This Privacy Policy explains how Elephant and Castle Florist ("we", "us", or "our") collects, uses, stores, and protects your personal information when you place an order with us in Elephant and Castle and surrounding districts. We are committed to respecting your privacy and protecting your data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
This Policy applies to all individuals who place orders with Elephant and Castle Florist, whether in-store, by telephone, or online, residing or ordering for delivery within Elephant and Castle and surrounding districts. By ordering from us, you agree to the terms of this Privacy Policy.
When you place an order or interact with Elephant and Castle Florist, we may collect the following categories of personal data:
We collect and process your data under one or more of the following lawful bases as defined by GDPR:
Your personal information may be used for the following purposes:
We may share your personal data with trusted third-party service providers ("processors") who assist us in delivering our services, such as:
All third-party processors are obliged to adhere to GDPR standards, process your data only on our instructions, and implement appropriate security measures.
We do not sell or share your personal information with third parties for their own marketing purposes.
We retain your personal data only as long as is necessary for the purposes it was collected, including to satisfy any legal, accounting, or reporting requirements. Typically, order, payment, and correspondence data is retained for up to seven years to comply with tax and financial regulations, after which it is securely deleted or anonymised. Marketing communications preferences are kept until you opt out or request deletion.
We employ a range of physical, technical, and organisational safeguards to protect your data against accidental loss, unauthorised access, use, alteration, or disclosure. This includes secure data storage, restricted access, staff training, and encrypted transfer of sensitive information where appropriate.
Under the GDPR, you have several rights in relation to your personal data. You can:
If you wish to exercise any of your rights, please contact us using the methods provided on our website or in our store. We will respond to all valid requests within one month, though we may require further information to confirm your identity for security reasons.
Your data is ordinarily stored and processed within the United Kingdom or European Economic Area (EEA). Where it is necessary to transfer your data outside the EEA (for example, if our service providers are located in other jurisdictions), we will ensure appropriate safeguards are in place to protect your information in accordance with data protection law.
We reserve the right to update or revise this Privacy Policy at any time to reflect changes in our practices or legal requirements. The latest version will always be available in-store and on our website. We recommend reviewing our policy from time to time to stay informed of how we use your data.
If you have questions about how we collect, use, or store your information, or wish to make a complaint, please refer to the contact section on our website or speak to us in-store. You also have the right to complain to the Information Commissioner’s Office (ICO) in the UK if you believe your data protection rights have not been upheld.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
