Flowers Lisson Grove GDPR Privacy Policy
  Introduction
This Privacy Policy explains how Flowers Lisson Grove collects, uses, shares, and protects your personal data when you place orders with us from Lisson Grove and the surrounding districts. We are committed to safeguarding your privacy and complying with the EU General Data Protection Regulation (GDPR), as well as all relevant data protection laws. This document outlines the types of data we collect, the legal basis for processing, data retention periods, third-party processors, and your rights over your data.
Scope of this Policy
This Privacy Policy applies to all individuals ("customers" or "you") who place orders with Flowers Lisson Grove, whether via our website, by telephone, or in person within Lisson Grove and surrounding districts. By making an order, you acknowledge the practices described in this policy.
Personal Data We Collect
We may collect and process the following information when you interact with us or make a purchase:
  - Identity Data: Your name, recipient’s name, and, where applicable, names of persons receiving deliveries.
 
  - Contact Data: Delivery address, phone numbers, and, where necessary, billing address.
 
  - Order Data: Details of purchases (such as floral arrangement selected, order comments, delivery notes), and transaction history.
 
  - Payment Data: Limited payment information (such as payment method), as processed through our secure payment processors. Actual card or bank account details are not stored by us.
 
  - Correspondence: Any information provided by you in communications with us (for example, enquiries, feedback, or complaints).
 
  - Technical Data: When you use our website, we may collect technical data such as browser type, device identifier, IP address, and website usage details through the use of cookies or similar technologies.
 
Lawful Basis for Processing
Under GDPR, we must have a lawful reason to process your personal data. Our legal bases include:
  - Contract Performance: Most data processing is necessary for us to fulfil your order or take steps at your request before arranging a purchase.
 
  - Legal Obligations: To comply with applicable laws regarding record keeping, tax, and consumer protection.
 
  - Legitimate Interests: For day-to-day business operations, such as improving our services, preventing fraud, ensuring network security, and managing correspondence, provided your interests and fundamental rights do not override those interests.
 
  - Consent: Where required by law, for marketing purposes or optional communications, we will request your explicit consent, which you may withdraw at any time.
 
How We Use Your Personal Data
Your personal information is used strictly for the following purposes:
  - Processing and delivering your orders, including contacting you about your order status or delivery requirements.
 
  - Processing payments via secure third-party payment providers.
 
  - Responding to your enquiries, requests, or feedback.
 
  - Maintaining accurate business and financial records.
 
  - Improving our services, analysing purchase patterns, and enhancing customer support.
 
  - Complying with legal and regulatory obligations.
 
  - With your consent, sending you occasional service-related updates or marketing communications (which you may opt out of at any time).
 
Third-Party Data Processors
We may share your data with selected third-party service providers (“processors”) necessary for our operations. These may include:
  - External payment service providers who securely manage transaction processing.
 
  - Trusted delivery partners or couriers for completing your delivery requests.
 
  - Providers of website hosting, IT support, and analytics services (who may process technical or usage data).
 
  - Professional advisors (such as accountants or legal consultants) where necessary for compliance or business administration.
 
All third-party processors are bound by contractual obligations under GDPR to handle your data securely and only as instructed by us, never for their own purposes.
International Data Transfers
Your personal data is generally processed within the United Kingdom or the European Economic Area (EEA). Where it is necessary to transfer data outside these areas, we ensure appropriate safeguards as required by the GDPR are in place, such as standard contractual clauses or adequacy decisions.
Data Retention
We retain your personal data only as long as necessary for the purposes for which it was collected, including for fulfilling any legal, accounting, or reporting requirements. Typical retention periods are:
  - Order and Delivery Records: Retained for up to 7 years as required for financial and tax purposes.
 
  - Customer Correspondence: Retained for as long as needed to resolve your enquiry and for up to 2 years for service improvement.
 
  - Technical and Analytics Data: Retained in line with our cookie and analytics policies, generally not exceeding 26 months.
 
After these periods, your data is securely deleted or anonymised.
Your Rights Under GDPR
You have a number of important rights in relation to your personal data:
  - Access: Request a copy of the personal data we hold about you.
 
  - Rectification: Request corrections to any inaccurate or incomplete data.
 
  - Erasure: Request deletion of data where there is no longer a valid reason for processing.
 
  - Restriction: Ask us to limit or suspend processing of your data.
 
  - Objection: Object to processing where we rely on legitimate interests or direct marketing.
 
  - Portability: Request transfer of your personal data to you or a third party.
 
  - Withdraw consent: Where you have given us your consent to process data, you can withdraw it at any time.
 
  - Lodge a complaint: You may file a complaint with the relevant supervisory authority if you have concerns about our data processing.
 
If you wish to exercise any of these rights, please contact us via the means provided on our website or in-store. We may require identification to verify your request.
Data Security
We take data security seriously and employ appropriate technical and organisational measures to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Third-party service providers are required to comply with similar security standards.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes to our practices or applicable law. The latest version will always be available at our store and on our website. We encourage customers to review this policy periodically.
Contact Us
If you have questions about this policy or how your personal data is handled, please reach out to us using the contact details provided on our website or visit our shop in Lisson Grove. Our staff will be happy to assist you regarding any privacy concerns.