Flowers Gerrards Cross Privacy and Data Protection Policy
Introduction
At Flowers Gerrards Cross, safeguarding your privacy is a priority. This Privacy Policy details how we collect, use, store, and process your personal information in compliance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers placing orders for Flowers Gerrards Cross from Gerrards Cross and surrounding districts.
Personal Data We Collect
When you place an order or interact with Flowers Gerrards Cross, we collect and process certain personal data to fulfil your requests and enhance your customer experience. This may include:
- Identity Data: Your name and, where applicable, the recipient's name.
- Contact Data: Billing and delivery addresses, telephone numbers, and other contact details required for order fulfilment.
- Order Details: Information about your flower orders, special instructions, preferences, and purchase history.
- Payment Data: Payment method details, for example, partial card information and transaction references. We do not store full payment card details ourselves; these are handled securely by our payment processors.
- Correspondence: Records of communications with our team, such as emails, order notes or customer service interactions.
- Technical Data: Basic technical information such as IP address, browser type, and device information when you interact with our website, collected via cookies and similar technology subject to your consent preferences.
Lawful Basis for Processing
We process your personal data only when we have a lawful basis under GDPR, such as:
- Performance of a Contract: Processing your data is necessary to provide our services—such as accepting, processing, and delivering your orders.
- Legal Obligations: We may process some data to comply with legal requirements, including record-keeping or responding to legitimate requests from authorities.
- Legitimate Interests: We use your data to enhance our service, manage customer relationships, improve our products, and ensure security, where these interests are not overridden by your rights.
- Consent: In cases where we require your consent (e.g., for marketing), we will ask for it explicitly and you can withdraw it at any time.
How We Use Your Information
Your personal data is used strictly for the following purposes:
- Processing and fulfilling your flower orders and delivering products to designated addresses.
- Handling payments and preventing fraud.
- Communicating order updates, confirmations, and responding to your enquiries.
- Maintaining internal records for accounting and compliance.
- Improving our products, services, and customer service based on feedback and order history.
- Sending marketing communications, only with your explicit consent, and offering tailored promotions or updates.
Data Sharing and Processors
To run our operations, we may use third-party service providers ("processors") who handle data on our behalf. These may include:
- Payment service providers who process your payment details securely.
- IT and system administration service providers who support our infrastructure.
- Delivery companies who transport flowers to recipients.
- Professional advisers (such as accountants or legal consultants), if necessary and bound by confidentiality obligations.
All such processors are bound by contracts requiring them to keep your data secure and to process data only in accordance with our instructions and GDPR requirements. We do not sell or rent your personal data to third parties.
International Transfers
Flowers Gerrards Cross endeavours to process your personal data within the UK and European Economic Area (EEA). Should it become necessary to transfer data outside these regions, we ensure equivalent data protection standards by using approved safeguards as required by GDPR.
Retention of Your Data
We retain your personal data only as long as necessary to fulfil the purposes we collected it for, including the need to satisfy legal, accounting, or reporting requirements. Typically, we keep order and correspondence data for up to 7 years, in line with UK tax and accounting laws. After this period, personal data is securely deleted or anonymised.
Your Rights under GDPR
As a data subject, you have various rights under GDPR, including:
- Right of Access: You may request access to your personal data and receive information about how it is processed.
- Right to Rectification: If you believe any personal data we hold is incorrect or incomplete, you may ask for it to be corrected.
- Right to Erasure: In certain circumstances, you can request deletion of your data (subject to legal exceptions).
- Right to Restrict Processing: You may request restricted processing where you contest the accuracy or legality of processing.
- Right to Object: You have the right to object to processing based on legitimate interests or direct marketing.
- Right to Data Portability: Where applicable, you can request that your data be provided in a machine-readable format or transferred to another controller.
- Right to Withdraw Consent: If we process your information based on consent, you can withdraw this at any time.
To exercise your rights, please contact us as detailed on our website. We will respond to all legitimate requests within one month.
Data Security
We implement appropriate technical and organisational measures to protect your personal data against accidental loss, unauthorised access, modification, or disclosure. Access to data is restricted to those who require it to perform their job duties. Regular training and review of our procedures help maintain data integrity and confidentiality.
Policy Updates
This policy may be updated occasionally to reflect regulatory changes or improvements in our privacy practices. The latest version will always be available on our website, and significant changes will be clearly communicated to our customers where appropriate.
Contact and Complaints
If you have questions about this Privacy Policy or how your personal data is handled, please refer to the contact details on our website. You also have the right to lodge a complaint with the UK Information Commissioner's Office if you believe your data protection rights have been breached.