Privacy Policy for Customers Ordering from Manor House and Surrounding Districts
Introduction
Flowers Manor House takes your privacy seriously and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and safeguard personal information from our customers. This policy is intended for everyone ordering products or services from Flowers Manor House within Manor House and surrounding districts. Our policy complies with the General Data Protection Regulation (GDPR) and relevant UK data protection law.
What Data We Collect
When placing an order with Flowers Manor House, we may collect the following types of information:
- Personal Identification Data: This includes your full name, address, postal code, and contact details such as phone number.
- Order and Delivery Information: Details about your order, delivery instructions, payment confirmation (collectively, 'transaction data').
- Payment Data: Limited payment information such as the transaction amount and method. We do not store your complete card details, and payments are handled through specialised third-party payment processors.
- Correspondence Data: Records of your communication with us, including order requests or feedback.
We do not intentionally collect special category data (such as health information) from our customers.
Lawful Basis for Processing Your Data
Under the GDPR, we process your data on the following lawful bases:
- Contractual Necessity: Most data is processed to carry out our obligations and provide you with products or services you have ordered. For instance, contact and delivery information are required to fulfil your order.
- Legal Obligation: We retain certain transactional and financial records as required to comply with tax and accounting laws.
- Legitimate Interests: We may use your data to improve customer service, resolve disputes, or prevent fraud, provided our interests are not overridden by your rights or interests.
- Consent: In cases where we seek to send you marketing communications or handle data not strictly necessary for order fulfilment, we will request your explicit consent. You can withdraw your consent at any time.
How We Use Your Data
Your information is used to:
- Process and deliver your orders
- Manage your customer account
- Respond to your enquiries
- Process payments securely
- Fulfil legal and regulatory requirements
- Improve our products and services
- Send you marketing communications, if you have agreed to receive them
Data Retention Periods
We will retain your personal data only for as long as necessary for the purposes it was collected. In particular:
- Order and Customer Information: Retained for up to 6 years from the date of your order to comply with statutory and tax requirements.
- Marketing Data: Retained until you withdraw your consent or opt out of receiving communications.
Once data is no longer required for its original purpose and is not subject to further legal or legitimate interest grounds, it will be securely erased or made anonymous.
Your Rights Under GDPR
As a customer, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can correct inaccurate or incomplete data.
- Right to Erasure: You can ask us to delete your data when it is no longer necessary for the purpose collected, or if you withdraw consent (where consent was required).
- Right to Restrict Processing: You can request we limit the way your data is used under certain circumstances.
- Right to Data Portability: You can ask to receive your data in a structured, commonly used, and machine-readable format and—where feasible—have it transferred directly to another organisation.
- Right to Object: You can object to the processing of your data for direct marketing at any time.
- Right to Withdraw Consent: If processing is based on consent, you can withdraw your consent at any time. This does not affect any processing already carried out before withdrawal.
- Right to Lodge a Complaint: You have the right to complain to a supervisory authority if you believe your data has been mishandled.
Disclosure and Data Processors
Flowers Manor House uses trusted third-party processors to help deliver our services. We ensure all processors are GDPR-compliant and have appropriate safeguards in place. Processors may include:
- Payment Providers: To process transactions and refunds securely
- Delivery Services: To physically deliver products to your address
- IT Support Providers: For technical support and data storage
Processors are only permitted to use your data for the agreed purposes and may not use it for their own purposes. We do not sell, trade, or rent your personal data to third parties.
Security of Your Data
We implement robust technical and organisational measures to protect your information from unauthorised access, alteration, disclosure, or destruction. Access to your information is limited to those employees, contractors, and agents who need to know it to process orders or perform other essential services.
International Data Transfers
Flowers Manor House does not routinely transfer personal data outside the UK or European Economic Area (EEA). If in rare cases international transfers are necessary, we ensure appropriate safeguards and legal mechanisms are in place to protect your data.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes to our practices, legal requirements, or for other operational reasons. All changes will take effect as soon as posted, and your continued use of our services indicates your acceptance of such changes.
Contact and Further Information
If you have any concerns or require further information about our data protection practices, you can contact us using the details provided on our official website or reach out directly at our Manor House location. We will do our best to address your privacy questions promptly and in accordance with GDPR.