Flower Delivery Beckenham: GDPR Privacy Policy
About This Privacy Policy
This Privacy Policy explains how Flower Delivery Beckenham collects, uses, stores, and protects your personal information when you place an order for flower delivery in Beckenham and surrounding districts. Our commitment is to respecting your privacy and fulfilling our obligations under the General Data Protection Regulation (GDPR).
Scope of Application
This policy applies to all customers who engage with Flower Delivery Beckenham to place flower orders for delivery in Beckenham and neighbouring areas. The document covers any personal data we collect, regardless of how an order is placed – whether online, by phone, or through other ordering channels provided by us.
Personal Data We Collect
We collect various types of personal data necessary to fulfil your order and comply with legal requirements. The categories of data we collect include:
- Identity Data: Including your full name and, where required, proof of identity.
- Contact Data: Such as your delivery address, billing address, postcode, and contact telephone number.
- Order Details: Including the flower selection, special delivery instructions, and the intended recipient’s name and delivery address.
- Payment Data: Payment card details or other payment information (handled securely via our payment processor and not retained by us).
- Communications: Records of correspondence or special instructions relating to your order.
- Technical Data: Such as your IP address, browser type, and device information, collected when you use our website to enhance functionality and security.
The Lawful Basis for Processing
We only process your personal information where permitted by law. Our lawful bases for processing your data include:
- Contractual Necessity: To enable us to fulfil your flower order and perform our service contract with you.
- Legal Obligation: Where we are legally required to process or retain certain information (for example, for tax or accounting purposes).
- Legitimate Interests: For legitimate business purposes in managing and improving our services and safeguarding business activities, provided these do not override your data protection rights.
- Consent: Where legally required, for example, if you opt in to receive marketing or promotional communications, you are always free to withdraw your consent at any time.
Purposes of Processing Your Data
We process your personal information for the following reasons:
- To process and deliver your order, including arranging payment, delivery, and customer service communications.
- To keep records for legal and accounting requirements.
- To respond to your enquiries, feedback, or complaints.
- To improve our operations and customer experience (using aggregated or anonymised data where possible).
- To send you order confirmations, notifications, and, if you have opted in, marketing communications about our services and promotions.
How Long We Keep Your Data (Retention Policy)
We retain your personal data only as long as necessary for the purposes stated above:
- Order information and related identity/contact data will be held for a maximum of 7 years in line with accounting and tax record-keeping obligations.
- Payment information is processed securely by our payment providers and is not stored by us.
- Enquiry and communication records may be kept for up to 3 years to assist with customer service and resolve any potential disputes.
- Where you have given marketing consent, we will retain your contact details for up to 2 years following your last interaction unless you withdraw your consent earlier.
Your data will be securely deleted or anonymised when it is no longer needed.
Data Sharing and Processors
We do not sell, rent, or trade your personal data. To provide our services, your information may be shared only with trusted third-party service providers who act as data processors under contract and are bound by strict confidentiality obligations. These may include:
- Payment processing providers, for secure handling of payments.
- IT support and hosting services, used to maintain our website and data systems.
- Delivery partners or couriers, for the purpose of fulfilling your flower delivery.
All data processors are selected carefully to ensure GDPR compliance and are permitted to use your data solely for providing the agreed service to us. We will not transfer your data outside the UK or European Economic Area unless adequate data protection arrangements are in place.
Your Data Protection Rights
Under the GDPR, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal information we hold about you.
- Right to Rectification: You can ask us to correct any inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your data where it is no longer necessary or where you withdraw consent.
- Right to Restrict Processing: You can ask us to restrict the processing of your personal data under certain conditions.
- Right to Data Portability: You can request transfer of your data in a structured, commonly used format to another provider.
- Right to Object: You can object to our processing of your data in certain circumstances, including for direct marketing purposes.
To exercise any of these rights, please contact us through the methods provided on our website or by written correspondence. We may require proof of your identity before processing your request to ensure your data is protected.
Security of Your Data
We have implemented appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, alteration, or disclosure. Our security practices are regularly reviewed and include access controls, encryption for payment data, secure website hosting, and staff training on privacy awareness.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in legal requirements or our data processing practices. The latest version will always be available on our website, and significant changes will be communicated when appropriate. Please review this policy from time to time to ensure you remain informed.
Contact and Concerns
If you have any questions, requests, or concerns regarding your personal data or this Privacy Policy, you may reach out via the contact information provided on our website. If you are dissatisfied with our response, you have the right to contact the Information Commissioner's Office (ICO) or the relevant supervisory authority.
This policy was last updated on 5 June 2024.