Privacy Policy for Customers of Flower Delivery Erith
Introduction
This Privacy Policy explains how Flower Delivery Erith collects, uses, stores, and secures your personal data in compliance with the General Data Protection Regulation (GDPR) and all applicable UK data protection laws. The policy applies to all customers placing orders for flower delivery services from Erith and surrounding districts. By placing an order or interacting with our services, you consent to the practices outlined herein.
What Personal Data We Collect
Flower Delivery Erith collects various categories of personal data as required for the fulfilment of our services and legal obligations. The types of data we collect may include:
- Contact Information: such as your name, delivery address, billing address, and telephone number.
- Order Details: including recipient’s name, delivery instructions, card messages, and details of your purchase.
- Payment Details: limited to payment confirmation data, not full card numbers (handled by compliant third-party payment processors).
- Communication Data: such as messages sent via our website contact form or during order processing.
- Technical Data: including IP address, browser type, and device identifiers collected through website usage analytics.
Lawful Basis for Data Processing
We only process your personal data where there is a valid and lawful basis under the GDPR. The primary lawful grounds for collection and processing include:
- Contractual Necessity: To process and fulfil your flower delivery order.
- Legal Obligation: To comply with applicable accounting, tax, and business regulations.
- Legitimate Interests: For business operations such as service improvement, fraud prevention, and maintaining customer service standards. We always assess these interests to ensure they do not override your rights and freedoms.
- Consent: For activities such as marketing communications, where you must provide explicit permission. You can withdraw consent at any time.
How We Use Your Data
Your data may be used for the following purposes:
- To process and deliver your orders.
- To communicate regarding your orders and respond to your queries.
- To process payments securely via third-party payment processors.
- To maintain service quality, train staff, and enhance our offerings.
- To meet legal, regulatory, or contractual requirements.
- For internal analysis and business development (using anonymised or aggregated data wherever possible).
Retention of Your Data
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. This means:
- Order and transaction records are typically held for six years in line with UK tax and accounting requirements.
- Contact and communication data may be retained for up to two years for customer service purposes, unless you request erasure sooner.
- Data provided for marketing purposes is retained until you withdraw your consent.
After the retention period ends, your personal data will be securely deleted or anonymised.
Data Processors and Data Security
We may share your data with trusted third-party service providers (processors) as necessary to perform core business functions. Examples include:
- Payment processing companies (to handle card payments securely).
- IT service providers (to host our website, process online orders, and store data).
- Couriers and delivery firms (to fulfil your delivery instructions).
- Professional advisers (such as accountants and legal advisers, where required).
All processors are required to adhere to robust standards of data protection and security and only process data according to our instructions, never for their own purposes. Flower Delivery Erith ensures that these parties offer appropriate safeguards in accordance with GDPR requirements.
We implement suitable technical and organisational measures to keep your data safe from loss, misuse, or unauthorised access. This includes secure servers, encryption where appropriate, regular staff training, and effective access controls.
Your Rights Under GDPR
Under data protection law, you have several important rights concerning your personal data:
- Right of Access: You can request a copy of your personal data and information about how it is used.
- Right to Rectification: You have the right to correct inaccurate or incomplete data.
- Right to Erasure: Also known as the ‘right to be forgotten’, you may request deletion of your data under certain circumstances.
- Right to Restrict Processing: You can limit how your data is used in specific situations.
- Right to Data Portability: You can request a copy of your data in a machine-readable format to transfer to another provider.
- Right to Object: You may object to data processing based on our legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: If processing is based on consent, you can withdraw this consent at any time.
- Right to Lodge a Complaint: You are entitled to raise issues with the Information Commissioner’s Office (ICO) if you believe your data rights have been infringed.
Requests to exercise your rights should be sent to our data protection point of contact. We will respond within one month as required by law.
Applicability of This Policy
This Privacy Policy applies to all Flower Delivery Erith customers in Erith and the surrounding districts who place orders via our website, by phone, or in person. We may update this policy periodically to ensure transparency and compliance with evolving regulations. Any significant changes will be communicated through our usual channels.
Your trust is very important to us. For any questions about this Privacy Policy or to exercise your rights, please contact our customer service team, who will be happy to assist you further.