Privacy Policy – Flower Delivery Blackheath
Introduction
This Privacy Policy explains how Flower Delivery Blackheath collects, uses, discloses, and safeguards your personal data when you place orders with us in Blackheath and surrounding districts. We are committed to ensuring that your privacy is protected and that we comply with the General Data Protection Regulation (EU) 2016/679 (GDPR) and relevant UK data protection laws. This policy applies to anyone who places an order with Flower Delivery Blackheath, whether online, by phone, or in person, for delivery in Blackheath or nearby areas.
What Data We Collect
To provide our flower delivery services efficiently and fulfil your orders, we may collect and process the following categories of personal data:
- Contact Information: Your name, delivery address, billing address, email address, and telephone number.
- Order Details: Details of the products you order, special instructions, card messages, and delivery details.
- Payment Information: Payment transaction details (such as payment card type, payment status, and billing address). We do not store full payment card details; such data is processed securely by our trusted payment processors.
- Recipient’s Information: Name, delivery address, and contact information for recipients if you are sending flowers to someone else.
- Communications: Records of your correspondence with us, including inquiries, order updates, and customer feedback.
- Technical Information: When you visit our website, we may collect data such as IP address, browser type, device information, and cookies (please refer to our Cookie Policy for more details).
Lawful Basis for Processing Data
We process your personal data only where there is a lawful basis as set out under GDPR. The primary lawful bases relevant to our activities are:
- Contractual Necessity: Processing is necessary to enter into or carry out the contract with you (e.g., to fulfil your flower order).
- Legal Obligations: To meet our legal duties, such as tax and accounting requirements.
- Legitimate Interests: For purposes such as improving our services, internal administration, fraud prevention, and direct marketing (in accordance with your preferences).
- Consent: Where you provide clear consent (for example, to receive marketing emails), processing is based on your explicit consent. You can withdraw this consent at any time.
How We Use Your Data
We use the personal data we collect for the following purposes:
- To process and deliver your orders accurately and efficiently.
- To contact you with updates about your order or respond to your requests and inquiries.
- To send recipient notifications and make sure deliveries are successfully completed.
- For administrative purposes such as auditing, billing, and record keeping.
- To comply with applicable legal and regulatory requirements.
- To personalise your experience with us and improve our services.
- To send you promotional messages or service updates, if you have consented or if we have a legitimate interest and it is lawful to do so.
Data Retention
We retain your personal data only as long as necessary for the purposes for which it was collected. Typically, we retain order and transaction data for up to seven years to comply with tax and contractual obligations. Where data is processed on the basis of your consent (for instance, marketing information), we retain it until you withdraw that consent or request erasure. When personal data is no longer needed, we securely delete or anonymise it. We regularly review our retention periods in line with legal and business requirements.
Processors and Data Sharing
To deliver our services efficiently, we use trusted third-party processors who process data on our behalf. These include:
- Payment Processors: To securely process payment transactions. These companies are PCI DSS compliant.
- IT Service Providers: For web and database hosting, customer relationship management, and order dispatch systems.
- Delivery Partners: To ensure timely and accurate delivery of your orders in Blackheath and surrounding districts.
All processors are contracted to handle your data with strict confidentiality, security, and in line with regulatory requirements. We may also need to share data with regulatory bodies if required by law. We do not sell or rent your personal information to third parties.
User Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You have the right to correct inaccurate or incomplete information.
- Right to Erasure: You can request deletion of your personal data where there is no justified reason for us to retain it.
- Right to Restrict Processing: You may ask us to restrict the processing of your personal data in certain circumstances.
- Right to Data Portability: You have the right to receive your data in a portable format and transmit it to another controller.
- Right to Object: You can object to certain types of processing, including direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you can withdraw your consent at any time.
To exercise any of these rights or if you have concerns about how we handle your data, please contact us using the details provided on our website or through your usual communication channel with Flower Delivery Blackheath.
Data Security
Protecting your personal data is important to us. We implement appropriate organisational and technical measures to safeguard your information, including encryption, secure storage solutions, and restricted access protocols. Despite these measures, please be aware that the transmission of data over the internet is not completely secure. We strive to protect your data, but cannot guarantee absolute security.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any changes will be posted on this page and will take effect upon publication unless otherwise stated.
Contact and Complaints
If you have any questions, concerns or complaints about this Privacy Policy or our processing of your personal data, please contact us through the methods provided on our website. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your rights have been infringed.