Tufnell Park Flowers - Privacy Policy
  Our Commitment to Your Privacy
At Tufnell Park Flowers, we are dedicated to protecting your privacy and respecting your rights in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. This Privacy Policy outlines how we collect, use, retain, disclose, and safeguard your personal data as our customer, and explains the rights you have regarding your personal information. This policy applies to all customers placing Tufnell Park Flowers orders from Tufnell Park and the surrounding districts.
What Data We Collect
When you place an order with Tufnell Park Flowers, we collect information that is necessary to process and fulfil your order, communicate with you, and improve our services. The types of personal data we may collect include:
  - Contact Information: Name, address, delivery address, and phone number (if voluntarily provided for order coordination).
- Order Details: Products ordered, delivery date and time, special instructions, and order notes.
- Payment Details: Payment transaction information (we do not store full card details; payments are processed by our trusted payment providers).
- Account Information: Username, password, and order history (if you create an account on our website).
- Communication Data: Correspondence via our contact forms, feedback, complaints, or queries regarding an order.
- Technical Data: IP address, browser type, and usage data collected via cookies to facilitate the use of our website and improve user experience.
Lawful Basis for Processing Your Data
Our collection and use of your personal data must have a valid legal reason under GDPR. The lawful bases upon which we process your data include:
  - Contractual Necessity: To process, confirm, and fulfil your flower order and manage deliveries.
- Legal Obligation: To comply with accounting, tax, and legal requirements regarding order records.
- Legitimate Interests: For purposes such as improving our services, preventing fraud, and maintaining security. Where our legitimate interests are not overridden by your rights.
- Consent: We will seek your explicit consent for any marketing communications or for the processing of optional personal data, such as feedback or review submissions. You can withdraw your consent at any time.
How We Use Your Data
Your information is used strictly for the following purposes:
  - Processing and fulfilling your flower orders.
- Managing payment and, if applicable, resolving payment queries (processed through external payment providers).
- Communicating order confirmations and updates, responding to enquiries, and handling any complaints or feedback.
- Complying with legal and regulatory obligations, such as maintaining business records and tax documentation.
- Improving our services and website offerings through the anonymised analysis of user behaviour and preferences.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which we collected it, including for the purpose of satisfying any legal, accounting, or reporting requirements. The retention periods depend on the type of data collected and the applicable legal obligations. In general:
  - Order and delivery information is kept for up to 6 years to comply with legal and accounting requirements.
- Correspondence and customer queries are retained for up to 2 years after resolution.
- If you have created an account, your account data will be kept as long as your account remains active. You may request deletion at any time.
- Aggregated or anonymised data, which does not identify individuals, may be retained for a longer period for statistical purposes.
Data Processors and Third Parties
To provide our services, we may need to share your data with selected third-party service providers (data processors) who process data on our behalf under strict contractual obligations and only for the specified purposes. These include:
  - Payment processors for secure handling and processing of payments.
- IT service providers who manage our website, email, and data storage solutions.
- Deliveries and logistics partners as necessary to complete orders within Tufnell Park and surrounding districts.
All third-party processors are contractually obliged to protect your data and act only on our instructions. We do not sell or rent your personal information to third parties for marketing purposes.
Your Rights Under GDPR
As a customer, you have legal rights concerning your personal data, including the following:
  - Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct any incomplete or inaccurate data we hold about you.
- Right to Erasure: You can ask us to delete your data where there is no good reason for us to continue to process it, subject to legal requirements.
- Right to Restrict Processing: You can ask us to suspend processing your data in certain circumstances.
- Right to Data Portability: You can request your personal data in a structured, commonly used format to transfer to another provider.
- Right to Object: You can object to us processing your data where we rely on a legitimate interest or use your data for direct marketing.
- Right to Withdraw Consent: If you have consented to any processing, you can withdraw it at any time.
To exercise your rights or for any privacy-related questions or concerns, please contact us using the contact options provided on our website. We will respond to your request in accordance with applicable laws and our procedures.
Data Security
We implement appropriate technical and organisational measures to secure your personal data from accidental loss, unauthorised access, disclosure, alteration, or destruction. Our payment processing partners comply with industry security standards. While we strive for maximum security, please be aware that no method of transmission over the internet or electronic storage can be guaranteed to be 100% secure.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to ensure its accuracy and compliance with data protection laws. Any significant changes will be communicated on our website. The updated policy will take effect as soon as it is published.
Contacting Us
If you have any questions, concerns, or requests regarding how we handle your personal data, please reach out to us using the contact details provided on our website. We are committed to addressing your privacy concerns and will respond accordingly.