Privacy Policy for Flower Delivery West Hampstead
Introduction
This Privacy Policy describes how Flower Delivery West Hampstead (“we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you order flower deliveries from us. This Policy applies to all customers who place Flower Delivery West Hampstead orders from West Hampstead and its surrounding districts. We are fully committed to complying with the General Data Protection Regulation (EU) 2016/679 (“GDPR”) and applicable UK privacy laws. Please read this policy carefully to understand your rights and our responsibilities regarding your personal information.
What Data We Collect
When you place an order, make an enquiry, or interact with our website or services, we may collect the following categories of personal data:
- Identity Data: Name, billing address, delivery address, and payment information (except for full payment card numbers, which are processed securely by payment gateways).
- Contact Data: Phone number and email address (where provided).
- Order Information: Details about the recipient (name, delivery address, phone number, and instructions), order content, delivery preferences, and any messages to accompany the flowers.
- Technical Data: IP address, device type, browser information, website usage statistics, and cookies as applicable to website functionality.
- Correspondence: Records of customer service communications, feedback, and complaints.
Lawful Basis for Processing Your Data
We only collect, use, and process your data when we have a valid legal basis to do so under GDPR. The main bases relevant to our services are:
- Contractual necessity: To process and deliver your orders, manage payments, and provide customer support.
- Legitimate interests: To improve our services, prevent fraud, or communicate important service information, as long as these interests are not overridden by your data protection rights.
- Legal obligation: To comply with relevant laws and regulations, including tax and accounting requirements.
- Consent: Where you have provided explicit consent, for example, to receive marketing communications. You may withdraw consent at any time.
How We Use Your Data
Your personal data will be used for the following purposes:
- Processing, fulfilling, and delivering your flower orders.
- Communicating with you about your orders and responding to enquiries.
- Managing payments and refunds via secure third-party payment processors.
- Improving our customer services, website functionality, and offerings.
- Detecting and preventing fraud or misuse of our services.
- Meeting our legal and regulatory obligations.
- With your consent, sending you relevant promotional offers or newsletters.
Data Retention
We will not retain your personal data for longer than is necessary to achieve the purposes for which it was collected and processed. Our retention periods are as follows:
- Order Data and Transaction Records: Retained for up to seven years to comply with accounting and taxation laws, as well as to resolve any disputes or enforce agreements.
- Customer Correspondence: Retained for up to three years from the last communication, unless required longer for legal purposes.
- Marketing Data: Retained until you withdraw your consent or unsubscribe from our communications.
- Technical and Analytical Data: Retained for no longer than 26 months from your website visit for performance, troubleshooting, and improvement analysis.
At the end of the retention period, or upon your request (if permitted), we will securely delete or anonymise your personal data.
Third-Party Processors and Data Sharing
We may share aspects of your data with trusted third-party service providers (“processors”) for the following reasons:
- Payment Processing: Secure payment gateways handle transaction data; we do not have access to your full card details.
- Delivery Partners: Local couriers and florists are provided with the necessary delivery and recipient details to fulfil your order.
- IT and Hosting Providers: For secure hosting and data backup.
- Analytical Services: To help us understand website usage and improve user experience, using anonymised or pseudonymised information whenever possible.
All our third-party processors are required by contract to keep your data secure and process it only as necessary to provide their services to us. We do not sell or rent your personal data to third parties. Data shared for legal compliance may be provided to public authorities if required by law.
International Data Transfers
We primarily process and store your data within the United Kingdom and European Economic Area (EEA). Should there be an instance where your data needs to be processed outside these regions, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or other lawful bases as recognised by the GDPR, to ensure your data remains protected.
Your Rights Under GDPR
The GDPR provides you with various rights regarding your personal data. These include:
- Right of Access: You can ask for a copy of the personal data we hold about you.
- Right to Rectification: Request corrections or updates to any incomplete or inaccurate data.
- Right to Erasure (“Right to be Forgotten”): Ask us to delete your personal data where it is no longer necessary or if processing is based on consent which you withdraw.
- Right to Restrict Processing: Request limited use of your data under certain circumstances.
- Right to Data Portability: Obtain your personal data in a structured, commonly-used format and transfer it to another provider.
- Right to Object: Object to our processing of your data for direct marketing or based on our legitimate interests.
- Right to Withdraw Consent: Withdraw any consent at any time, where our processing is based on your consent.
- Right to Lodge a Complaint: Lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe we have not handled your data in accordance with the law.
If you wish to exercise any of your rights, please contact us using our website’s contact form or postal address. We will respond to all legitimate requests within one month.
Data Security
We employ appropriate technical and organisational security measures to safeguard your personal information against accidental loss, misuse, alteration, or unauthorised access. Measures include secure servers, encryption, regular security assessments, and staff training.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in practices or law. Any significant changes will be posted on our website, and where appropriate, notified to you directly. Please check back regularly for the latest version.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please use the contact facilities on our website or send a written enquiry to our business address. We are committed to protecting your privacy and handling all concerns promptly and transparently.