Castelnau Flowers GDPR Privacy Policy
Scope and Purpose
This Privacy Policy explains how Castelnau Flowers collects, processes, and protects the personal data of customers who place flower orders from Castelnau and its surrounding districts. We are committed to respecting your privacy and ensuring that your personal information is handled in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
What Data We Collect
Castelnau Flowers collects, stores, and processes the following categories of data when you place an order with us:
- Identification Data: Your full name, delivery address, and billing address.
- Contact Information: Telephone numbers and delivery recipient information if different from the purchaser.
- Order Details: Nature and contents of your flower order, delivery instructions, occasions, and any special requests.
- Payment Data: Partial payment information as provided by our payment providers (we do not store full card details).
- Correspondence: Information from communications between you and Castelnau Flowers, such as enquiries or feedback.
- Website Usage Data: Technical data such as IP address, browser type, and browsing history on our site (through cookies and similar technology).
Lawful Basis for Processing Your Data
Under GDPR, we rely on specific lawful bases to process your personal data:
- Contractual Necessity: Most of your data is processed to fulfil our contract with you—for example, to prepare and deliver your order, process payments, and handle queries.
- Legal Obligation: We may retain data as required by law for accounting, taxation, or regulatory purposes.
- Legitimate Interests: We may contact you for feedback, or to inform you of changes to our services, where it does not override your fundamental rights and freedoms.
- Consent: When you opt-in to receive marketing or promotional materials, your consent will be sought and can be withdrawn at any time.
How We Use Your Data
We use your personal data only for the intended and stated purposes, which include:
- Processing and delivering flower orders to the correct recipient and address.
- Managing payments and refunds related to your purchased goods and services.
- Communicating with you regarding your order status, delivery information, and after-sales service.
- Responding to your enquiries, complaints, or feedback.
- Complying with legal, tax, or regulatory obligations.
- Ensuring security and integrity of our services, including preventing and detecting fraud or abuse.
- Improving our products, services, and customer experience based on anonymised data and feedback.
Retention of Your Data
Your personal data will be retained for only as long as necessary for the purposes outlined above. In practice, this means:
- Order information and correspondence are kept for a minimum of 6 years to comply with legal and accounting requirements.
- Contact details used for marketing purposes are retained until you withdraw consent or unsubscribe.
- Technical and browsing data may be retained for up to 26 months for analytical and security purposes.
When your data is no longer required, it will be securely deleted or anonymised.
Data Processors and Third Parties
We work with carefully selected third-party processors who support the efficient delivery of our services. These may include:
- Payment Providers: Securely manage your online payments.
- Delivery Partners: Handle the transport of your orders to the specified address.
- IT Service Providers: Maintain our website, customer database, and data backup solutions.
- Accountants and Legal Advisors: Assist us in fulfilling legal and regulatory obligations.
All third-party processors act under our instructions and are required under contract to keep your data safe and secure, compliant with GDPR obligations. Castelnau Flowers does not sell or rent your personal data to third parties for their direct marketing.
Your data will not be transferred outside the United Kingdom or European Economic Area unless adequate protection measures and safeguards, as prescribed by GDPR, are in place.
Your Data Protection Rights
You have the following rights regarding your personal data:
- Access: Obtain confirmation about whether your data is processed, and access to your personal data.
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Ask us to delete your data (the "right to be forgotten") under certain conditions.
- Restriction: Ask for the processing of your data to be limited in certain circumstances.
- Objection: Object to our processing where we rely on legitimate interests or direct marketing.
- Portability: Request transfer of your data in a commonly used, machine-readable format.
- Withdraw Consent: Where we rely on your consent, you may withdraw it at any time. This will not affect prior processing.
- Lodge a Complaint: Complain to your local data protection authority if you believe your data has not been handled correctly.
To exercise your rights, please contact us using the channels provided on our website or written correspondence.
Security of Your Data
Castelnau Flowers is committed to safeguarding your personal data. We implement technical and organisational measures such as restricted access, encryption, and staff training to prevent unauthorised access, disclosure, loss, or misuse. We regularly review our procedures to ensure ongoing compliance with data protection requirements.
Policy Changes and Updates
This policy may be updated from time to time to reflect changes in legal requirements, our practices, or the services we offer. The ‘last updated’ date at the top of this policy indicates when it was last revised. We encourage you to review this policy periodically.