GDPR-Compliant Privacy Policy for Customers
Introduction and Scope
This Privacy Policy explains how Flower Delivery Clerkenwell collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). It applies to all individuals and customers placing Flower Delivery Clerkenwell orders from Clerkenwell and surrounding districts. Our commitment is to handle your personal information transparently, securely, and lawfully.
What Data We Collect
When you order flowers or use our related services, we collect the following categories of personal data:
- Identity Data: Such as full name and title.
- Contact Data: Including delivery address, billing address, recipient address (if different), and, where provided, email address or telephone number for order communications.
- Order Details: Products ordered, delivery instructions, and order preferences.
- Payment Information: Details necessary for processing payments and refunds. Sensitive information such as card numbers is processed only via secure, compliant payment processors and is not stored by Flower Delivery Clerkenwell.
- Technical Information: IP address, browser type, time zone settings, and device information automatically collected during website use for security and analytics.
This information is essential for fulfilling your order, meeting our legal requirements, and improving our services.
Lawful Basis for Processing
Flower Delivery Clerkenwell processes your personal data on the following grounds:
- Performance of a Contract: We require your data to fulfil and deliver your orders, process payments, and provide customer service.
- Legal Obligation: Retaining certain transactional and accounting records is required by law for tax and regulatory compliance.
- Legitimate Interests: To operate and improve our service, prevent fraud, and ensure the security of our website and systems. We balance these interests with your rights and freedoms.
- Consent: In limited circumstances, such as sending marketing communications if you opt in, we rely on your explicit consent, which you can withdraw at any time.
How We Use Your Data
Your data is used solely for legitimate business purposes, including:
- Processing, confirming, and delivering your flower orders
- Managing payments, refunds, and invoices
- Handling customer queries and support requests
- Complying with legal and regulatory obligations
- Analysing trends and improving our services (using aggregated or anonymised data wherever possible)
- Sending occasional customer updates or offers, subject to your consent choices
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes outlined above, including satisfying any legal, accounting, or reporting requirements. Generally:
- Order and transaction records: retained for up to 7 years, as required by tax authorities.
- Customer support correspondence: retained up to 3 years after the order for quality assurance.
- Marketing preferences and consent: maintained until you withdraw consent or request data deletion.
After the retention period, your personal data will be securely deleted or anonymised.
Third-Party Processors and Data Sharing
In order to operate effectively, we share your data with trusted third-party service providers who act as data processors on our behalf. These include:
- Payment Processors: To securely handle and verify your payment information, subject to PCI DSS compliance.
- Website Hosting and IT Providers: For secure operation and maintenance of our online platform.
- Delivery Partners: To ensure successful delivery of your flowers in Clerkenwell and the surrounding areas.
- Professional Advisors: Such as accountants or legal advisors, when required for compliance and auditing.
All processors are contractually required to process your data only as instructed, protect its security, and uphold GDPR standards. Your data will not be sold and is not transferred outside the United Kingdom or the European Economic Area (EEA) without lawful safeguards.
Your Rights As a Data Subject
You have specific rights regarding your personal data under the GDPR, including:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any incomplete or inaccurate data.
- Right to Erasure ("Right to Be Forgotten"): Request deletion of your personal data, unless we have another lawful basis to retain it (e.g., legal obligations).
- Right to Restrict Processing: Ask us to suspend processing of your data under certain circumstances.
- Right to Data Portability: Receive your personal data in a structured, commonly used format and transfer it to another controller.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where we rely on consent, you may withdraw your consent at any time.
To exercise your rights, please contact us using the information provided in your order confirmation or through our official website contact form. We will respond within the legally required timeframe and may request proof of identity for security.
Data Security Measures
We employ a combination of organisational and technical measures to protect your data from unauthorised access, alteration, loss, or disclosure. These include secure data storage, user access controls, encryption of sensitive information, regular security reviews, and staff training in data protection.
Updates to this Policy
We may update this Privacy Policy periodically to reflect changes in legislation, our data practices, or service offerings. If you place an order after any update, the revised policy will apply. We encourage you to check this page regularly for the latest information.
Contact and Complaints
If you have any questions or concerns regarding this Privacy Policy or your data, please use the contact options provided on our website. If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.
This Privacy Policy is effective as of June 2024 and applies to all Flower Delivery Clerkenwell customers in Clerkenwell and surrounding districts.