Privacy Policy – Flower Delivery Esher: Data Protection and Your Rights
Introduction
This Privacy Policy describes how Flower Delivery Esher collects, uses, stores, and protects your personal information when you place an order with us. This policy applies to all customers ordering flower delivery services from Flower Delivery Esher within Esher and the surrounding districts. Our commitment is to ensure your privacy is respected and that your personal data is processed in compliance with the General Data Protection Regulation (GDPR) and applicable UK data protection laws.
What Data We Collect
When you use our flower delivery services, we may collect the following categories of personal data:
- Contact Information: Name, address, phone number, and email address of both the sender and recipient.
- Order Details: Products selected, card messages, delivery instructions, preferred delivery date and time.
- Payment Information: Payment card details are processed securely through our payment processor and not stored by Flower Delivery Esher.
- Correspondence: Any communications with us, such as customer service inquiries, feedback, or complaints.
- Website Usage Data: IP address, browser type, operating system, referring URLs, and actions taken on our website (gathered through cookies or similar technologies).
Lawful Basis for Processing Personal Data
Under the GDPR, we must have a valid lawful basis to process your personal data. The lawful grounds under which Flower Delivery Esher processes your data include:
- Contractual Necessity: To fulfill orders you place and provide the requested flower delivery service. Without this information, we cannot process or complete your order.
- Legal Obligation: To comply with laws and regulations, such as financial record keeping and fraud prevention obligations.
- Legitimate Interests: To improve our services, develop our business, and communicate with customers about similar products or services. We ensure that such interests do not override your privacy rights.
- Consent: Where you have provided consent, for example, to receive marketing communications. You can withdraw consent at any time.
How We Use Your Information
Your data is used solely for purposes necessary to provide and improve our services. Typical uses include:
- Processing and delivering your flower order to the intended recipient.
- Communicating with you regarding your order and any customer service issues.
- Managing payments and invoicing through secure third-party payment processors.
- Sending information on services or products similar to those you have previously purchased, where permitted by law.
- Monitoring website usage to improve customer experience and website security.
- Maintaining financial and legal records as required by law.
Data Processors and Third Parties
Flower Delivery Esher may share your personal data with certain trusted third parties ("data processors") who act on our behalf for specific functions. These include:
- Payment Providers: Handling payment transactions securely.
- Delivery Partners: Assisting with delivering orders to customers in Esher and surrounding districts.
- IT Support and Hosting Providers: Maintaining our website and customer databases.
- Customer Communication Services: Managing emails or messages related to your order.
We require all processors to handle your data in compliance with data protection laws and to process it only for specified purposes. Your data will not be sold, rented, or traded to any unrelated third party for marketing purposes.
Data Retention
We retain your personal data only for as long as necessary for the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements:
- Order Information: Retained for up to 7 years to meet legal and financial record-keeping obligations.
- Correspondence: Retained for as long as necessary to resolve your inquiry or complaint.
- Marketing Preferences: Retained until you withdraw your consent or update your preferences.
- After the retention period, data is securely deleted or anonymised.
Your Rights Under GDPR
As a customer, you are entitled to the following rights under the GDPR with respect to your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any incomplete or inaccurate information.
- Right to Erasure: Ask for your data to be deleted under certain circumstances.
- Right to Restrict Processing: Request us to limit the way we use your data in certain situations.
- Right to Data Portability: Ask for your information to be provided in a structured, commonly used, and machine-readable format.
- Right to Object: Object to processing of your data when we rely on legitimate interests, or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw this at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with a supervisory authority if you believe your data has not been handled properly.
International Transfers
Your personal data is primarily stored and processed within the United Kingdom or the European Economic Area (EEA). In rare cases where data may be transferred outside these regions, we ensure appropriate safeguards are in place to protect your data as required by data protection law.
Security of Your Data
We employ physical, electronic, and managerial measures to protect your data against unauthorised access, loss, misuse, or disclosure. This includes the use of secure servers, encryption, access controls, and regular staff training in data protection.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in the law or how we process personal data. Any revisions will be posted on this page, and we recommend you review this policy periodically.
Contact and Further Information
If you have any questions about this Privacy Policy or how your personal information is handled, please use the contact details provided on our website to reach out to our Data Protection Officer or Customer Service team. We are committed to addressing your concerns promptly and transparently.