Flower Delivery White City Privacy Policy
Introduction
This Privacy Policy explains how Flower Delivery White City ("we", "us", or "our") collects, uses, protects, and manages your personal information when you place an order with us. Compliance with the General Data Protection Regulation (GDPR) is central to this policy. This policy applies to all customers in White City and the surrounding districts who use our flower delivery services.
What Data We Collect
To process your orders and provide the best possible service, Flower Delivery White City may collect the following forms of personal data:
- Identity Data: Full name, delivery recipient’s name, and title.
- Contact Data: Delivery address, billing address, phone number, and occasionally email address.
- Order Data: Details of flower selections, orders you place, and delivery instructions.
- Payment Data: Payment method and transaction details; payment card details are processed directly by our payment processors and are not stored on our servers.
- Usage Data: Information about how you interact with our website (such as page visits and interactions), collected via cookies and analytics tools.
The Lawful Basis for Data Processing
Under the GDPR, we are required to have a lawful basis for collecting and using your personal data. Our lawful bases include:
- Contractual Necessity: We process your data as required to fulfill your flower delivery order and to provide customer care before, during, and after the transaction.
- Legitimate Interests: Certain processing activities, such as internal analytics and service improvements, may be based on our legitimate business interests, providing these do not override your rights and interests.
- Legal Obligations: We may be obliged to process your data to comply with legal and regulatory requirements.
- Consent: Where required (such as for marketing communications), we will request your explicit consent, which you may withdraw at any time.
How We Use Your Data
We use your personal data for the following purposes:
- To process and deliver your orders, including verifying your identity and arranging deliveries.
- To communicate with you regarding your purchase, address any enquiries or complaints, and provide customer support.
- To process payments securely via trusted payment processors.
- To improve our website’s functionality, user experience, and services, using aggregated and anonymised data where possible.
- If you have provided consent, to send you service updates and special offers relevant to our business.
Data Retention Policy
We retain your personal data only for as long as is necessary to fulfill the purposes for which we collected it, including for purposes of satisfying any legal, accounting, or reporting requirements. The typical retention periods are:
- Order and Transaction Data: Retained for up to six years from the date of transaction for tax and contractual reasons.
- Marketing Data: Retained until you withdraw consent or opt out of receiving marketing communications.
- Website Analytics Data: Retained in anonymised form for up to two years to assess and improve website usage.
When we no longer need your data, it is securely deleted or anonymised.
Data Processors and Third Parties
We may share your data with trusted third-party service providers who act as data processors on our behalf to enable the effective delivery of our services:
- Payment Service Providers: To securely process your payments.
- Delivery Partners: To manage the physical delivery of your order.
- IT and Hosting Providers: To securely host and maintain our website and business systems.
- Analytics Providers: To analyse user behaviour and improve our digital service.
All third-party service providers are contractually obliged to protect your data, use it only for the specified purposes, and comply with GDPR obligations. We do not sell or trade your personal information to any third parties for marketing or other commercial purposes.
International Data Transfers
Your personal data is generally processed within the United Kingdom or the European Economic Area (EEA). If, due to our legitimate business operations, your data must be processed outside the EEA, we ensure it is subject to equivalent levels of protection by adhering to legal safeguards such as Standard Contractual Clauses.
Your Rights Under the GDPR
Under the GDPR, you have a suite of rights regarding your personal data. These include:
- Right to Access: You can request access to, and a copy of, your personal data held by us.
- Right to Rectification: You can ask us to correct or complete your personal data if it is inaccurate or incomplete.
- Right to Erasure ("Right to be Forgotten"): In certain circumstances, you can request the deletion of your data.
- Right to Restriction: You can request that we suspend the processing of your data in specific scenarios.
- Right to Data Portability: You may request to receive your data in a structured, commonly used format or transfer it to another service provider.
- Right to Object: You can object to certain types of processing, such as direct marketing.
- Right to Withdraw Consent: Where your data has been processed based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us using the details provided on our website. We may require you to verify your identity before actioning your request.
Data Security
We implement robust technical and organisational measures to protect your data from loss, misuse, unauthorised access, disclosure, or alteration. These measures include encryption, secure storage, regular security reviews, and staff training on privacy protocols.
Children’s Privacy
Our services are not directed at children under 16. If we become aware that personal information has been collected from a child, we will take appropriate steps to remove that information from our records.
Changes to this Privacy Policy
From time to time, we may update this Privacy Policy to reflect changes to our operations or regulatory requirements. We encourage you to review this policy periodically. The most recent version will always be available on our website with an updated effective date.
Contact and Complaints
If you have questions, concerns, or wish to exercise your privacy rights relating to your data, please contact us using our published contact details. If you believe your data privacy rights have been violated, you may also lodge a complaint with the Information Commissioner’s Office (ICO) or your local supervisory authority.