West Harrow Florist Privacy Policy
  Introduction
This privacy policy applies to all customers who place orders with West Harrow Florist from West Harrow and the surrounding districts. We are committed to respecting your privacy and safeguarding your personal data, in accordance with the General Data Protection Regulation (GDPR) and relevant UK data protection laws. Please read this policy carefully to understand how we process your data, your rights as a data subject, and how you can exercise these rights.
What Personal Data We Collect
When you interact with West Harrow Florist, place an order, or make an enquiry, we may collect and process the following types of personal data:
  - Identity Data: Name, title (where provided), and contact details.
- Contact Information: Billing address, delivery address, telephone number, and other contact information you provide.
- Order Details: Details of orders you place, items purchased, recipient information (name and delivery details), and order notes.
- Payment Information: Payment card details (processed securely via our payment processor and not stored by West Harrow Florist), payment method, and transaction history.
- Correspondence: Records of communications when you contact us, such as via telephone or any written correspondence.
- Technical Data: IP address, browser type, and device information when you use our website, used for security and analytics purposes.
Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process your personal data. West Harrow Florist processes your personal data under one or more of the following lawful bases:
  - Contractual Necessity: To process your orders, deliver goods, arrange payment, and provide customer service.
- Legal Obligation: For compliance with legal and regulatory requirements (for example, for accounting and tax purposes).
- Legitimate Interests: For purposes such as improving our products and services, handling customer enquiries, and keeping records of transactions.
- Consent: Where required, for example, if you specifically consent to receive our marketing communications. You can withdraw your consent at any time.
How We Use Your Information
We use your information for the following purposes:
  - Processing and fulfilling your orders, including arranging delivery and communicating with you about your purchase.
- Handling payments, refunds, and resolving queries related to your orders.
- Providing customer support and handling complaints or enquiries.
- Complying with our legal and regulatory obligations, including record keeping for tax and accounting.
- Improving our services, understanding how customers interact with us, and enhancing your experience.
- Marketing our products and services to you, where permitted by law and subject to your preferences.
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Generally, we will retain order information for a minimum of six years to comply with tax and accounting responsibilities. After this period, your data will be securely deleted or anonymised.
Data Processors and Third Parties
West Harrow Florist may share your personal data with selected third-party service providers, known as data processors, who assist us in providing our services to you. These may include:
  - Payment Service Providers: For processing secure payments. We do not store full payment card details.
- Delivery Partners: To ensure your order is delivered efficiently.
- IT Service Providers: For hosting and managing our website, software, and databases.
- Professional Advisors: Such as accountants and legal advisers, where necessary.
All third-party processors are required to respect the security and confidentiality of your data and act only on our instructions. We do not sell or rent your personal data to third parties.
Data Security
We take appropriate technical and organisational measures to safeguard your personal data from misuse, unauthorised access, loss, or disclosure. This includes secure physical and electronic storage, access controls, data encryption where appropriate, and regular review of our data protection practices.
Your Data Protection Rights
As a customer within West Harrow and surrounding districts, you have the following rights under GDPR:
  - Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct any inaccurate or incomplete data.
- Right to Erasure: In certain circumstances, you can request your personal data be erased from our records.
- Right to Restrict Processing: You may ask us to restrict the processing of your personal data in specific cases.
- Right to Data Portability: You can request a copy of your data in a common machine-readable format.
- Right to Object: You may object to the processing of your data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time.
To exercise any of these rights, please contact us using the details provided on our website. We may require verification of your identity to process your request. Please note that some rights are subject to limitations and we may retain certain information where required by law.
Policy Updates
We review and update our privacy policy regularly to ensure continued compliance with data protection legislation and changes in our practices. We encourage you to revisit this policy from time to time to stay informed about how we protect your data.
Contact and Complaints
If you have questions about this privacy policy or how we process your personal information, please get in touch using the contact details provided on our website. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your local data protection authority.