Belmont Flowers GDPR-Compliant Privacy Policy
Introduction
This Privacy Policy outlines how Belmont Flowers (“we”, “us”, or “our”) collects, manages, and safeguards the personal data of its customers in Belmont and the surrounding districts. This policy is designed to comply with the General Data Protection Regulation (GDPR) and is applicable to all persons placing orders with Belmont Flowers, whether online, by telephone, or in person. Your privacy and trust are paramount to us, and we are committed to protecting your personal information at every stage.
What Data We Collect
Belmont Flowers collects and processes various types of personal data to fulfill orders and provide customer service. The categories of personal data we may collect include:
- Contact Information: Name, billing address, delivery address, phone number.
- Order Details: Products ordered, delivery instructions, gift messages.
- Payment Information: Payment method, partial card information (as permitted), transaction records. We do not store full card details after payment is processed.
- Communication Records: Correspondence relating to orders, inquiries, complaints, or feedback.
- Technical Data: IP address, browser type, access times, and similar technical data when you interact with our website (if applicable).
We do not intentionally collect or process any special categories of personal data (such as information concerning health, ethnicity, or religious beliefs) in the normal course of providing our service.
Lawful Basis for Processing
Belmont Flowers only processes your personal data when there is a lawful basis to do so under GDPR. The primary lawful bases applicable are:
- Contractual Necessity: Processing is necessary to enter into or perform a contract — for example, to fulfill your floristry order, process payment, deliver goods, and communicate about your purchase.
- Legal Obligation: Processing when required to comply with our legal and regulatory obligations, such as retaining records for tax or accounting purposes.
- Legitimate Interests: Where we have a legitimate business interest, such as improving our services, preventing fraud, or responding to your queries. We always balance these interests with your fundamental rights and freedoms.
- Consent: For certain optional data uses, such as direct marketing communications, we rely on your explicit consent, which you may withdraw at any time.
How We Use Your Personal Data
We use your personal information for the following purposes:
- To process, confirm, and deliver your flower orders.
- To communicate order updates and respond to your inquiries or feedback.
- To handle refunds, returns, or complaints.
- To maintain proper business records and meet our legal obligations.
- To improve our products and customer experience.
- With your consent, to send marketing communications (which you can opt out of at any time).
Retention of Personal Data
We retain your personal data only for as long as necessary to meet the purposes outlined in this policy, including for legal, accounting, or reporting requirements. Generally, order and transaction data will be retained for up to seven years in accordance with financial regulations. Personal information used solely for marketing will be kept until you withdraw your consent or unsubscribe. After the applicable retention period, data will be securely deleted or anonymized.
Data Processors and Third Parties
To provide our services, we may engage third-party service providers (data processors) who process personal data on our behalf and under our instructions. These include:
- Payment processing services to enable secure transactions.
- Technical, hosting, and IT support providers maintaining our online ordering systems.
- Delivery services for order fulfillment.
- Providers of external customer support or communication tools.
We ensure all third parties only process your data as necessary for providing their specific services, and that they are bound by contractual obligations to safeguard your information in compliance with GDPR requirements. We do not sell, rent, or otherwise distribute your personal data to unaffiliated third parties for their marketing purposes.
Your Data Protection Rights
Under GDPR, you have various rights regarding your personal data. Subject to certain limitations and legal requirements, these include:
- Right to Access: You may request confirmation and a copy of the personal data we hold about you.
- Right to Rectification: You have the right to request correction of inaccurate or incomplete data.
- Right to Erasure: Also known as the ‘right to be forgotten’; you may ask us to delete your personal data in certain circumstances.
- Right to Restrict Processing: You can request limitations on how we process your data.
- Right to Data Portability: You may request your data in a structured, commonly used, and machine-readable format and have the right to transmit that data to another controller, where technically feasible.
- Right to Object: You can object to the processing of your data for certain purposes, such as direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw this at any time without affecting the lawfulness of processing prior to withdrawal.
If you wish to exercise any of these rights, please contact us using the contact details published on our website or in your order confirmation. We will respond to your request in accordance with applicable laws.
Security of Your Information
We employ appropriate organizational and technical measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. Access to your information is limited to those employees and processors who need it to fulfill your orders and responsibilities. All external processors handling your data are required to adhere to strict data protection standards.
Policy Updates
We reserve the right to update or amend this Privacy Policy to remain compliant with current data protection laws or to reflect changes in our business practices. Any updates will be published on our website and will be effective upon posting. We encourage you to review this policy periodically to remain informed about how we protect your privacy.
Applicability
This Privacy Policy applies to all customers placing orders with Belmont Flowers who reside in or are arranging deliveries to Belmont and the surrounding districts. By placing an order with us, you acknowledge and agree to this policy’s terms, as may be amended from time to time.
Further Information
If you have any questions or concerns about this Privacy Policy or how your personal data is handled, please refer to our website’s contact information. We are committed to working with you to resolve any privacy concerns promptly and transparently.
