Islington Flowers Privacy Policy
  Introduction
This Privacy Policy explains how Islington Flowers ("we", "us", "our") collects, uses, processes, and protects your personal data in accordance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Islington Flowers in Islington and surrounding districts.
Personal Data We Collect
To provide our floral delivery and related services, we collect various types of personal data from our customers. The types of data we may collect include:
  - Contact Information: Name, address, telephone number, and delivery address of both sender and recipient.
 
  - Identification Data: Occasion details (e.g., birthdays, anniversaries), card message contents, and order notes.
 
  - Transaction Information: Order history, payment method details (note: we do not store full payment card numbers), and billing information.
 
  - Technical Information: IP address, device type, browser used, and usage data collected through our website cookies and analytics tools.
 
We collect your data when you place an order with us, interact with our website, communicate with us directly, or subscribe to our marketing communications.
Lawful Basis for Processing Personal Data
Under GDPR, we must have a valid lawful basis to process your personal data. Islington Flowers relies on the following bases:
  - Contractual Necessity: We process your personal data when it is necessary to fulfill our contract with you, such as processing payments and delivering your floral orders.
 
  - Legal Obligations: We may process data to comply with our legal and regulatory obligations, such as tax and accounting regulations.
 
  - Legitimate Interests: We process data to improve our services, manage customer relations, and for the security and operation of our website, provided these activities do not override your privacy rights.
 
  - Consent: Where you have provided clear consent, for example, when signing up to receive marketing emails or offers.
 
How We Use Your Personal Data
Your personal information is used in the following ways:
  - To process and fulfill your floral orders, including delivery to recipients.
 
  - To communicate with you regarding your order, delivery details, or any queries.
 
  - To enhance our website’s user experience and develop new products and services.
 
  - To improve our customer service and manage complaints or disputes.
 
  - Where consent is given, to send you marketing communications about our products, services, and promotions. You may withdraw this consent at any time.
 
Data Retention
We retain your personal data for no longer than is necessary for the purposes for which it was collected. The retention period depends on the type of data and the purpose of processing:
  - Order Records: Retained for up to 7 years to satisfy legal, tax, and contractual obligations.
 
  - Marketing Data: Retained until you withdraw your consent or unsubscribe from communications.
 
  - Technical Data: Retained for up to 2 years for analytical and security purposes.
 
At the end of the retention period, your data is securely deleted or anonymized.
Data Sharing and Processors
We may share your personal data with trusted third-party service providers ("processors") who assist us in fulfilling your orders and operating our business. These may include:
  - Payment processing providers (for securely handling transactions).
 
  - Courier and delivery partners (for delivering flowers to recipients).
 
  - IT and website hosting service providers.
 
  - Professional advisors, such as accountants or auditors, where required by law.
 
All processors are contractually bound to process your data only according to our instructions and in compliance with GDPR. We do not sell or rent your data to third parties for marketing purposes.
Your data may be processed outside the UK, but only in countries with adequate data protection standards as determined by the UK Government or where appropriate safeguards are in place.
Your Rights under GDPR
As a data subject, you have the following rights regarding your personal data:
  - Right to Access: Request a copy of the personal data we hold about you.
 
  - Right to Rectification: Request correction of inaccurate or incomplete information.
 
  - Right to Erasure: Request deletion of your data where there is no legitimate reason for its continued processing.
 
  - Right to Restrict Processing: Ask us to suspend processing of your data in certain circumstances.
 
  - Right to Data Portability: Request transfer of your data to another service provider.
 
  - Right to Object: Object to processing based on legitimate interests or direct marketing.
 
  - Right to Withdraw Consent: Where we use consent as a basis for processing, you may withdraw this consent at any time.
 
  - Right to Lodge a Complaint: If you believe your rights have been infringed, you have the right to complain to the UK supervisory authority for data protection matters.
 
Data Security
We implement appropriate technical and organisational security measures to protect your data from unauthorised access, loss, or misuse. These measures include secure servers, access restrictions, encryption where appropriate, and regular staff training on data protection.
Changes to This Policy
We review and update our Privacy Policy regularly to reflect changes in our processes, legal requirements, or industry best practices. Any updates will be posted with a new effective date. We encourage you to review this policy periodically.
Contact and Further Information
If you have any questions about this Privacy Policy or would like to exercise your rights, please contact us via our website or by writing to our business address. We are committed to responding to your requests promptly and within the timelines required by law.