Waterloo Florist – Privacy Policy
Introduction to Our Privacy Policy
Waterloo Florist is committed to ensuring the privacy and protection of your personal data. This Privacy Policy outlines how we collect, use, store, and safeguard your information in accordance with the General Data Protection Regulation (GDPR). The policy applies to all individuals placing orders with Waterloo Florist from Waterloo and the surrounding districts.
Scope of the Policy
This Privacy Policy is relevant to all customers, whether ordering online, by phone, or in store, and applies to any use of our services for flower orders and associated products from Waterloo Florist in Waterloo and its surrounding districts. By placing an order or interacting with our services, you agree to the terms described in this policy.
What Data We Collect
We only collect information necessary to process your order, communicate with you, and enhance your customer experience. The types of personal data we may collect include:
- Identity Data: Your first and last name.
- Contact Data: Delivery address, billing address, phone numbers, and (if provided during the order process) email address.
- Order Data: Details of purchased items, order date, order value, delivery instructions, and card messages (if applicable).
- Payment Data: Payment method and confirmation – we do not store complete payment card details but rely on third-party processors for secure transactions.
- Correspondence: Records of enquiries, complaints, requests, or communications you send to us.
- Technical Data: When you use our website, we collect your IP address, browser type, device information, and usage patterns through cookies strictly necessary for site functionality and security.
Lawful Bases for Processing Your Data
We process your personal data only when allowed by GDPR, which means we rely on one or more of the following lawful bases:
- Contractual Necessity: Processing data as required to fulfill your order, such as processing payments and delivering your flowers.
- Legal Obligations: Complying with tax, accounting, and other binding regulations.
- Legitimate Interests: Using your data for reasonable business purposes, like improving services, fraud prevention, or communicating necessary information. We balance these interests with your rights and freedoms.
- Consent: Where applicable, we obtain your active consent before sending promotional communications. You may withdraw your consent at any time.
How We Use Your Data
Your personal data will not be sold or made available for marketing by third parties. We use your data to:
- Process and fulfill your orders, including contacting you for delivery information if needed.
- Respond to your enquiries and provide customer support.
- Comply with legal and financial record-keeping requirements.
- Improve our products, website, and customer experience.
- Send you updates on your order and (if you have opted in) occasional promotional offers.
- Ensure security and integrity of our systems.
Data Retention
We retain your personal information only as long as is reasonably necessary for the purposes set out above:
- Order, payment, and invoicing data – typically for up to 7 years, to comply with legal requirements.
- Contact and delivery information – retained as long as needed to fulfill your order and resolve any related issues.
- Promotional communications – until you withdraw consent or unsubscribe.
- Technical logs – typically retained for a short period for security monitoring.
After the relevant periods, your data is either securely deleted or anonymized.
Our Data Processors and Third Parties
To provide our services, we engage trusted third-party processors, each of whom is contractually bound to process your data only as directed by us and in compliance with GDPR. These include:
- Payment service providers for secure card processing.
- IT service providers hosting our website and customer databases.
- Delivery partners who may receive only the information required for successful delivery of your order.
- Professional advisers (for instance, accountants or legal consultants) as required by law.
We do not transfer your data outside the European Economic Area except where necessary with adequate protections in place.
Your Data Protection Rights
Under GDPR, you have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Request correction of any inaccurate or incomplete data.
- Erasure: Request deletion of your data when it is no longer required, except where we must keep it for legal reasons.
- Restriction: Request us to limit the processing of your data in certain circumstances.
- Objection: Object to processing where we rely on legitimate interests, including for direct marketing.
- Portability: Receive your personal data in a structured, commonly used digital format, and have the right to request transmission to another data controller.
- Withdraw Consent: Where we process your data based on consent (such as promotional emails), you may withdraw it at any time.
If you wish to exercise any of these rights or have concerns about your data, please contact us through the contact methods provided on our website or in our store. You also have the right to lodge a complaint with your local data protection authority if you believe your rights are infringed.
How We Protect Your Information
We take data security seriously. Your personal information is stored on secure servers, protected by up-to-date firewalls and encryption measures. Access to customer data is strictly controlled and limited to essential personnel and trusted partners. When handling online payments, we use reputable payment processors implementing industry-standard security (such as PCI DSS compliance).
Changes to this Policy
We may update this Privacy Policy occasionally to reflect changes in legal obligations or business practices. We encourage you to review this document regularly. Where significant changes are made, we will notify customers in advance where possible.
Contact Us
If you have questions, requests, or concerns about your personal information or this privacy policy, please use the contact details provided at our store or on our official website.