Privacy Policy for Flower Delivery North Woolwich
Introduction
This Privacy Policy explains how Flower Delivery North Woolwich ('we', 'our', 'us') collects, processes, stores, and protects your personal data. It applies to all individuals placing flower delivery orders in North Woolwich and surrounding districts through our services. We are firmly committed to safeguarding your privacy and complying with all obligations under the General Data Protection Regulation (GDPR) and relevant UK data privacy laws.
What Data We Collect
When you use our services to place a flower delivery order, we may collect the following categories of personal data to provide and improve our services:
- Identity Data: Your name, and when relevant, the recipient's name.
- Contact Data: Address, delivery location, contact number, and other contact details provided for order completion.
- Order Details: Information about the products and services purchased, delivery preferences, messages attached to orders, and purchase history.
- Payment Data: Details concerning your payment method. Please note, we do not store full payment details; our payment processors manage this securely.
- Technical Data: IP address, browser type and version, time zone setting and location, and information about how you interact with our website or app (cookies and analytics data).
- Communication Data: Customer service inquiries, correspondence, and feedback.
Lawful Basis for Processing Personal Data
We process your information in accordance with the lawful bases provided under the GDPR. The specific lawful bases we rely upon include:
- Contract Performance: Most data processing is required to fulfill the contract of delivering your order to the recipient at your request, including communicating about delivery status and managing transactions.
- Legal Obligation: We may need to process certain data to comply with statutory and regulatory obligations (for example, accounting, taxation, or reporting requirements).
- Legitimate Interests: We have a legitimate business interest in understanding our customers’ preferences, improving our services, preventing fraud, and maintaining the security and integrity of our platform. Where we rely on these interests, we consider your rights and freedoms and do not override them.
- Consent: In some instances, such as for direct marketing emails or non-essential cookies, we seek your consent before processing your data. You can withdraw consent at any time.
How We Use Your Information
Your personal data is used for these purposes:
- To process, confirm, and deliver your flower orders and communicate order status.
- To facilitate payment through secure third-party payment processors.
- To manage customer queries, requests, and complaints.
- To customize and improve our services, including website analytics and customer feedback.
- To comply with legal and governmental obligations.
- For marketing communications, provided you have given consent where required.
Data Retention
We retain your personal data only for as long as is necessary to fulfill the purposes outlined in this Policy and to comply with applicable legal, accounting, or reporting requirements. Typically, we retain order-related information for up to seven years to meet legal obligations and for our legitimate business interests. Technical and analytics data may be retained for a shorter period as defined in our data retention schedules. When your data is no longer required, we securely delete, anonymize, or destroy it.
Processors and Data Sharing
To provide our services effectively, we may share your data with selected third-party service providers (processors) strictly for the purposes outlined below:
- Payment Service Providers: To securely process payments and manage refunds.
- IT and Hosting Partners: To host and maintain our website and ensure service reliability and security.
- Delivery Partners: Where necessary, we may pass recipient contact and delivery information to trusted local couriers to fulfill orders.
- Professional Advisors: Including accountants, legal advisors, and insurance partners (for compliance or in connection with legal claims).
All processors act strictly on our instructions and under appropriate contractual obligations, including data security and confidentiality requirements. We do not sell or share your data with third parties for their own marketing purposes.
International Data Transfers
Wherever possible, your personal data is processed within the United Kingdom or the European Economic Area (EEA). If it is necessary to transfer your personal data outside these regions (for example, due to the location of specific service providers), we ensure such transfers are subject to appropriate safeguards to guarantee an adequate level of data protection, in accordance with GDPR requirements.
Your Rights Under GDPR
As a customer placing orders within North Woolwich and the surrounding areas, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request corrections to your personal data if it is inaccurate or incomplete.
- Right to Erasure: Ask for your personal data to be deleted, subject to legal and operational retention requirements.
- Right to Restrict Processing: Request limits on how we process your information in certain circumstances.
- Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format or have it sent to another controller where feasible.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: Contact the UK’s Information Commissioner's Office (ICO) if you have concerns about our data handling practices.
To exercise any of your rights, please contact us in writing. We will endeavour to respond to your request promptly and within the statutory timescales.
Data Security
We implement organisational and technical measures to protect your data from accidental loss, unauthorised access, or disclosure. These include secure servers, encrypted communications (SSL), regular reviews of our security systems, restricted staff access, and mandatory confidentiality obligations for anyone handling your data.
Changes to This Policy
We may update this Privacy Policy from time to time. Updates will be posted on our website or made available when you use our services next. Please review this page regularly to remain informed about how we protect your personal information.
Contacting Us
If you have any questions about this Privacy Policy, our data practices, or wish to exercise your rights, please contact us using the details provided on our website or by writing to our physical business address.