Privacy Policy for Flower Delivery Paddington Orders
Introduction
This Privacy Policy explains how Flower Delivery Paddington, hereafter referred to as "we" or "us," collects, uses, and safeguards your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"). This policy applies to all customers ordering flower deliveries from Flower Delivery Paddington within Paddington and the surrounding districts.
What Data We Collect
We collect the following categories of personal data to process your orders and provide our services:
- Identity Information: Name, address, and delivery address (if different), recipient name and address.
- Contact Details: Phone number and (if provided) email address.
- Order Details: Flowers and products ordered, message included with gift, delivery date and time.
- Payment Information: Payment card details and transaction information (handled securely in accordance with PCI DSS standards).
- Website Technical Data: IP address, browser type, device identifiers, and cookies (see our Cookie Policy, if applicable).
We do not collect or process special category data unless it is voluntarily provided by you for the purposes of your order.
Lawful Basis for Processing
We process your personal data on the following lawful bases as defined under the GDPR:
- Contractual Necessity: To fulfill and deliver your flower orders and to communicate with you about your purchase.
- Legal Obligation: To comply with applicable laws (such as record-keeping for tax purposes).
- Legitimate Interest: To analyze sales trends, improve our services, and prevent fraud, provided that such interests do not override your privacy rights.
- Consent: Where you provide optional information, such as for receiving marketing materials or special offers. You may withdraw your consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
- Processing and fulfilling your order, including delivery of flowers and communication regarding your purchase.
- Managing payments, refunds, and accountancy records.
- Providing customer support and resolving issues related to your order.
- Improving our website performance and service offerings.
- Complying with legal, regulatory, or tax obligations.
- Subject to your consent, sending marketing communications.
Data Retention
Your personal data will be retained only for as long as necessary to fulfill the purposes outlined in this policy, unless a longer retention period is required or permitted by law. In general:
- Order information and contact data are retained for a period that enables us to comply with our legal obligations (typically up to 7 years for tax and accounting records).
- Payment details are processed securely and not retained beyond what is legally or contractually necessary.
- Data used for marketing purposes will be retained until you unsubscribe or request deletion.
After these periods, data will be securely deleted or anonymized.
Data Sharing and Processors
To provide our services, we may need to share your data with trusted third-party service providers (processors) who assist us with:
- Payment processing
- Website hosting and IT infrastructure
- Delivery and courier services
- Customer support solutions
- Accounting services
All such processors are contractually obligated to handle your data securely and only in accordance with our instructions. We do not sell or disclose your personal data to any other parties for their own purposes.
Where processors are located outside the European Economic Area (EEA), we ensure appropriate safeguards are in place for international data transfers, in line with the GDPR requirements.
How We Protect Your Data
We take the security of your data seriously. Appropriate technical and organizational measures are in place to protect your personal data from loss, unauthorized access, or misuse. These measures include encryption of payment details, restricted access controls, and regular security reviews.
Your Rights as a Customer
Under the GDPR, you have the following rights with regard to your personal data:
- Right to Access: Request access to any personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your data where there is no legal or contractual reason for us to retain it (the "right to be forgotten").
- Right to Restrict Processing: Request that we limit how we process your data in certain circumstances.
- Right to Data Portability: Obtain a copy of your data in a commonly used, machine-readable format.
- Right to Object: Object to the processing of your data in certain circumstances, such as for direct marketing purposes.
- Right to Withdraw Consent: Withdraw your consent for processing at any time where processing is based solely on consent.
- Right to Lodge a Complaint: Lodge a complaint with your local data protection supervisory authority if you feel your rights are not being upheld.
Requests regarding your rights should be sent in writing. We will respond to your request without undue delay, and in any case within one month as required by the GDPR.
Updates to This Privacy Policy
This policy may be updated periodically to reflect changes in our practices or legal requirements. The latest version will always apply and be available on our website.
Contact Information
For any questions or concerns about this Privacy Policy, the personal data we hold about you, or to exercise your rights, please use the contact form provided on our website or write to our registered business address. We commit to addressing your inquiries promptly and transparently.