Flower Delivery Cheam: Our Commitment to Your Privacy
Introduction
Flower Delivery Cheam is dedicated to safeguarding the privacy and personal information of our customers. This Privacy Policy outlines how we collect, use, store, and protect your data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and the Data Protection Act 2018. This policy applies to all individuals placing orders for flower delivery services from Cheam and surrounding districts.
What Data We Collect
We collect specific data needed to process and deliver your orders, provide quality service, and comply with legal obligations. The types of personal data we may collect include:
- Identity Data: Your name and, if relevant, the recipient’s name.
- Contact Data: Delivery address, billing address, telephone number, and (if provided) email address.
- Order Details: Information about the products you order, delivery instructions, and any gift notes or messages.
- Payment Data: Payment card details (handled by secure payment processors), payment history, and transaction IDs.
- Technical Data: IP addresses, browser type, device information, and data collected via cookies or similar technologies when you visit our website.
- Correspondence: Records of communications or customer service interactions you have with us.
Lawful Basis for Processing Your Data
We process your personal data based on the following lawful bases outlined in the GDPR:
- Contractual Necessity: To fulfil our contract to deliver your order and communicate with you about your purchases.
- Legitimate Interests: To improve our services, ensure security, respond to enquiries, and maintain business records.
- Legal Obligation: To fulfil our legal and regulatory obligations, including tax and accounting requirements.
- Consent: Where required, we will obtain your explicit consent before using your data for direct marketing or similar activities. You may withdraw your consent at any time.
How We Use Your Data
We only use your personal information for the purposes it was collected. Specifically, we may use your data to:
- Process and deliver your orders, including sharing necessary information with delivery partners.
- Provide customer service and communicate with you regarding your order status or queries.
- Handle payments and refunds securely via third-party processors.
- Comply with legal reporting and tax requirements.
- Improve our website, services, and customer experience through anonymized analytics.
- Send you service messages or, with your consent, occasional marketing communications.
Data Retention
We retain your personal data only as long as necessary for the purposes for which it was collected, including satisfying legal, accounting, or reporting obligations. Typically:
- Order and Payment Data: Retained for up to 7 years to meet tax and financial regulations.
- Customer Communications: Retained for up to 2 years after your last contact with us.
- Marketing Data: Retained until you withdraw consent or opt-out of communications.
- Technical Data: Retained according to cookie and analytics policies, usually no longer than 13 months.
At the end of retention periods, your information is securely deleted or anonymized.
Data Processors and Third Parties
We sometimes use trusted third-party service providers (“data processors”) to support business operations. These may include:
- Payment processors for handling card transactions.
- Website hosting and IT service providers.
- Delivery and logistics companies for order fulfillment.
- Professional advisers such as accountants or legal consultants.
All processors are bound by contractual obligations to process data only on our instructions and to uphold high standards of privacy and security in line with GDPR. We do not sell or rent your personal data to third parties for commercial purposes.
Your Data Protection Rights
Under GDPR, you have several rights regarding your personal data:
- Right of Access: Request a copy of your personal data held by us.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request the deletion of your data, where legally permissible.
- Right to Restrict Processing: Request us to suspend or limit the processing of your data.
- Right to Data Portability: Request transfer of your data to you or another provider in a structured, commonly used format.
- Right to Object: Object to our processing of your data for certain purposes, such as direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time.
- Right to Lodge a Complaint: You can raise a complaint with the Information Commissioner’s Office (ICO) if you believe your data rights have not been upheld.
How We Protect Your Data
We implement appropriate technical and organizational security measures to protect your personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction. This includes encryption, data access controls, secure storage, and staff training on data protection. Third-party processors are reviewed for GDPR compliance before any data is shared.
International Data Transfers
As a local flower delivery service in Cheam, we primarily process your data within the UK and European Economic Area (EEA). Should we transfer data outside the EEA, we ensure adequate protections are in place as required by GDPR and UK data protection law.
Policy Updates
We periodically review and update this Privacy Policy to reflect changes in regulations or practices. Significant updates will be notified to customers using reasonable methods. Please review this policy regularly for the latest information about how we use and protect your data.
Contacting Us
If you have questions about this Privacy Policy or wish to exercise your rights, please contact us through the details provided on our website or through our customer service channels. We are committed to assisting you promptly and transparently.