Privacy Policy for Customers Ordering from Flower Delivery West Harrow
Introduction
This Privacy Policy explains how Flower Delivery West Harrow (“we”, “our” or “us”) collects, uses, stores, and protects the personal data of customers placing flower delivery orders from West Harrow and surrounding districts. Protecting your privacy is paramount to us, and we manage your personal data in full compliance with the General Data Protection Regulation (GDPR) and applicable UK data protection laws. This policy applies to all customers who interact with us regarding flower delivery services within the specified areas.
Personal Data We Collect
Depending on how you interact with us, we collect the following types of personal data:
- Identity and Contact Data: Name, delivery address, billing address, recipient name (if different), phone number, and order-related email address (if provided).
- Order and Transaction Details: Details of the flowers or products ordered, purchase date, payment status, and any notes or instructions provided.
- Payment Data: Payment card details (processed securely via trusted payment processors; we do not store your card details on our servers), payment method, transaction records.
- Device and Usage Data: IP address, browser type, devices used to access our website, and usage information (cookies and analytics where consented).
- Correspondence: Records of communications with customer service (by phone, written message, or in-person, as applicable).
Lawful Basis for Processing Your Data
Under the GDPR, we must have a legal basis to collect and use your personal data. These include:
- Contractual Necessity: Most data processing is necessary for us to enter into and perform our contract with you, such as processing your flower delivery orders, accepting payment, and fulfilling your purchases.
- Legal Obligations: We retain records and conduct certain processing to meet statutory or legal requirements (e.g., tax, fraud prevention).
- Legitimate Interests: We may process your data for our legitimate interests in providing and improving our services, except where these interests are overridden by your fundamental rights and freedoms.
- Consent: We rely on consent for certain types of communications, such as marketing or the use of cookies and analytics. Where consent is required, you will be asked explicitly.
How We Use Your Data
Your personal data is used for the following purposes:
- To process and deliver your orders and manage payments.
- To communicate with you about your order status, delivery, and any changes or updates.
- To respond to your customer service requests or enquiries.
- For internal record-keeping and to comply with legal requirements.
- To improve the quality, functionality, and security of our services and website.
- If consented, to send you marketing communications regarding offers or new products that may be of interest to you.
Retention of Your Data
Your personal data is retained only for as long as necessary to fulfill the purposes outlined in this policy, including any legal or accounting requirements. Typically, this means:
- Order and transaction data: Held for up to seven years to meet accounting and regulatory obligations.
- Marketing list data: Until you withdraw consent or unsubscribe.
- Correspondence data: Up to two years after the resolution of your enquiry or complaint.
- Technical/analytics data: As specified by the relevant cookies or analytics provider or until you opt out.
Once the retention period is reached, your data will be securely deleted or anonymised.
Data Processors and Third Parties
To deliver our services effectively, we sometimes share your personal data with trusted third-party service providers (‘processors’) who assist in processing your order. These include:
- Payment processing companies: to securely handle transactions.
- Delivery partners: to ensure your flowers arrive at the correct address and on time.
- IT and website support providers: for hosting, detecting security incidents, and maintaining our digital infrastructure.
- Accountants or legal advisors: where required for compliance and auditing.
All such processors are subject to contractual obligations under the GDPR to process your personal data only according to our instructions and to maintain appropriate security measures. Your data is not sold or shared for third-party marketing.
International Data Transfers
Generally, your data is processed and stored within the UK or the European Economic Area (EEA). In the rare case that data must be transferred outside the UK or EEA, we ensure there are adequate safeguards in place as required by law.
Your Rights Under the GDPR
You have the following rights regarding your personal data:
- Access: You can request a copy of the personal data we hold about you.
- Rectification: You have the right to have inaccurate or incomplete data corrected.
- Erasure: You can request deletion of your data where it is no longer necessary or if you withdraw consent (subject to legal retention requirements).
- Restriction: You may request restriction of processing in certain circumstances.
- Objection: You can object to processing based on legitimate interests or to receiving marketing communications at any time.
- Portability: You may request that we provide your personal data in a machine-readable format to another service provider where technically feasible.
- Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time.
Security of Your Data
We implement appropriate organisational and technical security measures to protect your data against loss, misuse, unauthorised access, disclosure, alteration, or destruction. These safeguards include secure servers, encryption, and access controls.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal or regulatory requirements, our practices, or our services. If significant changes are made, we will notify customers by posting a prominent notice on our website or with your next order confirmation. The latest version will always be available for you to review before placing an order.
Contacting Us
If you have any questions about this policy, your rights, or how your data is handled, please contact our customer service team through the contact options made available to you on our website or at the point of sale. We are committed to ensuring your privacy and will respond to all data protection queries and requests in accordance with applicable laws and best practices.