Flower Delivery Gidea Park Privacy Policy
Introduction
This Privacy Policy explains how Flower Delivery Gidea Park collects, uses, and protects the personal data of our customers. We are committed to safeguarding your privacy and processing your personal data in a lawful, transparent, and fair manner. This policy applies to all individuals placing orders with Flower Delivery Gidea Park within Gidea Park and the surrounding districts, regardless of whether orders are made via our website, by phone, or in person.
What Data We Collect
When you place an order with Flower Delivery Gidea Park, we collect and process certain data necessary to fulfil your order and provide our services. The personal data we may collect includes:
- Identification information: Name, email address, and phone number
- Delivery information: Recipient’s name, address, delivery instructions, and contact number
- Order details: Products ordered, purchase history, order amounts, and payment method information (such as payment card type, but not full card numbers, which are processed by secure payment providers)
- Communications: Any messages or queries you send to us, including instructions, complaints, or compliments
- Technical information: Website usage data such as IP address, device information, browser type, and cookies (where applicable and consented to)
Lawful Basis for Processing Your Data
Under the General Data Protection Regulation (GDPR), we must have a lawful ground for processing your personal data. Our principal grounds are:
- Contractual necessity: Processing your data is necessary for us to fulfil our contract with you, such as delivering your order, processing payments, and providing customer support.
- Legitimate interests: We may process your data to improve our services, maintain security, or prevent fraud, where these interests do not override your privacy rights.
- Legal obligations: We are required by law to retain certain information for purposes such as tax, accounting, or complying with government authorities.
- Consent: With your clear consent, we may use your data for direct marketing (such as email newsletters). You have the right to withdraw your consent at any time.
How We Use Your Data
Your data is only used for the purposes for which it was collected. This includes:
- Processing and delivering your flower orders
- Communicating order and delivery updates
- Responding to customer enquiries and resolving complaints
- Maintaining our records and accounts
- Improving our website and customer experience
- Preventing and detecting fraud or misuse of our services
- Marketing (where consent has been given)
Disclosure to Data Processors and Third Parties
To provide our services, we may share your data with selected third-party processors who assist us. These include:
- Payment processors: To securely handle your card or payment details
- Delivery partners or couriers: To ensure safe and timely flower delivery
- IT and service providers: Such as website hosting or marketing platforms, under strict data processing agreements
All third-party processors act only on our instructions, process data securely, and are required to comply with GDPR. We do not sell your data to any other organisation.
Data Retention
We retain your personal data only as long as necessary to fulfil the purposes it was collected for, including satisfying any legal, accounting, or reporting requirements. Typically, we keep order and customer information for up to seven years after your last order, to comply with tax and accounting laws. For marketing and communication preferences, we retain consent records only as long as you remain subscribed. If you unsubscribe or exercise your right to erasure, we will remove your data unless retention is required by law.
Your Rights Under GDPR
Under the GDPR, you have robust rights over your personal data, including:
- Right to access: You may request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct or complete inaccurate or incomplete information.
- Right to erasure: Also known as the 'right to be forgotten', you can request deletion of your data under certain circumstances.
- Right to restrict processing: You can request that we limit processing of your data.
- Right to data portability: You can ask us to provide your data in a machine-readable format to you or another service provider.
- Right to object: You can object to our processing for direct marketing or other purposes based on legitimate interests.
- Right to withdraw consent: Where we rely on consent, you may withdraw it at any time without affecting prior processing.
- Right to lodge a complaint: You may contact the relevant data protection authority if you have concerns about our data practices.
Data Security
We take the protection of your personal data seriously. Appropriate technical and organisational measures are in place to prevent loss, misuse, unauthorised access, disclosure, alteration, or destruction of your data. These include encryption, secure payment processing, restricted staff access, and regular security reviews.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The most current version will always be available for review before you place an order. We recommend reviewing this policy periodically to stay informed about how we protect your data.
Contact and Further Information
If you have any questions about how your personal data is used or wish to exercise your rights, please contact us using the details provided on our website. We are committed to responding promptly and addressing your concerns transparently and fairly.
This Privacy Policy was last updated in June 2024.