Privacy Policy – GDPR Compliant Practices at Flowers Cambridge Heath
Introduction
This Privacy Policy outlines how Flowers Cambridge Heath (“we”, “us”, “our”) collects, processes, and stores your personal data in accordance with the General Data Protection Regulation (GDPR) and all applicable data protection legislation. This policy applies to all customers placing orders with Flowers Cambridge Heath within Cambridge Heath and the surrounding districts.
Information We Collect
When you use our services to place orders for flowers, we collect the following types of data:
- Personal Identification Information: This includes your full name, delivery address, billing address, and order information.
- Contact Information: We collect your phone number and, where required, your postal details to process and fulfill your order.
- Transactional Information: Details of the products you order, your chosen delivery date, and payment references.
- Payment Data: Basic payment verification information may be gathered by our payment processors, as further detailed below. We do not directly store your card details on our servers.
- Correspondence: If you contact us, we may keep a record of communications to resolve queries or address issues relating to your order or our services.
Lawful Basis for Data Processing
Flowers Cambridge Heath relies on the following lawful bases for processing your personal data under the GDPR:
- Contractual Necessity: Most of the information we collect is required to fulfill our contract with you when you place an order. Without this information, we cannot process or deliver your order.
- Legal Obligation: In some circumstances, we are legally obliged to retain certain data, for example, for accounting and tax purposes.
- Legitimate Interests: We may use your information for our legitimate interests, such as improving our services, communication, handling queries, or updating you about your order status, provided that these interests are not overridden by your rights and freedoms.
- Consent: Where required by law, or if additional processing is conducted for marketing purposes, we will request your explicit consent.
How We Use Your Data
Your personal data may be used for the following purposes:
- Processing and fulfilling your flower order, including delivery to the specified address.
- Communicating with you about your order or updates associated with our services in Cambridge Heath and surrounding areas.
- Responding to queries and providing customer support.
- Retaining necessary records for accounting, auditing, and legal compliance.
- Improving and personalising your customer experience with us.
Data Retention
Flowers Cambridge Heath keeps your personal data only for as long as is necessary for the purposes for which it was collected, or as required by applicable laws. Typically, we retain order and transactional data for a period of six (6) years to comply with legal and accounting obligations. After this period, your information will be securely erased or anonymised so it can no longer be associated with you.
Processors and Data Sharing
To provide our services, we may use third-party service providers (“Processors”) who process data on our behalf. These include:
- Payment Processors: To securely process payments and prevent fraud, your payment information is handled by trusted payment service partners, who are themselves GDPR compliant and do not retain your card details beyond the transaction.
- Delivery Partners: We may share delivery details with local couriers or drivers to ensure your flower order reaches its recipient in Cambridge Heath and nearby areas.
- IT and Hosting Providers: Our website and data infrastructure are supported by third-party IT and data hosting companies with strict data security protocols in place.
All processors have contractual obligations to protect your data, not to use it for their own purposes, and to act only on our instructions. We do not sell, rent, or otherwise share your personal data with unaffiliated third parties for their own use.
User Rights under the GDPR
As a Flowers Cambridge Heath customer, you have a number of rights regarding your personal data, including:
- Right of Access: You can request details of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure: You can request the deletion of your data in certain circumstances, for instance if it’s no longer necessary for us to retain it or where you have withdrawn your consent.
- Right to Restrict Processing: You can request that we limit the processing of your data in some situations.
- Right to Data Portability: You can ask us to provide you with your data in a structured, commonly used format for your own purposes.
- Right to Object: You may object to certain types of processing, such as direct marketing or processing based on our legitimate interests.
- Right to Withdraw Consent: Where you have given consent to our processing, you have the right to withdraw it at any time, which will not affect the lawfulness of any processing carried out before withdrawal.
If you would like to exercise any of these rights, please contact us using the contact details available on our website. We may require confirmation of your identity before fulfilling your request. Requests are generally handled within one month, in keeping with legal requirements.
Data Security
We take the security of your data seriously. Appropriate security measures are employed to prevent personal data from being accidentally lost, used, accessed in an unauthorised way, altered, or disclosed. These include access controls, encryption where appropriate, and regular review of processing practices. In the unlikely event of a personal data breach, we have procedures in place to assess and mitigate risks, and to notify both users and relevant authorities where required by law.
International Data Transfers
Typically, your data is processed within the United Kingdom. If data were to be processed or transferred outside the UK or European Economic Area by any of our trusted processors, we ensure appropriate safeguards are in place to protect your personal data.
Changes to This Policy
This Privacy Policy may be updated to reflect changes in how we process your data or to comply with new legal requirements. We encourage you to review this policy periodically for any updates. Material changes will be clearly communicated to users where appropriate.
Contact and Complaints
If you have questions about this policy, concerns about your data, or wish to make a complaint, please use our website’s contact methods to get in touch. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) or relevant data protection authority in your jurisdiction.
Scope
This policy is applicable to all customers ordering from Flowers Cambridge Heath, whether for themselves or recipients in Cambridge Heath and the surrounding districts. By using our services, you acknowledge that you have read and understood this Privacy Policy.