This Privacy Policy explains how Florists Crystal Palace ('we', 'us', 'our') collects, processes, and protects your personal data when you place an order with us. The policy applies to all customers placing orders from Florists Crystal Palace and the surrounding districts. We are committed to complying with the General Data Protection Regulation (GDPR) and ensuring your privacy is safeguarded.
To provide you with our floral services, we may collect and process the following categories of personal data:
We only process your personal data where permitted by GDPR. Our main lawful bases are:
Your personal data is used for the following purposes:
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, in line with legal, accounting, and reporting requirements. Typically, order and payment records are kept for up to seven years to comply with financial and tax laws. Other data, such as customer correspondence, is kept for up to two years unless a longer retention period is required or permitted by law. Once retention periods expire, your data is securely deleted or anonymised.
Florists Crystal Palace takes care in selecting trusted third parties ('processors') who may process your data on our behalf, including:
All processors are required to take appropriate security measures to protect your information and may only use it as instructed by us. We do not sell or rent your personal data to third parties. Personal data may be shared with government authorities if required by law.
Under the GDPR, you have the following rights regarding your personal data:
To exercise any of these rights, please contact us using the details provided on our website. We will respond to all legitimate requests within one month.
We take the security of your personal data seriously. Appropriate organizational and technical measures are in place to prevent your data from being lost, used, accessed, altered, or disclosed unlawfully. Access to your data is limited to employees and processors who require it for business purposes. Procedures are in place to deal with suspected data breaches, and we will notify you and regulators where legally required.
We generally store and process your personal data within the United Kingdom or the European Economic Area (EEA). Where third-party processors operate outside these locations, we ensure your data is protected by appropriate safeguards, in accordance with GDPR requirements.
We may update this privacy policy occasionally to reflect changes in how we handle your personal data or to comply with legal requirements. When we make significant changes, we will notify you by updating the policy on our website and indicating the revision date.
If you have any queries about this privacy policy or how your data is processed at Florists Crystal Palace, please contact us via the contact information provided on our website. If you are dissatisfied with how we handle your personal data, you are entitled to lodge a complaint with the UK Information Commissioner’s Office (ICO).
Please fill out the form below to send us an email and we will get back to you as soon as possible.
