Privacy Policy – Flower Delivery Catford
Introduction and Scope
This Privacy Policy describes how Flower Delivery Catford collects, uses, retains, and safeguards your personal information in compliance with the General Data Protection Regulation (GDPR) and applicable UK law. The policy applies to all customers placing orders with Flower Delivery Catford in Catford and neighbouring districts. By placing an order or interacting with our services, you acknowledge and accept the practices described within.
What Data We Collect
When you order flowers or engage with our services, we may collect and process the following types of information:
- Identity Data: Your full name and, where required, the recipient’s name.
- Contact Data: Address, delivery address, billing address, city, postcode, and contact telephone number.
- Order Details: Products and services ordered, delivery instructions, and other preferences linked to your order.
- Payment Information: Details necessary to process your payment, such as card type and transaction references. Please note, we do not store full credit or debit card numbers; this information is handled securely by our payment processors.
- Communications: Records of your correspondence with us, including order confirmations, requests, feedback, and any complaints.
- Technical Data: IP address, device information, browser type, and interaction with our website, collected via cookies and analytics tools for website security and service improvement.
Lawful Basis for Processing Data
Flower Delivery Catford processes personal data only where a lawful basis exists under GDPR:
- Contractual Necessity: Processing your information is necessary to fulfil your flower order or to take steps at your request prior to entering into a contract.
- Legal Obligation: We may process your data to comply with legal and regulatory requirements, such as tax or audit obligations.
- Legitimate Interests: We may process data to improve our services, safeguard against fraud, or respond to your queries. Such processing will always consider your rights and interests.
- Consent: For certain marketing communications, we will only process personal data where you have given clear consent, which can be withdrawn at any time.
How We Use Your Personal Data
Your personal data is used for the following purposes:
- Processing and fulfilling your flower delivery orders, including payment and delivery coordination.
- Communicating with you regarding your orders, questions, and customer support requests.
- Improving our services and tailoring customer experiences based on preferences and order history.
- Complying with applicable laws, regulations, and enforcement requests.
- Managing and protecting our website, systems, and business operations.
Data Retention
We retain personal information only for as long as necessary to fulfil the purposes we collected it for, including satisfying legal, accounting, or reporting requirements. Generally, we retain order and customer data for up to six years after the completion of a transaction, unless a longer retention period is required by law or for handling potential disputes. After these periods, data is securely deleted or anonymised.
Processors and Data Sharing
Flower Delivery Catford works with trusted third-party service providers ("processors") who assist with order processing, payment handling, delivery logistics, IT infrastructure, and website hosting. All processors are contractually bound to protect your personal data in accordance with GDPR and only process data under our instruction. We do not sell or share your data with unrelated third parties or for purposes unrelated to your order or our services unless required to do so by law.
Categories of processors may include:
- Payment processing platforms
- Delivery couriers and logistics partners
- Customer service and communication software providers
- IT and security support providers
Your Rights Under GDPR
As a data subject, you have the following rights under GDPR in relation to your personal data:
- Right of Access: You have the right to request access to personal data we hold about you.
- Right to Rectification: You may request correction of any inaccurate or incomplete data.
- Right to Erasure: You may request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Restrict Processing: You can ask us to restrict the use of your data in certain circumstances.
- Right to Data Portability: You have the right to receive your personal data in a structured, commonly used, and machine-readable format and to request transfer of that data to others where technically feasible.
- Right to Object: You may object to our processing of your data where processing is based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where we rely on your consent, you can withdraw it at any time. This will not affect data processed before withdrawal.
- The Right to Lodge a Complaint: If you have concerns about how your data is handled, you may contact the relevant supervisory authority in the UK.
Data Security
We have established appropriate technical and organisational safeguards to ensure your data is processed and stored securely and to prevent unauthorised access, disclosure, alteration, or loss. These include access controls, data minimisation practices, and regular security reviews.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes to our data practices or for legal reasons. Any significant changes will be communicated through our usual customer channels. This policy was last updated in June 2024.
Contact Us
If you have any questions regarding this Privacy Policy or wish to exercise any of your rights, please get in touch with our customer support team. We are committed to addressing your queries in a timely and transparent manner.