Marylebone Florist Privacy Policy
  Introduction
This Privacy Policy outlines how Marylebone Florist collects, uses, and safeguards your personal data when you place an order with us. The policy is designed to comply with the General Data Protection Regulation (GDPR) and applies to all customers placing orders from Marylebone and the surrounding districts.
What Data We Collect
When you place an order with Marylebone Florist, we collect different types of personal data depending on your interaction with us. This may include:
  - Identity Data: Your name and the recipient’s name.
- Contact Data: Delivery address, billing address, telephone number (if provided), and any other contact details you provide.
- Order Data: Details of the floral arrangements you order, delivery instructions, personalised messages, and order history.
- Payment Data: Transaction and payment information (such as payment method and status). Please note, payment processing is handled by trusted third-party payment processors; Marylebone Florist does not store complete card or bank details.
- Technical Data: When visiting our website, we may collect information including your IP address, browser type, device information, and usage data (such as pages viewed and interactions recorded through cookies or similar technologies).
Lawful Basis for Data Processing
Marylebone Florist processes your personal data in accordance with the GDPR, relying on several lawful bases:
  - Contractual Necessity: Most data we process is to fulfil our contract with you, such as processing orders, arranging delivery, and managing transactions.
- Legal Obligation: We may need to process certain data to comply with financial, accounting, or tax regulations.
- Legitimate Interests: We may process data to improve our services, administer our site, prevent fraud, or communicate relevant updates, provided they do not override your rights.
- Consent: Where required, such as for direct marketing communications that are not related to your order, we will only process your data with your explicit consent.
How We Use Your Personal Data
We use your information in the following ways:
  - To process and deliver your floral order, including sharing necessary data with our drivers or delivery partners for fulfilment.
- To communicate with you about your order, confirmations, or delivery issues.
- To process payments using secure third-party providers.
- To comply with legal, regulatory, or contractual requirements.
- To improve our website, services, and customer experience through analysis of technical data and feedback.
Data Retention
Marylebone Florist retains personal data only for as long as necessary to fulfill the purposes for which it was collected, including any legal, accounting, or reporting requirements. For example:
  - Order Data: Retained for up to seven years to comply with financial record-keeping laws.
- Enquiries and correspondence: Generally retained for up to one year, unless required to resolve disputes or meet legal obligations.
- Technical data (cookies and logs): Retention depends on the type of cookie or log file and will not exceed the period necessary for the stated purpose.
When data is no longer necessary, it will be securely deleted or anonymised.
Data Processors and Third Parties
To deliver our services, we may share your data with third parties acting as data processors. These may include:
  - Payment processing companies who complete financial transactions securely.
- Delivery partners responsible for delivering your order.
- IT service providers who host and maintain our website and data storage systems.
- Professional advisors (such as accountants or legal consultants) if necessary for compliance.
All third-party processors are required to adhere to data protection laws and are contractually bound to process your data only for the purposes specified by Marylebone Florist.
Your Rights Under GDPR
As a customer, you have a range of rights under GDPR:
  - Right of Access: You can request details of the personal data we hold about you.
- Right to Rectification: You may ask us to correct or update incorrect or incomplete data.
- Right to Erasure: You may request deletion of your personal data in certain circumstances.
- Right to Restrict Processing: In some cases, you can ask us to limit the way we use your data.
- Right to Object: You can object to certain types of processing, such as direct marketing.
- Right to Data Portability: You can request that we provide your data to you or another controller in a structured, commonly used format.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw this at any time.
If you wish to exercise any of these rights, please contact us. Verification of your identity may be required before actioning your request.
Policy Scope and Updates
This Privacy Policy applies to all customers placing orders with Marylebone Florist from Marylebone and the surrounding districts. We may update this policy from time to time to reflect changes in legal obligations, our practices, or our services. Please check this page regularly for updates. Significant amendments will be communicated where appropriate.
Contact and Concerns
If you have questions or concerns about how your data is handled by Marylebone Florist, or if you wish to exercise any of your rights, please use the contact details provided on our website. Should you remain unsatisfied with our response, you also have the right to lodge a complaint with the UK Information Commissioner's Office or your local supervisory authority.