplete data.
- The Right to Erasure: You can ask to have your data deleted where there is no good reason for us to continue holding it.
- The Right to Restrict Processing: You can object to certain uses of your personal data or request us to limit its use.
- The Right to Data Portability: You can ask to receive your personal data in a commonly used, machine-readable format.
- The Right to Object: You may object to processing based on legitimate interests or direct marketing.
- The Right to Withdraw Consent: Where you have given consent to processing, you may withdraw it at any time.
- Right to lodge a complaint: You have the right to lodge a complaint with the data protection authority if you feel your rights have been infringed.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business or legal requirements. Any changes will be posted on our website and we encourage you to review this page regularly to stay informed.
Contacting Paddington Florist
If you have any questions or concerns about this Privacy Policy or your personal data, please contact us using the details provided on our website. We are committed to resolving any issues promptly and transparently.