Privacy Policy for Flower Delivery Penge
Introduction
At Flower Delivery Penge, we are committed to protecting your personal information and respecting your privacy. This Privacy Policy explains how we collect, use, store, share, and secure your data when you place an order with us. It applies to all customers placing Flower Delivery Penge orders from Penge and surrounding districts. Our practices are designed to comply with the General Data Protection Regulation (GDPR) and all relevant UK data protection legislation.
Personal Data We Collect
To fulfill your flower order and provide a high-quality service, we collect different types of personal data when you interact with us:
- Contact Information: Your name, delivery address, email address, and phone number.
- Order Details: Products purchased, delivery date, recipient’s information (if different), and preferred delivery instructions.
- Payment Information: Details required to process your payment, such as transaction reference (please note, we do not store credit card numbers ourselves; these are handled securely by our payment processors).
- Correspondence: Any communications you send to us, such as inquiries, feedback, or requests.
- Website Usage Data: Limited technical information such as IP address, browser type, and device type to ensure site functionality and security. We do not use this for profiling or marketing without your consent.
Lawful Basis for Data Processing
We rely on several lawful bases under the GDPR for processing your personal data:
- Performance of a contract: We process your data as necessary to fulfill your flower delivery order and contractual obligations.
- Legitimate interests: For instance, to improve our products and services, maintain security, or handle customer service issues.
- Legal obligations: We may retain or disclose information if required to comply with applicable laws and regulations.
- Consent: Where we rely on your consent for other purposes, such as sending marketing communications, we will always provide you with an option to opt-in or out.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing and fulfilling your orders, including delivery and billing.
- Communicating with you about your order or any inquiries you make.
- Improving our website, products, and customer service.
- Preventing fraud and maintaining the security of our services.
- Meeting legal and regulatory requirements.
- Sending you marketing information if you have given explicit consent.
Data Retention Periods
We retain your personal data only as long as it is necessary for the purposes set out in this policy and as required for legal, accounting, or reporting purposes.
- Order and customer data are kept for up to six years for accounting and warranty purposes, in line with legal obligations.
- Marketing preferences are stored until you withdraw your consent.
- Technical and security logs are typically retained for up to one year unless needed for dispute resolution or security investigations.
Data Processors and Third Party Services
To operate our services efficiently and securely, we may share limited data with vetted third-party service providers ("processors") who act strictly on our instructions. These include:
- Payment processing providers for secure transaction handling.
- Courier and delivery companies to fulfill your order.
- IT service providers for website management, hosting, and customer support.
All processors are contractually required to protect your data and use it only for the agreed services. Your data is not shared with third parties for their own marketing purposes.
Your Rights Under the GDPR
Under the General Data Protection Regulation, you have clear and specific rights regarding your personal data:
- Access: The right to ask for a copy of the personal data we hold about you.
- Rectification: The right to request correction of inaccurate or incomplete data.
- Erasure: The right to ask us to delete your data in certain circumstances ("the right to be forgotten").
- Restriction: The right to ask us to halt processing your data in specific situations.
- Portability: The right to receive your data in a portable format and transmit it to another data controller.
- Objection: The right to object to processing in specific scenarios, such as direct marketing.
- Withdraw Consent: If we rely on your consent, you have the right to withdraw it at any time.
- Lodge a complaint: The right to complain to a supervisory authority if you believe your rights are infringed.
To exercise any of these rights, please contact us using the communication methods provided on our website or order documents.
Data Security and International Transfers
We store your data on secure servers located within the UK or European Economic Area. Where we use processors outside these areas, we ensure your data receives equivalent protection through standard contractual clauses or approved safeguards. We implement technical and organisational measures to safeguard your data against loss, misuse, unauthorised access, disclosure, alteration, or destruction.
Policy Updates
This Privacy Policy may be updated from time to time to reflect changes in legal requirements or our data processing practices. Any changes will be published on our website, and significant updates will be communicated to you where appropriate.
Contact and Queries
If you have any questions, concerns, or wish to exercise your data protection rights regarding this Privacy Policy, please get in touch using the contact details provided on our website or within your order confirmation. We are committed to responding promptly to all privacy-related queries.