Whetstone Florist Data Protection Policy
  Introduction
This Privacy Policy describes how Whetstone Florist collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Whetstone Florist from Whetstone and its surrounding districts. We take your data privacy seriously and are committed to ensuring that your personal information remains secure and is processed transparently.
What Data We Collect
Whetstone Florist collects information necessary to fulfill your order and provide you with a high-quality service experience. The types of personal data we collect include:
    - Identifying Information: such as your full name and, if applicable, the recipient's name.
 
    - Contact Details: including your address, delivery address, telephone number, and, where relevant, email address.
 
    - Order Details: specifics about your floral order, delivery instructions, and any personal messages you provide.
 
    - Payment Information: limited to transaction details and method of payment; sensitive card data is handled securely by payment processors and is not stored by us.
 
    - Communication Records: such as correspondence regarding your order or customer service queries.
 
    - Website Data: data collected via cookies or similar technologies when browsing our website, such as IP address, browser type, and browsing behavior (where applicable).
 
Lawful Basis for Processing Your Data
Under GDPR, we process your personal data based on the following lawful bases:
    - Contractual Necessity: Most of the information we process is necessary for fulfilling our contract with you — to process, deliver, and confirm your order.
 
    - Legal Obligation: We may need to process certain data to comply with applicable tax, accounting, or other legal obligations.
 
    - Legitimate Interests: For uses such as responding to inquiries or improving our services, where these interests do not override your fundamental rights and freedoms.
 
    - Consent: In some cases, such as for optional marketing communications (if available), we will only process your data with your explicit consent, which you can withdraw at any time.
 
How We Use Your Data
We use your personal data for the following purposes:
    - To process and fulfill your flower orders.
 
    - To communicate with you regarding your order, delivery, or any customer service issues.
 
    - To manage our business operations, including maintaining financial and delivery records.
 
    - To improve our services and understand customer needs (using aggregate, anonymised data where possible).
 
    - To comply with our legal and regulatory obligations.
 
How Long We Keep Your Data
We retain your personal information only as long as necessary to fulfill the purposes it was collected for, including for contractual, legal, accounting, or reporting requirements. Typically:
    - Order Data: Retained for up to 7 years to comply with tax and accounting legislation.
 
    - Customer Communications: Retained for up to 3 years after your last interaction with us.
 
    - Marketing Preferences: Retained until you withdraw your consent or opt out.
 
When personal data is no longer required, it is securely deleted or anonymised.
Who Processes Your Data
Your data may be processed by staff at Whetstone Florist and by carefully selected third-party service providers ("processors") acting on our behalf. These include:
    - Payment Processors: to handle your transactions securely.
 
    - Delivery Partners: to ensure your orders are delivered on time and to the correct address.
 
    - Accountancy Services: for legal tax and accounting purposes.
 
    - IT Support and Hosting Providers: for secure storage and management of digital data (where applicable).
 
We ensure that all processors act in compliance with this Privacy Policy and only process your data upon our instructions, maintaining appropriate safeguards to protect your information.
How We Protect Your Data
We implement industry-standard security measures to protect against unauthorised access, unlawful processing, accidental loss, destruction, or damage of personal data. This includes physical, electronic, and managerial procedures. All staff handling your data are trained in data protection principles and confidentiality.
Your Rights Under GDPR
As a customer of Whetstone Florist, you have a range of rights under GDPR, including:
    - Right to Access: You may request details about the personal data we hold about you.
 
    - Right to Rectification: You can ask us to correct any inaccurate or incomplete data.
 
    - Right to Erasure: You can request deletion of your personal data where justified.
 
    - Right to Restrict Processing: You may request that your data is only used for certain purposes.
 
    - Right to Data Portability: You can request your data in a structured, commonly used format and transfer it to another provider where feasible.
 
    - Right to Object: You can object to certain types of processing, such as direct marketing.
 
    - Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
 
    - Right to Lodge a Complaint: You have the right to raise a concern with your local data protection authority if you believe your data rights have been infringed.
 
Policy Updates
This Privacy Policy was last updated in 2024. We may amend this policy periodically to reflect changes in our practices or legal requirements. Updates will be clearly signposted in-store and on our website where applicable.
Contact Information
If you have any questions regarding this Privacy Policy, require further information, or wish to exercise your rights, please contact us directly at our Whetstone premises or via our standard contact channels as listed on your order confirmation or receipt.