Flowers Wandsworth GDPR Privacy Policy
Introduction
This Privacy Policy explains how Flowers Wandsworth (“we”, “us”, “our”) collects, uses, stores, and protects your personal data. It applies to all customers placing orders for flowers with Flowers Wandsworth from Wandsworth and the surrounding districts. We are committed to safeguarding your privacy and ensuring your personal information is handled in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).
What Personal Data We Collect
Flowers Wandsworth collects only the data necessary to process your orders, fulfill our obligations to you, and improve our services. We may collect and process the following categories of personal data:
- Identity Data: Your first and last name.
- Contact Data: Billing and delivery address, telephone number, and other contact details you provide.
- Order Information: Details about the floral products or services you order, preferred delivery times, and any special instructions.
- Payment Data: Certain payment information required for order processing and fraud prevention, such as partial card numbers or payment confirmation, processed securely via payment providers.
- Communication Data: Records of your interactions with us, including emails, feedback, and customer service communications.
- Technical Data: Limited technical details about your device, browser, and interactions with our website, collected through cookies or similar technologies for security and site improvement (subject to your consent where legally required).
Lawful Bases for Processing
Under GDPR, data must be processed on a valid lawful basis. Flowers Wandsworth processes your data under one or more of the following legal grounds:
- Contractual Necessity: Processing is necessary to fulfill our contract with you, such as delivering your order and managing your account.
- Legal Obligation: Certain data must be processed to comply with legal requirements (e.g., financial record keeping or fraud prevention).
- Legitimate Interests: We may process your data as necessary for our legitimate interests, such as improving our services or direct marketing (unless such interests are overridden by your rights).
- Consent: In cases where we rely on your consent (for example, for certain marketing communications or the use of analytical cookies), you are free to withdraw it at any time.
How We Use Your Data
Your personal data is used for the following primary purposes:
- Processing and fulfilling your flower orders, including payment and delivery.
- Communicating order confirmations, delivery updates, and customer service responses.
- Conducting fraud checks and ensuring the security of our services.
- Meeting legal and regulatory obligations.
- Enhancing user experience and improving our products and services.
- Sending you marketing communications, when permitted by law and your preferences.
Processors and Sharing of Your Data
Flowers Wandsworth may share your personal data with selected third parties (“processors”) when necessary to deliver our services or comply with legal obligations. These may include:
- Payment processing providers for secure handling of payments.
- Delivery partners for order fulfillment and tracking.
- IT service providers and cloud storage solutions supporting secure data management.
- Professional advisers, such as accountants, for regulatory compliance.
All processors are required to act only on our instructions and are subject to contractual obligations to safeguard your data in compliance with GDPR. We do not sell or rent your personal data to third parties for their own marketing purposes.
International Data Transfers
Where any data is transferred outside the United Kingdom or European Economic Area, Flowers Wandsworth ensures that adequate safeguards are in place, such as approved standard contractual clauses or equivalent mechanisms, as required by law to maintain the security of your data.
Data Retention Policy
Your personal data will be retained only as long as necessary to fulfill the purposes outlined in this policy, to satisfy legal, accounting, or reporting requirements, or to resolve potential disputes. In general:
- Order, billing, and delivery data are retained for up to 6 years after your last transaction to comply with tax and legal obligations.
- Customer service correspondence is stored for up to 3 years after the last interaction.
- Marketing preferences and consents are maintained until you withdraw your consent or request erasure.
Once retention periods expire, your data is securely deleted or anonymised.
Your Rights as a Data Subject
Under GDPR, you have several rights regarding your personal data. Flowers Wandsworth is committed to respecting and facilitating your rights, which may include:
- Access: Request a copy of your personal data we hold.
- Rectification: Request corrections to any inaccurate or incomplete information.
- Erasure: Ask for your data to be erased (the “right to be forgotten”) when retention is no longer necessary, subject to certain legal exceptions.
- Restriction: Request limits on processing under specific conditions.
- Objection: Object to certain processing activities, such as direct marketing.
- Portability: Receive your data in a structured, machine-readable format and transmit it to another service provider, where technically feasible.
- Withdrawal of Consent: Where processing is based on your consent, you may withdraw it at any time without affecting previous lawful processing.
- Complaint: Lodge a complaint with a supervisory authority if you believe we have not complied with data protection laws.
Data Security
Flowers Wandsworth implements appropriate technical and organisational measures to protect your personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These measures include secure servers, access controls, encryption, and regular staff training.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any amendments will be published on our website with an updated revision date. Please review this policy periodically to ensure you are aware of the latest terms.
Contact and Further Information
If you have questions about this Privacy Policy, the data we hold about you, or if you wish to exercise any of your privacy rights, please contact us through the channels provided on our website. We are committed to addressing your concerns promptly and transparently.