Flower Delivery Woodford Privacy Policy
Introduction
At Flower Delivery Woodford, we are committed to protecting your privacy and personal data. This Privacy Policy sets out how we collect, use, store, and protect your information in accordance with the EU General Data Protection Regulation (GDPR). This policy applies to all customers who place orders with Flower Delivery Woodford from Woodford and surrounding districts. Please read this document carefully to understand how your data is handled.
What Data We Collect
When you place an order or interact with Flower Delivery Woodford, we collect various types of personal data to process your request and ensure a seamless delivery experience. The types of data we may collect include:
- Contact Information: such as your full name, delivery address, billing address, and postcode.
- Order Details: details about the products or flowers you order, including recipient details if you are sending to another person.
- Payment Information: payment card details or transaction references (note: we do not store full card details ourselves if the transaction is processed by a third-party payment processor).
- Communication Data: any correspondence you have with us, such as emails, order notes, or queries through our website contact forms.
- Technical Data: IP address, browser type, and information about how you interact with our website, collected through cookies and analytics tools (where applicable and in accordance with consent preferences).
Lawful Basis for Data Processing
We only process your personal data when we have a lawful reason to do so under GDPR. Our lawful bases include:
- Contract: Processing is necessary for fulfilling our contract with you (for example, to deliver your order).
- Legal Obligation: Processing may be required to comply with applicable laws and tax regulations.
- Legitimate Interests: We may process your data for legitimate business interests (such as improving our services), provided it does not override your interests or fundamental rights.
- Consent: Where you have provided clear consent for specific purposes (such as email marketing), you may withdraw this consent at any time.
How We Use Your Data
Your personal information may be used for the following purposes:
- Processing and fulfilling your flower delivery orders.
- Communicating with you regarding your order, delivery status, or queries.
- Managing payments and preventing fraud.
- Complying with legal and regulatory obligations.
- Improving our products, services, and customer experience.
- Sending you marketing communications (with your explicit consent).
Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes it was collected for, including to comply with legal, accounting, or reporting obligations. Our general data retention periods are:
- Order and transaction data: retained for a minimum of six years to meet tax and accounting requirements.
- Customer communication data: retained while your order is active and for up to two years thereafter.
- Marketing consent records: maintained as long as you are subscribed or until you withdraw consent.
After the retention period, we will securely delete or anonymize your personal data.
Processors and Third Parties
For the effective operation of our business, certain external partners and processors may have access to your data. These may include:
- Payment processors: Securely process your card transactions on our behalf.
- Delivery and courier services: To deliver your flowers to the designated address.
- IT and website service providers: Support and maintain our order management, website hosting, and customer communication.
- Professional advisors: Such as accountants or legal consultants to comply with statutory requirements.
Each processor acts in accordance with written contracts and is required to maintain GDPR-compliant security and data protection standards. We never sell your data to third parties.
User Rights Under GDPR
As a customer of Flower Delivery Woodford, you have the following rights in relation to your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request that inaccurate or incomplete data be corrected.
- Right to Erasure: Request deletion of your personal data in certain circumstances.
- Right to Restrict Processing: Ask us to suspend or limit the processing of your data.
- Right to Data Portability: Receive your personal data in a structured, commonly-used format and have it transmitted to another controller.
- Right to Object: Object to the processing of your data for direct marketing or where our legal basis is legitimate interests.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw this at any time.
To exercise these rights, you may contact us using the details provided on our website. We may require you to verify your identity before fulfilling your request. You also have the right to lodge a complaint with the UK Information Commissioner’s Office if you have any concerns about how your data has been handled.
Data Security
We implement appropriate technical and organisational measures to safeguard your personal data from unauthorised access, loss, alteration, or disclosure. These measures include secure server technology, encryption for payment data, restrictions on data access, and regular staff training on data protection.
Policy Updates
We may update this Privacy Policy to reflect changes in our practices or for legal or regulatory reasons. The most current version will always be available on our website, with the effective date indicated at the top. We encourage you to review this page regularly to stay informed of how we protect your information.
Contact, Queries, and Further Information
If you have any questions, concerns, or requests regarding this Privacy Policy or how we manage your personal data, please reach out via the contact options provided on our website. We are committed to addressing your concerns promptly and transparently.