This Privacy Policy outlines how Cambridge Heath Flowers ('we', 'us', or 'our') collects, uses, stores, and protects your personal data in accordance with the UK General Data Protection Regulation (GDPR) and all relevant local laws. This policy applies to all individuals placing orders with Cambridge Heath Flowers within Cambridge Heath and its surrounding districts.
When you place an order with Cambridge Heath Flowers, we collect and process certain personal information to fulfill your requests and provide our services effectively. The personal data we may collect includes:
Cambridge Heath Flowers only processes your data where there is a lawful basis under GDPR. These bases include:
Your data is used to:
We retain your personal data only for as long as is necessary to fulfill the purposes described in this policy or as required by law. Typically, we will maintain customer order and communication records for up to six years to comply with business and taxation requirements. Technical and website usage data may be retained for a shorter period, unless necessary for security or legal reasons.
Once your data is no longer required, it will be securely erased or anonymised so that you can no longer be identified from it.
Cambridge Heath Flowers may use third-party service providers (processors) to assist with certain business operations. These may include payment processing companies, delivery service partners, IT support providers, and website analytics services. We ensure that all third-party processors comply with GDPR requirements and protect your data to the same high standards. Your personal data will not be sold or shared with organisations for their own marketing purposes.
Where such processors operate outside the UK or European Economic Area, we take steps to ensure that your data remains protected through recognized safeguards such as Standard Contractual Clauses.
We implement appropriate technical and organisational measures to protect your personal data, including role-based access controls, encrypted storage solutions, and secure data transfers. Only authorised personnel who require access to your data to perform their duties will be permitted such access. We review and update our security practices regularly to safeguard your information against unauthorised access, loss, or misuse.
Under GDPR, you have several rights in relation to your personal data. These include:
We may revise this Privacy Policy from time to time to reflect changes in regulations, our data processing practices, or for other operational reasons. Updates will take immediate effect upon publication. We encourage customers to review this policy regularly to stay informed of how we protect your information.
If you have any questions about this Privacy Policy or about your rights regarding your personal data, please contact us using the details provided on our website. We will endeavour to respond to your queries promptly and to resolve any concerns you may have about your data.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
