Privacy Policy for Parsons Green Flower Delivery
Introduction
This Privacy Policy sets out how Flower Delivery Parsons Green ("we", "us", or "our") collects, uses, stores, and protects the personal data of all customers who place orders for flower delivery within Parsons Green and the surrounding districts. We are committed to safeguarding your privacy and ensuring compliance with applicable laws, including the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
Scope of This Policy
This Privacy Policy applies to our flower delivery services provided to customers in Parsons Green and adjacent districts. By placing an order, visiting our website, or otherwise engaging with our services, you acknowledge and agree to the data processing practices described herein.
What Data We Collect
In providing our flower delivery services, we may collect and process the following categories of personal data:
- Contact Information: Name, address, email address, and phone number of the customer and recipients.
- Order Details: Order contents, delivery instructions, requested delivery dates, and personal messages included with deliveries.
- Payment Information: Payment method, transaction number, and billing address (note: payment card details are processed securely by third-party payment processors and not stored by us).
- Account Information: If you choose to create an account, username, password, and related account preferences.
- Communication Records: Correspondence with our customer service, including queries, feedback, or complaints.
- Technical Data: IP address, device type, browser information, and usage data collected via cookies for website analytics and security.
Lawful Basis for Processing Your Data
We collect and process your personal data solely on the basis of one or more of the lawful grounds set out in Article 6 of the UK GDPR:
- Contractual Necessity: To process and deliver your flower orders and fulfil our contract with you.
- Legal Obligation: To comply with legal and regulatory requirements, such as accounting and tax obligations.
- Legitimate Interests: For our day-to-day business operations, such as improving our services, fraud prevention, and direct marketing relevant to your interactions with our company, provided your fundamental rights do not override these interests.
- Consent: Where you have expressly given us consent, for example, to receive marketing communications. You may withdraw consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- To process and deliver your flower orders to the designated recipients.
- To communicate with you regarding your orders, delivery updates, or service issues.
- To respond to your queries, requests, or complaints.
- To comply with legal record-keeping requirements.
- To enhance and optimise our service and customer experience.
- To send you direct marketing communications, if you have consented to receive them.
- To detect and prevent fraud and maintain the security of our services.
Who Processes Your Data (Processors)
To provide our services, we may share your data with trusted third-party processors who act strictly on our instructions. These may include:
- Payment Processors: Securely process online payments on our behalf; we do not store your payment card details.
- Delivery Partners: Couriers or delivery agents requiring access to recipient names, addresses, and relevant order details to fulfill your order.
- IT Service Providers: Companies that support and maintain our information systems and website hosting.
- Email & Communication Platforms: Secure platforms facilitating order confirmations and service notifications.
- Analytical and Security Services: Providers that assist in monitoring website traffic and enhancing system security.
All our processors are required to comply with this Privacy Policy, applicable data protection laws, and to keep your information secure.
Data Retention
We retain your personal data only as long as necessary to fulfil the purposes it was collected for, including providing services and satisfying legal, accounting, or reporting requirements. The retention periods are as follows:
- Order and Account Data: Retained for up to seven years to comply with tax and accounting regulations.
- Marketing Data: Retained until you withdraw your consent or unsubscribe.
- Technical Data: Typically retained for no longer than 18 months for analytical and security purposes.
Once no longer required, your data will be securely deleted or anonymised in accordance with industry best practices.
International Data Transfers
Your data is stored and processed within the United Kingdom or European Economic Area (EEA). If data must be transferred outside these regions (for example, to technical service providers), this will be done only with appropriate safeguards in place to ensure adequate data protection.
How We Protect Your Data
We implement organisational and technical measures to secure your personal data from loss, theft, unauthorised access, disclosure, or destruction. These include encryption, secure server infrastructure, access controls, and regular staff training on data privacy.
Your Data Rights
Under the UK GDPR, you have various rights in relation to your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data in certain circumstances.
- Right to Restrict Processing: Ask us to limit how your data is used.
- Right to Data Portability: Receive your data in a commonly used, machine-readable format and transfer it to another data controller, where feasible.
- Right to Object: Object to our processing of your data, particularly for direct marketing.
- Right to Withdraw Consent: If processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.
To exercise your rights or for questions about how your data is processed, please contact us using the details provided on our website or by post. We may need to verify your identity before fulfilling your request.
Policy Updates
We may review and update this Privacy Policy from time to time to reflect changes in legal requirements or our business practices. The most current version will always be available on our website. We encourage you to review this policy regularly to stay informed about how we protect your data.
Contact and Complaints
If you have concerns about how we handle your data, you are entitled to lodge a complaint with the UK Information Commissioner's Office (ICO), the independent authority overseeing data protection in the UK.
We value your privacy and are committed to addressing any concerns promptly and transparently.