Privacy Policy for Flowers Little Ilford Customers
Introduction
At Flowers Little Ilford, we respect your privacy and are committed to protecting your personal information. This Privacy Policy outlines how we collect, use, store, share, and protect the data of our customers. The policy applies to all individuals placing orders with Flowers Little Ilford from Little Ilford and the surrounding districts. Please review this policy to understand your rights and how we handle your data in accordance with the General Data Protection Regulation (GDPR).
What Data We Collect
We collect only the minimum personal data required to process your orders efficiently and to provide you with a better service. The types of data we collect include:
- Identity Data: Name and, if relevant, the name of the recipient of the flowers.
- Contact Data: Delivery address, contact number, and any other delivery instructions you provide.
- Order Data: Details about the products you have ordered, order dates and times, and payment information (note: direct payment information such as credit card numbers are processed by our payment service providers and not stored by us).
- Correspondence: Any communications you send us, such as feedback, queries, or complaints.
Lawful Basis for Processing Your Data
Our collection and use of your personal data is lawfully grounded in the following bases under the GDPR:
- Contractual Necessity: We collect and process your information in order to fulfill your orders and provide our services to you.
- Legitimate Interests: To improve our services, maintain security, prevent fraud, and ensure a satisfactory customer experience, where this does not override your rights or interests.
- Legal Obligation: In some cases, we may need to retain and process your data to comply with our legal and regulatory obligations, such as standard business record keeping and accounting requirements.
- Consent: If you explicitly agree, we may use your data for marketing purposes or to keep you updated about our products or services. You can withdraw your consent at any time.
How We Use Your Personal Information
Your personal information is used strictly for the purposes it was collected, including to:
- Process your flower orders and arrange delivery
- Communicate with you about your order status or respond to your enquiries
- Improve our services and operations based on customer feedback
- Maintain records for tax, legal, and regulatory requirements
- Send marketing updates if you have given your explicit consent
Retention of Your Data
We retain your personal data only for as long as necessary to fulfill the purpose it was collected for, including for the purposes of satisfying any legal, accounting, or reporting requirements. Typically:
- Order information is retained for up to seven years in line with HMRC and accounting requirements.
- Contact details used for marketing (if you consented) will be held until you unsubscribe or withdraw your consent.
- Correspondence is retained as long as it is necessary to resolve your enquiry or complaint and may be stored for record-keeping for up to two years.
Data Processors and Third Parties
To provide our services effectively, we may need to share certain personal data with trusted third-party processors, including:
- Payment Providers: Process payments securely on our behalf. We never store your full payment details.
- Delivery Partners: Assist in the delivery of your order to the correct address and may require your contact information for successful delivery.
- IT Service Providers: Help maintain and support our website, booking, and communication systems.
We require all our third-party processors to maintain the confidentiality and security of your data and to act strictly on our instructions. We do not sell your personal data to anyone.
International Data Transfers
Flowers Little Ilford is based in the UK and does not routinely transfer personal data outside the UK or the European Economic Area (EEA). If, in exceptional cases, we must transfer personal data internationally (e.g., if a third-party processor is based outside the EEA), we will ensure that appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission, to guarantee your data is protected.
Your Rights as a Customer
As a data subject under the GDPR, you have the following rights concerning your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You may ask us to correct any inaccurate or incomplete information we hold.
- Right to Erasure: You can request deletion of your data when it is no longer necessary for the purposes for which it was collected, except where we need to retain it for legal or legitimate reasons.
- Right to Restrict Processing: In certain circumstances, you can ask us to restrict or suppress the processing of your data.
- Right to Object: You can object to processing based on legitimate interests or to receiving direct marketing.
- Right to Data Portability: You can ask us to provide your data in a structured, commonly used, and machine-readable format and/or to transmit it to another controller.
- Right to Withdraw Consent: Where we rely on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us using the details provided on our website. We may ask you to verify your identity before considering your request to protect your privacy and security.
Data Security
We take appropriate technical and organisational measures to safeguard your personal data, including secure servers, encrypted communications, and strict access controls. While we strive to protect your information, no security system is completely infallible. We recommend that you use strong passwords and keep your order reference numbers confidential.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. Any significant changes will be notified on our website. We encourage you to regularly review this policy for the latest information on our privacy practices.
Contact and Complaints
If you have any questions, comments, or concerns about this policy or your personal data, please use the contact options displayed on our website to reach our Data Protection Officer. If you are dissatisfied with our response, you also have the right to lodge a complaint with the UK Information Commissioner’s Office.