Privacy Policy - Flower Delivery Wapping
Introduction
This Privacy Policy sets out how Flower Delivery Wapping ("we", "us", or "our") handles your personal data when you place flower delivery orders from Wapping and surrounding districts. We are committed to protecting the privacy and security of your information in accordance with the General Data Protection Regulation (GDPR) and applicable UK data protection laws. By using our services, you agree to the collection and use of information as described in this policy.
What Data We Collect
We collect and process various types of personal data to provide you with our flower delivery services. The categories of information we may collect include:
- Identity Data: Full name, title.
- Contact Data: Delivery address, billing address, email address, and phone number.
- Transaction Data: Order details including products purchased, delivery instructions, recipient name and address.
- Payment Data: Payment card details or transaction references (processed securely by third-party payment processors; we do not store full card details).
- Technical Data: IP address, browser type, device identifiers, and how you use our website (collected via cookies and other tracking technologies).
- Preference Data: Preferences regarding types of flowers, delivery dates, and special requests.
Lawful Basis for Processing Your Data
Under GDPR, we rely on several lawful bases to process your personal data. These include:
- Performance of a Contract: Processing your personal data is necessary to fulfill your flower delivery order and manage our contract with you.
- Legal Obligation: We must process certain information to comply with legal and regulatory obligations, such as maintaining transaction records for tax purposes.
- Legitimate Interests: We may process your personal data for our legitimate business interests, for example, to improve our services or communicate delivery updates, provided that such interests are not overridden by your rights and freedoms.
- Consent: In cases where consent is required (such as for marketing communications), we will always ask for your clear and explicit permission.
How We Use Your Personal Data
We use your personal data for the following purposes:
- To process and deliver your orders, including communicating with you and recipients about delivery status.
- To manage transactions and payment processing.
- To provide customer support and respond to your inquiries or requests.
- To improve our website, services, and customer experiences.
- To comply with our legal and regulatory obligations.
- To send you marketing communications, promotions, or updates, where you have provided your consent.
Retention of Your Data
We only keep your personal data for as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. The retention periods depend on the type of data and the reason for its processing:
- Order and Transaction Data: Retained for up to six years after your last transaction to comply with legal obligations and resolve any disputes.
- Marketing Data: Retained until you withdraw your consent or unsubscribe from our communications.
- Technical Data: Retained in accordance with our cookie policy and website analytics retention schedules.
When retention periods expire, we securely delete or anonymise your data.
Data Processors and Third Parties
We work with trusted third-party service providers ("processors") to help deliver our services. These may include:
- Payment processing companies for secure handling of card transactions.
- IT and website hosting providers.
- Delivery and logistics partners.
- Marketing and communication tools to manage emails or promotions (where consent has been given).
All our processors are required to act only on our instructions and are bound by contractual obligations to protect your data. We do not sell your personal information or share it with unrelated third parties for their own marketing purposes.
International Data Transfers
We generally process your personal data within the United Kingdom and the European Economic Area (EEA). If we need to transfer your information outside these regions, we ensure that appropriate safeguards are in place, such as Standard Contractual Clauses, to protect your privacy rights.
Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request corrections if your data is inaccurate or incomplete.
- Right to Erasure: Ask us to delete your personal data in certain circumstances (also known as the "right to be forgotten").
- Right to Restrict Processing: Request that we restrict how we use your data in certain situations.
- Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format and have it transferred to another provider.
- Right to Object: Object to our processing of your personal data for direct marketing or where processing is based on legitimate interests.
- Right to Withdraw Consent: Where consent is the legal basis for processing, you can withdraw it at any time. This does not affect processing already carried out before withdrawal.
- Right to Lodge a Complaint: If you believe your data protection rights have been breached, you may lodge a complaint with the relevant supervisory authority.
To exercise any of these rights, please contact us using the details provided in the 'Contact' section of our website.
Data Security
We implement appropriate technical and organisational measures to safeguard your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include encryption, access controls, regular security assessments, and staff training.
Despite these precautions, no internet-based system is completely secure. We urge you to take care when transmitting personal data online and use strong, unique passwords for your accounts.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, regulatory, or operational reasons. We will notify you of any significant changes where required by law. Please review this page periodically to stay informed about how we protect your data.
Policy Scope
This Privacy Policy applies to all individuals placing orders with Flower Delivery Wapping from Wapping and the surrounding districts. If you use our services or website from outside these areas, the policy will still apply to your data processing within the context of our flower delivery business.