This Privacy Policy sets out how Cambridge Heath Florist (“we”, “us”, or “our”) collects, uses, stores, and protects your personal information when you place orders with us in Cambridge Heath and the surrounding districts. We take data privacy seriously and process your information in compliance with the United Kingdom General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains your rights regarding your personal data and how to exercise them.
This policy applies to all customers placing orders with Cambridge Heath Florist from Cambridge Heath and its surrounding areas, whether orders are placed in person, by phone, via our website, or through other respected channels we may use for order processing and delivery.
When you place an order with us, we collect the following categories of personal data:
Under the UK GDPR, we must have a lawful basis for processing your personal information. Cambridge Heath Florist processes your data based on the following grounds:
Your data is used strictly for the purposes for which it was collected, including:
We will keep your personal information only as long as reasonably necessary to fulfil the purposes we collected it for, including to satisfy any legal, accounting, or reporting requirements:
After these periods, personal information will be securely deleted or rendered anonymous.
Your personal data may be shared with trusted third-party service providers (“processors”) who help us fulfil orders, process payments, deliver flowers, maintain our website, or perform marketing on our behalf. These processors include delivery couriers, CRM and payment systems, and IT support services. Each processor is strictly bound by an agreement to maintain the confidentiality and security of your data and is only permitted to process your data following our instructions.
We do not sell, rent, or trade your personal data to third parties.
Where required by law or to protect our rights or customers’ safety, we may disclose data to governmental bodies or law enforcement agencies.
Your personal data is stored in the UK or the European Economic Area (EEA). If any processing occurs outside these jurisdictions, safeguards will be implemented to ensure your data remains protected in line with UK GDPR standards.
Under the UK GDPR, you have the following rights regarding your personal data:
We are committed to ensuring that your data is secure. We have put in place appropriate technical and organisational measures to protect your personal information from unauthorised access, accidental loss, misuse, alteration, or disclosure. Access to your data is strictly limited to authorised personnel and trusted processors. All data transmissions are secured using industry-standard encryption where appropriate.
We may update this privacy policy from time to time to reflect legal requirements or changes in our business processes. Significant updates will be communicated to you where appropriate. The most recent version is always available through our main customer communication channels and on our website.
If you have any questions about this Privacy Policy or about your data protection rights, please contact us using the usual customer enquiry channels or by writing to our premises during business hours.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
