At Sutton Florist, we are dedicated to protecting the privacy of our customers and ensuring the confidentiality of all personal data collected during the ordering process. This Privacy Policy outlines how we process, store, and protect your information in compliance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Sutton Florist from Sutton and surrounding districts, whether online, by phone, or in person.
We collect information necessary to fulfil your order and provide our floral delivery services. Depending on how you interact with us, we may collect the following categories of personal data:
Under GDPR, we are required to have a lawful basis to process your personal data. Sutton Florist processes your personal information primarily on the following grounds:
We retain your personal data only as long as is necessary to fulfil the purposes for which it was collected. Typically, this means:
Your information may be shared with trusted third-party service providers (processors) who support our operations. These may include:
All third-party processors are required to adhere to strict data protection standards, only process your data on our instructions, and are not allowed to use it for their own purposes. We do not sell or rent your personal data to any third parties for marketing purposes.
You have various rights under GDPR regarding your personal data:
To exercise any of these rights, please contact us using the contact form available on our website or by writing to our business address. We will respond to your request in accordance with GDPR requirements and may need to verify your identity before acting. There is no fee for most requests, although we reserve the right to charge a reasonable fee if a request is unfounded or excessive.
We have implemented appropriate technical and organisational measures to ensure the security and confidentiality of your personal data. These include secure storage, encryption of sensitive data, restricted access controls, and regular staff training. However, please note that no data transmission over the internet can be guaranteed as entirely secure.
Your data is primarily processed and stored within the UK. If we need to transfer your data outside the UK or European Economic Area, we will ensure that adequate safeguards are in place, such as standard contractual clauses or the use of providers certified under appropriate data protection frameworks.
We may update this Privacy Policy from time to time to reflect changes in legal obligations or the way we process your personal data. The updated version will always be available on our website with the latest revision date. We encourage you to review this policy periodically.
If you have any further questions about how we use your personal data or wish to raise a concern, please contact us using the online contact form or by writing to our business address. If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK’s data protection regulator, though we would appreciate the opportunity to address your concerns first.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
