Florist Welling Privacy Policy Statement
  Florist Welling Customer Privacy Policy
This Privacy Policy outlines how Florist Welling collects, uses, stores, and protects personal data for all customers placing orders in Welling and surrounding districts. We are committed to ensuring your information is managed transparently, securely, and in compliance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and applicable UK data protection legislation.
Scope of This Policy
This Privacy Policy applies to customers, recipients, and individuals who interact with our services relating to ordering and delivery of flowers and related products from Florist Welling within Welling and nearby areas.
What Personal Data Do We Collect?
Depending on how you interact with us, Florist Welling may collect the following personal data:
  - Identifying Information: Full name, title, and contact details (including postal address and telephone number).
- Order and Delivery Information: Recipient’s name, address, and preferred delivery times.
- Payment Information: Transaction details (we do not store full payment card details, but payment processors may securely process these).
- Communication Records: Copies of correspondence, including queries, complaints, and order details.
- Marketing Preferences: Your consent to receive marketing messages where applicable.
- Technical Data: IP address, browser type, interaction with our website or ordering system (collected via cookies or similar technologies, where consented).
Lawful Basis for Processing Your Data
Under GDPR, we must have valid legal grounds to process your personal data. Florist Welling relies on the following bases:
  - Contractual Necessity: To fulfill your order and provide associated customer services.
- Legal Obligation: To meet any regulatory requirements or respond to requests from law enforcement where legally obliged.
- Legitimate Interests: For business purposes, including customer support, improving our services, and direct marketing (where you have not opted out), provided your rights do not override our interests.
- Consent: For electronic marketing communications and optional cookies. Where we rely on consent, you are free to withdraw it at any time.
How We Use Your Personal Data
We use the personal data we collect for the following purposes:
  - Processing, fulfilling, and delivering floral and related orders.
- Communicating with you regarding your order, enquiries, or customer support issues.
- Processing payments and preventing fraudulent transactions.
- Keeping records to meet legal, accounting, and regulatory requirements.
- Sending you marketing communications (if opted in).
- Improving our website, services, and customer experience.
Who Processes Your Personal Data?
For the fulfilment of our services, we sometimes share your data with trusted external parties (processors), only as necessary for service delivery:
  - Payment processing providers for secure order payment.
- Delivery couriers fulfilling your order (recipient details).
- IT and web hosting service providers.
- Professional service providers (e.g., accountants, auditors), under confidentiality agreements.
All processors adhere to GDPR requirements and are contractually obliged to maintain the security and confidentiality of your data. Florist Welling does not sell personal data to third parties.
Data Retention
We retain your personal data only as long as necessary to fulfill the purposes it was collected for, including legal, accounting, and regulatory requirements. Typically, the storage periods are as follows:
  - Order Records: Retained for up to seven years to satisfy tax and contractual obligations.
- Marketing Data: Retained until you withdraw your consent or object to processing.
- Technical Data: Retained for up to 26 months where not anonymised, or in line with your cookie consent preferences.
When data is no longer required, it is securely deleted or anonymised.
How We Protect Your Data
We implement a range of organisational and technical measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. These measures include access controls, secure storage, encryption technologies, and staff training on data protection responsibilities.
Your Data Protection Rights
Under the GDPR, you have a number of rights regarding your personal data:
  - Right to Access: Request details or copies of your personal data held by us.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data, subject to certain legal exceptions.
- Right to Restrict Processing: Ask us to suspend processing of your data in certain circumstances.
- Right to Object: Object to processing for direct marketing or where processing is based on our legitimate interests.
- Right to Data Portability: Request transfer of your data to another provider.
- Right to Withdraw Consent: Where you have given consent, the right to withdraw it at any time.
Florist Welling will respond to requests regarding your rights within one month. Proof of identity may be required for security reasons.
Children’s Privacy
Our services are not intended for persons under 16 years of age. We do not knowingly collect personal data from children.
Changes to This Policy
This Privacy Policy may be updated from time to time. Significant changes will be communicated appropriately. Please review this Policy periodically for updates.
Contact and Complaints
If you have questions about how your personal data is used or wish to exercise your rights, please contact us in writing via our official contact page or postal address. You also have the right to lodge a complaint with the UK’s Information Commissioner’s Office (ICO).