Flower Delivery Stepney Privacy Policy
Introduction
This Privacy Policy outlines how Flower Delivery Stepney ("we", "our", or "us") collects, uses, safeguards, and shares your personal data when you place an order with us. This policy applies to all customers who order flower delivery services from Stepney and surrounding districts. We are committed to ensuring your privacy and handling your data in compliance with the UK General Data Protection Regulation (GDPR).
What Data We Collect
To provide our services, we may collect the following categories of personal information:
- Identity Data: Your full name, title, and contact details (e.g., phone number, postal address).
- Recipient Data: Name, address, and phone number of the designated recipient of your flower order.
- Order and Transaction Data: Purchase history, order contents, payment confirmations (note: we do not process or store full payment card details; these are handled directly by our trusted payment processors).
- Communication Data: Records of your communications with us, including messages regarding order inquiries, delivery details, or customer support requests.
- Technical Data: Limited website usage data such as IP address, browser type, and access times to improve our website performance and security.
Lawful Bases for Processing Your Data
In accordance with GDPR, we process your personal data lawfully based on one or more of the following grounds:
- Contractual Necessity: Processing is required to perform the contract between you and Flower Delivery Stepney, specifically to fulfill your orders and deliver our services.
- Legal Obligation: We may process your data to comply with legal or regulatory requirements, such as tax or accounting obligations.
- Legitimate Interests: We may process data where it is necessary for our legitimate business interests (e.g., to improve customer service, enhance website security, or manage business operations), provided those interests are not overridden by your rights and interests.
- Consent: In certain cases where we ask for consent (for instance, for marketing communications), you have the right to withdraw that consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- To process and manage your flower delivery orders.
- To communicate with you regarding your order status and delivery.
- To respond to your enquiries or requests for support.
- To improve our products, services, and customer experience.
- To meet our legal and regulatory obligations.
- For internal record-keeping and administrative purposes.
Data Retention
We retain your personal data only as long as is necessary to fulfill the purposes for which it was collected, including for satisfying legal, accounting, and reporting requirements. In practice, we typically retain:
- Order and transaction records for up to 7 years to comply with tax and regulatory requirements.
- Communications data for up to 2 years to respond to queries and manage service improvements.
- Technical data (e.g., IP addresses) is stored for a limited period, generally no longer than 1 year, unless required for security purposes.
When your data is no longer required, it will be securely deleted or anonymised.
Data Processors and Third Parties
In providing our services, we may share your data with trusted third-party service providers ("processors") who act on our behalf and under our instructions. These may include:
- Payment processing providers who securely handle payment transactions.
- Courier and delivery services to ensure fulfilment of your order.
- IT service providers offering website hosting, data storage, and security support.
All processors are required to adhere to GDPR standards and maintain the confidentiality and security of your personal data. We do not sell or rent your personal information to third parties for marketing purposes.
International Transfers
Your personal information is generally stored and processed within the UK and European Economic Area (EEA). Where transfers outside these regions occur, we ensure adequate safeguards are in place as prescribed by GDPR.
Security Measures
We are committed to protecting your personal data and have implemented suitable technical and organisational security measures to prevent unauthorised access, disclosure, alteration, or loss of your data. These measures include secure data storage, limited access to personal data, staff training, and regular security assessments.
Your Data Protection Rights
Subject to legal limitations, you have the following rights regarding your personal data under the GDPR:
- Right of Access: You can request confirmation of whether we hold personal data about you and ask for a copy of that data.
- Right to Rectification: You can request correction of inaccurate or incomplete personal data.
- Right to Erasure: You can request deletion of your data in certain circumstances (also called the "right to be forgotten").
- Right to Restriction: You can request we restrict the processing of your data under certain conditions.
- Right to Data Portability: You can request transfer of your data to another provider, where applicable.
- Right to Object: You can object to processing of your data where we are relying on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time.
To exercise your rights, you may submit a written request. Please describe your request clearly and provide sufficient information to identify yourself and your order(s). We will respond within the timeframe required by law, and may request further verification to protect your privacy.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our business practices or legal requirements. The latest version will always be posted on our website. We encourage you to review this policy periodically to stay informed of how we protect your privacy.
Contact and Complaints
If you have questions about this Privacy Policy or concerns about how your data has been handled, please contact us through the communication channels provided on our website. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your data is not being handled in accordance with the law.