Flowers Walthamstow Privacy Policy
Introduction
This Privacy Policy explains how Flowers Walthamstow ("we", "us", or "our") collects, uses, and protects your personal data. The policy applies to all customers who place orders with Flowers Walthamstow from Walthamstow and the surrounding districts. We are committed to respecting your privacy and complying with the UK General Data Protection Regulation (GDPR).
What Data We Collect
To provide our products and services, we collect a variety of information from you. Depending on your interactions with us, the information we may collect includes:
- Contact Information: This includes your name, address, and any delivery addresses, as well as information required to complete an order.
- Order Details: Information about the floral arrangements and gifts you purchase, including messages and preferences.
- Payment Information: This includes transaction data provided when making a purchase. (Please note that payment processing is handled by secure, third-party processors and we do not store your card details ourselves.)
- Communication Data: Records of your communications with us, including emails or messages regarding queries, feedback, or after-sales service.
- Website Usage Data: When you use our website, we may collect technical and usage data, such as your IP address, browser type, referring or exit pages, and interactions to help us improve our services.
Lawful Basis for Processing Personal Data
We process your personal data only when there is a lawful basis to do so, in accordance with the GDPR. The lawful bases we rely upon include:
- Contractual Necessity: Processing your personal data is necessary to carry out our obligations under a contract—such as fulfilling your flower order and delivering products to you or your recipient.
- Consent: Where required, we will ask for your explicit consent to process certain data, such as for marketing communications.
- Legal Obligation: We are required by law to retain some information for accounting and tax purposes.
- Legitimate Interests: We may use your data to improve our services, prevent payments fraud, and for general business reporting, where such use does not override your fundamental rights and freedoms.
Use of Your Personal Data
Your personal data is used for the following purposes:
- Processing and delivering your orders, including sharing necessary delivery details with couriers.
- Managing your relationship with us, including responding to your requests and queries.
- Communicating with you about your orders, including order confirmations and delivery updates.
- Internal record-keeping, business analysis, and service improvement.
- Compliance with legal obligations.
- Sending you marketing communications, only if you have provided your consent where applicable.
Data Retention
We will not retain your personal data for longer than is necessary for the purposes for which it was collected. The retention period depends on the type of data and our legal obligations:
- Order Information: Retained for up to six years after completion of your order in line with standard accounting and tax requirements.
- Marketing Preferences: Retained for as long as you remain subscribed to our communications, or until you withdraw consent.
- Communication Records: Usually retained for three years for quality and training purposes.
When data is no longer needed, it will be securely erased or anonymised.
Data Processors and Third Parties
We may share your personal data with third-party service providers ("processors") who perform functions on our behalf, such as:
- Payment service providers for processing transactions securely.
- Delivery and logistics companies for dispatching your orders.
- Information technology service providers who help manage our website and data storage.
All third-party processors are selected carefully and are required to act only on our instructions, maintain the confidentiality and security of your data, and comply with GDPR requirements. We do not sell or rent your data to third parties for marketing purposes.
Security of Your Data
We implement appropriate technical and organisational measures to protect your personal data from loss, misuse, unauthorised access, alteration, or disclosure. These measures include access controls, encryption, and regular review of our data handling practices.
User Rights
As a data subject, you have the following rights under the GDPR regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request that we correct inaccuracies in your data.
- Right to Erasure ('Right to be Forgotten'): You can request that we delete your data, subject to certain legal limitations.
- Right to Restrict Processing: You can request the restriction of data processing under certain circumstances.
- Right to Data Portability: You may request the transfer of your data to another service provider.
- Right to Object: You have the right to object to processing, especially for direct marketing.
- Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time.
If you wish to exercise any of these rights, please contact us using the methods provided on our website. For your privacy and security, we may ask you to verify your identity before we fulfil your request.
Children's Privacy
Our services are not intended for children under the age of 16. We do not knowingly collect data from children in this age group. If we become aware of such data, we will take steps to remove it promptly.
International Data Transfers
Your personal data is stored and processed within the United Kingdom or European Economic Area (EEA). If in the future we transfer data outside these regions, we will ensure appropriate safeguards, such as Standard Contractual Clauses, are in place to protect your data in line with GDPR requirements.
Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes in our practices or legal obligations. Any changes will be posted on our website. Please review this policy periodically to remain informed about how we protect your data.
Contact Us
If you have any questions about this Privacy Policy or how we process your data, please refer to the contact options available on our website. We will do our best to address your concerns promptly.