Flower Delivery Surrey Quays Privacy Policy
Introduction
This Privacy Policy sets out how Flower Delivery Surrey Quays (“we”, “us”, or “our”) manages your personal data when you place orders with us from Surrey Quays or nearby districts. We are committed to respecting your privacy and protecting your personal data in accordance with the UK General Data Protection Regulation (“GDPR”). This policy explains what data we collect, the lawful basis for processing, how long data is kept, who processes it, and your rights as a data subject.
Scope of This Privacy Policy
This Privacy Policy applies to all customers who place flower delivery orders with Flower Delivery Surrey Quays, whether through our website, by phone, in person, or via other ordering channels, and who request delivery in Surrey Quays and surrounding areas. By placing an order or interacting with our services, you are agreeing to the terms described here.
What Personal Data We Collect
We collect only data that is necessary to process and fulfill your flower delivery orders and to provide customer service. The categories of personal data we may collect include:
- Contact Information: such as your name, address, delivery addresses, telephone number, and any other means of contact you provide.
- Order Information: details about the flowers or gifts ordered, card messages, delivery instructions, and payment method (note: we do not store full payment card details).
- Recipient Information: if you order for someone else, their name, delivery address, and contact details, as necessary for delivery.
- Communication Data: your communications with us, including enquiries, feedback, and complaints (in writing or by phone).
- Technical Data: your IP address, browser type, and usage data collected via cookies or analytics tools on our website.
We do not intentionally collect special categories of personal data (such as health information) through our standard ordering process.
Lawful Basis for Processing Personal Data
We process your personal data on several lawful bases under the GDPR:
- Contractual Necessity: Most data is processed as it is necessary for us to fulfil our contract with you – namely, to process, dispatch, and deliver your order, and to communicate with you about the order.
- Legal Obligations: We may be required by law to retain and provide records to the relevant authorities, e.g., for tax purposes.
- Legitimate Interests: We may use your data to improve our services and customer experience or to prevent fraud. We ensure such uses do not override your fundamental rights.
- Consent: For some purposes (such as marketing messages), we may ask for your explicit consent. You can withdraw your consent at any time, without affecting the lawfulness of prior processing.
Data Retention Periods
We retain personal data only as long as necessary for the purposes for which it was collected, or as required by law. In general:
- Order details and contact information are retained for a period of up to 7 years to comply with accounting and tax regulations.
- Data collected for marketing purposes will be retained until you withdraw your consent or unsubscribe from communications.
- Technical data and analytics are kept for a maximum of 2 years from the date of collection.
After these periods, personal data is securely deleted, anonymised, or otherwise rendered inaccessible.
Personal Data Processors and Sharing
We use trusted third-party service providers (data processors) to help operate our business and deliver your orders. These processors include:
- Payment processing companies
- Delivery and courier services
- IT hosting providers
- Website analytics platforms
All processors are selected according to strict criteria, required to process your data only for specified purposes, and to implement adequate data protection and security measures. Your personal data will not be sold or shared with third parties for their own marketing purposes.
We may disclose personal data if required by law, regulation, court order, or to protect our legal rights, property, or safety.
International Transfers
Your personal data is stored and processed within the United Kingdom or the European Economic Area (EEA) wherever possible. Should it be necessary to transfer data outside the UK or EEA (for example, if a processor’s servers are located abroad), we will ensure appropriate safeguards are in place to protect your privacy rights, as required by the GDPR.
Your Data Protection Rights
Under the GDPR, you have various rights regarding your personal data, including:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Ask us to correct any inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data where there is no compelling reason for its continued processing.
- Right to Restrict Processing: Ask us to restrict or limit processing in certain cases.
- Right to Data Portability: Request transfer of your data to you or another organization in a structured, commonly used format.
- Right to Object: Object to data processing based on our legitimate interests, or to receiving marketing communications.
- Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time.
To exercise your rights, please contact us using the contact details provided in your order confirmations or on our website. To protect your privacy, we may require you to verify your identity before processing your request.
Data Security
We take appropriate technical and organisational measures to safeguard your personal data from unauthorized access, alteration, disclosure, or destruction. This includes secure servers, encryption, and regular staff training on data protection. However, as with all online transactions, we cannot guarantee absolute security of data transmitted via the Internet.
Changes to This Privacy Policy
We review this Privacy Policy periodically and may update it as required by law or to reflect changes in how we process personal data. Any updates will be published on our website. Please check back regularly for the most current version.
Contact Us
If you have questions about this Privacy Policy or your personal data, please use the contact details we provide in your order confirmations or on our website. We are committed to addressing your enquiries promptly and respectfully, including resolving any concerns about your data privacy.
