Flower Delivery Kentish Town Privacy Policy
Scope and Applicability
This Privacy Policy outlines how Flower Delivery Kentish Town manages, collects, stores, and processes personal data as defined under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. It applies to all customers placing orders with Flower Delivery Kentish Town from Kentish Town and the surrounding districts, covering all interactions, both online and offline, related to our flower delivery services.
Personal Data We Collect
When you use our services, we may collect the following categories of personal data:
- Identification Information: Name, title, and contact details such as postal address and telephone number.
- Order Information: Details about your flower orders, delivery instructions, recipient names and addresses, and special messages as part of your delivery request.
- Payment Details: Information necessary for transaction processing, such as the last four digits of your payment card (full payment data is handled by third-party processors, not stored by us).
- Communication Records: Notes of your interactions with us, such as order confirmations, inquiries, and feedback.
- Technical Data: IP address, device type, browser type and version, and cookie information when you use our website.
Lawful Basis for Processing
We ensure all processing of your personal data is conducted under at least one of the lawful bases set out by the GDPR:
- Performance of a Contract: The majority of the data we collect is necessary to fulfil your flower order and delivery requests.
- Legal Obligation: In certain circumstances, we are obliged to retain and disclose specific data for legal and regulatory reasons, such as the prevention of fraud or compliance with tax laws.
- Legitimate Interests: To improve our services, ensure the safety and security of our website, and respond to your enquiries, we may process your data as part of our legitimate business operations, ensuring such interests do not override your fundamental rights.
- Consent: We may ask for your explicit consent in scenarios where it is required by law, such as for marketing communications.
How We Use Personal Data
Your personal data is used for the following purposes:
- To process flower delivery orders and manage customer accounts.
- To arrange for delivery, including contacting you if necessary regarding your order.
- To process payments and issue invoices or receipts.
- To respond to your queries and provide customer support.
- To improve the functionality and security of our website and services.
- To fulfil obligations under applicable laws and regulations.
- For internal record keeping and management of business operations.
Data Retention
Your personal information will only be retained for as long as necessary to fulfil the purpose for which it was collected, including compliance with legal, accounting, or reporting requirements. Generally, for customer and order records, we keep data for up to six years after your last order, unless a shorter or longer retention period is required by law. Once your data is no longer necessary, it will be securely deleted or anonymised.
Data Processors and Third Parties
In order to provide efficient and reliable services, we may engage with selected third-party processors that manage certain operations on our behalf. These may include:
- Payment processing providers (for handling transactions securely).
- Certain IT and cloud storage providers (for website operation and data hosting).
- Couriers or delivery partners (to ensure your orders reach the correct destination).
All data processors acting on our behalf are contractually obliged to process your data in accordance with this policy, following GDPR requirements and maintaining the security and confidentiality of your personal information. We do not sell or rent your personal data to any third parties.
Security Measures
We implement stringent security measures to protect your personal data from unauthorised access, disclosure, alteration, or destruction. This includes the use of encrypted connections (SSL), regular security reviews, restricted access to data, and staff training on data protection responsibilities.
Your Rights Under GDPR
You have a series of rights concerning your personal data under the GDPR, including:
- Right to Access: You can request access to the personal data we hold about you.
- Right to Rectification: You have the right to have incomplete or inaccurate information corrected.
- Right to Erasure: In some cases, you may request that your data be deleted.
- Right to Restrict Processing: You can ask us to restrict the processing of your personal data in certain conditions.
- Right to Data Portability: You can request a copy of your data in a structured, commonly-used electronic format.
- Right to Object: You may object to the processing of your data in certain circumstances, particularly where processing is based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe your rights have been violated.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in laws, regulations, or our practices. Any changes will be made available through our official communication channels and on our website. We encourage customers to review this policy regularly.
Contact Information
If you require further information regarding this Privacy Policy, want to exercise your rights, or have any questions about how we handle your data, please reach out to us via our customer service channels. All privacy-related requests will be handled in accordance with applicable law and responded to promptly.