Flowers Dollis Hill Privacy Policy
Introduction
This Privacy Policy describes how Flowers Dollis Hill processes personal data in compliance with the General Data Protection Regulation (GDPR). It applies to all individuals placing an order with Flowers Dollis Hill for delivery or pickup within Dollis Hill and the surrounding districts. Flowers Dollis Hill is committed to respecting your privacy and protecting your personal data.
What Data We Collect
We collect the following categories of personal data when you place an order or contact us:
- Identity Data: Name, surname, and, when required for identification, age (for age-restricted products).
- Contact Data: Delivery address, billing address, and telephone number.
- Order Details: Product selections, delivery instructions, messages for recipients.
- Payment Data: Payment confirmation (we do not store full card details; these are processed by our payment service providers).
- Communication Data: Correspondence regarding your order, complaints, or enquiries.
- Technical Data: Information such as IP address, browser type, and access times may be collected through our website to ensure secure and reliable service delivery.
Lawful Basis for Processing
We process your personal data on the following lawful bases as set out by the GDPR:
- Contractual Necessity: Processing is required for the performance of a contract with you, such as fulfilling your flower order, processing your payment, and delivering your products.
- Legal Obligation: Processing may be necessary to comply with applicable laws, such as accounting or tax regulations.
- Legitimate Interests: We may process your data to improve our services, engage in customer support, or prevent fraud, ensuring these interests are not overridden by your rights and interests.
- Consent: For certain optional activities, such as sending you marketing communications, we will rely on your explicit consent, which you may withdraw at any time.
How We Use Your Data
Your personal data is used solely for the following purposes:
- To register and process your order, manage payment, and arrange product delivery or collection.
- For customer service, including responding to your requests or concerns.
- To comply with legal and regulatory duties, such as record keeping.
- For accounting, auditing, and internal record maintenance.
- To improve and personalise our products or services.
- If you have opted in, to send newsletters or promotional offers related to our services.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected. This typically means:
- Order and billing data are retained for up to seven years, in line with tax and accounting laws.
- Communication data is kept as long as necessary to resolve your query or provide customer support.
- Where data is processed with your consent (e.g., marketing), data is kept until you withdraw consent.
After the relevant period, personal data is securely deleted or anonymised.
Processors and Data Sharing
We may share your data with trusted third parties (‘processors’) only where necessary for business operations and only with those bound by equivalent obligations under GDPR:
- Payment Service Providers: To securely process transactions. We do not retain full payment card details.
- Delivery Partners: To deliver your order to the specified location.
- IT and Website Management: Providers supporting our website hosting, maintenance, or data storage.
- Professional Advisors: Such as accountants or legal representatives, where required for compliance or legal disputes.
We never sell or rent your personal data to third parties. When providing data to a processor, we ensure adequate safeguards are in place and that data is processed only under our instructions. If data is transferred outside the UK or European Economic Area, we ensure appropriate data protection measures are in place, consistent with GDPR requirements.
User Rights
Under the GDPR, you have the following rights regarding your personal data:
- The right to be informed: You have the right to know which personal data we are processing and why.
- The right of access: You can request a copy of the personal information we hold about you.
- The right to rectification: If you believe any data we hold is inaccurate or incomplete, you can ask for it to be corrected.
- The right to erasure: You may request deletion of your personal data, subject to certain conditions (such as our legal or contractual obligations).
- The right to restrict processing: You can request that we limit use of your data under certain circumstances.
- The right to data portability: You may request that your personal data is provided to you in a structured format or transmitted to another organisation.
- The right to object: You can object to certain types of data processing, such as direct marketing.
- Rights relating to automated decision making: You have the right not to be subject to decisions made solely by automated means, where relevant.
Protecting Your Data
We are committed to safeguarding your personal data. Physical, electronic, and managerial procedures are in place to prevent unauthorised access, loss, alteration, or disclosure of your information.
Changes to This Policy
Flowers Dollis Hill may update this Privacy Policy from time to time. Updates will be posted on our website and apply from the date of publication. We encourage you to review this policy regularly to stay informed of how we process and protect your information.
Contact and Complaints
If you have questions regarding this Privacy Policy, want to exercise any of your rights, or wish to lodge a complaint about our handling of your personal data, please contact us using the methods provided on our website. If you are not satisfied with our response, you may also complain to the UK Information Commissioner’s Office or your local data protection authority.