Florist Castelnau Privacy Policy
Introduction
This Privacy Policy describes how Florist Castelnau ("we", "us", or "our") processes your personal data when you place an order with us. This policy is in accordance with the General Data Protection Regulation (GDPR) and applies to all customers placing orders from Castelnau and its surrounding districts.
What Personal Data We Collect
When you interact with Florist Castelnau, either online, by phone, or in person, we may collect and process the following types of personal data:
- Identification Data: Your full name, recipient name, and, if applicable, company name.
- Contact Data: Address, email address, and telephone number of yourself and the recipient.
- Order Details: Products you order, delivery instructions, card messages, and purchase history.
- Payment Information: Payment card details (processed securely via our payment processors and not stored by us), billing address, and transaction data.
- Technical Data (if ordering online): IP address, browser type, device identifiers, and cookies necessary for website functionality.
- Correspondence: Any communications you send to us, including feedback or queries.
The Lawful Basis for Processing Your Data
Under the GDPR, we must have a lawful basis to process your personal data. The bases we rely on include:
- Contract: Processing your data is necessary to fulfill our contract with you, such as handling your order, processing payments, or delivering flowers.
- Legal Obligation: We may need to process your information to comply with legal requirements, such as accounting or tax obligations.
- Legitimate Interests: We may process your data to manage and improve our services, prevent fraud, or respond to your enquiries. Our legitimate interests will never override your fundamental rights and freedoms.
- Consent: In certain cases where we are not able to rely on another lawful basis, we will ask for your explicit consent to process your data (e.g., for marketing purposes). You can withdraw consent at any time.
How We Use Your Data
Your data is used for purposes including:
- Processing and fulfilling your order, including delivery and customer service
- Maintaining records for accounting or legal requirements
- Communicating with you regarding orders, queries, or service updates
- Improving our services and understanding customer preferences
- Sending marketing information, if you have opted in
How Long We Keep Your Data (Data Retention)
We retain your personal data only as long as necessary for the purposes described in this policy, including fulfilling your orders, complying with legal obligations, or resolving disputes. Typically, order and accounting records are retained for up to 7 years in line with local legal requirements. After this period, your data will be securely deleted or anonymized so that it can no longer be identified.
Our Use of Processors and Third Parties
In order to deliver our services, we may share your personal data with trusted third parties, including:
- Payment Service Providers: To process and verify your transactions securely. We do not store your full card details.
- Delivery Partners: To deliver your flowers or gifts as instructed by your order.
- IT and Website Support Partners: For hosting, maintaining, and securing our website and communications.
- Professional Advisors: Such as accountants or legal advisers, where necessary.
All third-party processors are contractually obliged to safeguard your data and may only use it for the purposes set out by Florist Castelnau. We do not sell or rent your personal data to third parties.
Your Rights Under GDPR
The GDPR provides you with certain rights regarding your personal data. As a customer of Florist Castelnau, you have the right to:
- Access: Request confirmation as to whether we process your personal data and, if so, to obtain a copy of it.
- Rectification: Request correction of any inaccurate or incomplete personal data.
- Erasure: Request deletion of your personal data under certain conditions, for example, when the data is no longer necessary for the purposes for which it was collected.
- Restriction: Request restriction of processing in specific cases (e.g., if you contest the accuracy of the data).
- Data Portability: Where applicable, request a copy of your data in a commonly used format to transfer to another provider.
- Object: Object to processing of your data on grounds relating to your particular situation, in cases where we rely on legitimate interests.
- Withdraw Consent: Where we process data based on your consent, you can withdraw that consent at any time.
To exercise your rights, please contact Florist Castelnau using the details provided on our website or in your order confirmation.
Data Security
Florist Castelnau takes the security of your personal data seriously. We employ technical and organisational measures to protect your data from loss, misuse, unauthorized access, disclosure, or alteration. These measures include secure servers, encryption of sensitive information, and staff training in data protection. While we strive to keep your data safe, no transmission over the internet or electronic storage is totally secure and you provide your data at your own risk.
International Data Transfers
Your personal data is generally processed within the United Kingdom and European Economic Area (EEA). If we need to transfer your data outside this area, we will ensure it is protected by appropriate safeguards as required by law.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices, legal requirements, or for other operational reasons. The latest version will always be available on our website. Please review it regularly to stay informed.
Contacting Florist Castelnau
If you have any questions about this Privacy Policy, how your data is handled, or wish to exercise your rights, please contact us using the details available on our website or found in your order confirmation. We are committed to ensuring your privacy and addressing your concerns promptly.