Privacy Policy for Customers of Flower Delivery Harrow
Introduction
This Privacy Policy explains how Flower Delivery Harrow ("we", "us", "our") collects, uses, stores, and safeguards your personal information when you place an order for flower delivery services in Harrow and the surrounding districts. We are committed to ensuring that your privacy is protected in compliance with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
Scope
This Privacy Policy applies to all customers who place flower delivery orders through Flower Delivery Harrow for delivery within Harrow and its surrounding districts. By using our services, you agree to the terms outlined below regarding the collection and processing of your personal data.
What Data We Collect
We collect different types of personal data to fulfil your order and provide you with excellent service. The types of data we may collect include:
- Identity Data: Name, surname
- Contact Data: Billing and delivery addresses, phone numbers
- Order Data: Order details such as types of flowers, messages for recipients, order number, delivery instructions
- Payment Data: Payment card details or payment system transaction references (note: full card details are never retained by us locally and are processed through secure third-party payment processors)
- Technical Data: IP address, browser type, device information, and usage data (when ordering via our website)
- Communication Data: Records of your communication with us, including customer queries and feedback
Lawful Basis for Processing Personal Data
Under GDPR, we must have a lawful basis to process your personal data. The lawful bases for our data processing include:
- Contractual Necessity: We process your personal data to fulfill our contract with you and deliver ordered goods and services.
- Legal Obligation: We may need to process your data to comply with legal requirements, such as tax, accounting, and regulatory obligations.
- Legitimate Interests: We may process data to improve our products and services, manage our business operations, prevent fraud, and respond to your inquiries, provided these interests are not overridden by your rights and freedoms.
- Consent: For certain activities, such as sending marketing materials, we will only process your data with your explicit consent. You can withdraw this consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing and delivering your flower orders
- Communicating with you about your order or queries
- Processing payments securely
- Improving our products and customer experience
- Maintaining business and financial records
- Complying with applicable legal obligations
- Sending marketing communications, offers, or updates when you have given consent
Data Retention
Your personal data will be retained only for as long as necessary to fulfill the purposes it was collected for, including legal, accounting, or reporting requirements. Standard retention periods are:
- Order and transaction data: Retained for up to 7 years in accordance with tax and accounting regulations.
- Communication and support records: Retained for up to 3 years after your last interaction with us.
- Marketing preferences and consent records: Retained unless and until you withdraw consent.
- Technical and usage data: Retained for up to 2 years to improve our services and maintain website security.
Once the retention period expires, your personal data will be securely deleted or anonymized.
Data Processors and Third Parties
We may use third-party service providers ("processors") to support our business operations, including:
- Payment processors: For secure handling of payments
- Delivery partners: For fulfilling delivery of your orders
- IT service providers: For hosting and maintaining our website and systems
- Accountants and legal consultants: For regulatory compliance
All our processors are contractually obligated to handle your data securely and only in accordance with our instructions. We do not sell or rent your personal data to any third party. Personal information may be transferred outside the UK or EEA only where adequate safeguards are in place as required by law.
Your Data Protection Rights
You have the following rights as a data subject under the GDPR:
- Right of Access: Request a copy of your personal data held by us.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data where there is no valid reason for its continued processing.
- Right to Restriction: Request restriction of processing in certain circumstances.
- Right to Data Portability: Request a copy of your data in a machine-readable format for transfer to another provider.
- Right to Object: Object to processing of your data, particularly for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you have the right to withdraw it at any time.
To exercise these rights or for any queries about your data, please contact us using the details provided on our website. We will respond within one month of receiving your request.
Data Security
We take reasonable and appropriate technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. This includes: encrypted connections, secure storage, limited access controls, and staff training.
Policy Updates
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The latest version will always be published on our website. We encourage you to review it regularly.
Contact
If you have questions, concerns, or requests regarding this Privacy Policy or your data rights, please get in touch with us using the contact information provided on our website. We will be happy to assist you.