Flower Delivery Chesham Privacy Policy
Introduction
At Flower Delivery Chesham, we are dedicated to maintaining the privacy and security of your personal information. This Privacy Policy outlines how we collect, use, retain, and share your data in compliance with the General Data Protection Regulation (GDPR). The policy applies to all customers placing flower delivery orders from Chesham and surrounding districts.
What Data We Collect
When you place an order with Flower Delivery Chesham, we collect the following types of personal data:
- Contact Information: Your name, address, delivery address, and phone number.
- Order Details: Information about the products and services you purchase, recipient details, and any personalized messages.
- Payment Information: Details necessary to process your payment (note: sensitive card details are not stored by us but managed securely by our payment processors).
- Account Information: If you create an account, we store your username, encrypted password, and order history.
- Communication Records: Details of communication with our customer service team, including inquiries and complaints.
- Device and Usage Data: Information automatically collected through cookies and similar technologies when you browse our website, such as IP address, browser type, and usage patterns.
Lawful Basis for Data Processing
We process your personal data lawfully and transparently under the following bases as outlined by the GDPR:
- Performance of a Contract: Most of the data we collect is used to fulfil our contract with you, namely processing and delivering your order.
- Legal Obligation: Certain information may be required to comply with legal or tax obligations.
- Legitimate Interests: We may use your data to improve our services, prevent fraud, or carry out marketing (with appropriate safeguards and your right to object).
- Consent: Where required, such as for direct electronic marketing, we will obtain your explicit consent and provide an option to withdraw it at any time.
How We Use Your Data
Flower Delivery Chesham uses your personal information for the following purposes:
- To process and fulfill your flower delivery orders.
- To communicate with you about your orders, respond to inquiries, and resolve complaints.
- To improve our products and customer service.
- For administrative purposes, including record keeping and compliance with our obligations.
- To send you information about similar goods and services, if you have not opted out of such communications.
- For analytical purposes to improve our website and user experience.
Data Retention
We retain personal data only for as long as necessary for the purposes for which it was collected:
- Order history and transaction data are retained for up to 7 years to comply with legal and accounting requirements.
- Contact and account information are retained as long as your account is active or until you request its deletion, subject to our legal obligations.
- Communication records may be retained for up to 2 years for quality control and dispute resolution.
- Data collected for marketing purposes is retained until you withdraw consent or object to processing.
Data Processors and Sharing
Your personal data may be shared with trusted third-party service providers solely for the purpose of conducting our business operations. These may include:
- Payment processors to securely handle payments.
- Delivery couriers for fulfilling the delivery of your order.
- Technical partners who assist in website hosting, IT support, email communication, and data analytics.
We ensure all processors comply with GDPR requirements and only process your data according to our instructions. We do not sell or rent your personal data to third parties for marketing purposes.
User Rights Under GDPR
As a data subject under GDPR, you have the following rights regarding your personal information:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You may ask us to correct any inaccurate or incomplete information.
- Right to Erasure: You have the right to request deletion of your data in certain circumstances.
- Right to Restrict Processing: You can ask us to restrict or limit the processing of your personal data.
- Right to Data Portability: You can request to receive your data in a machine-readable format or have it transferred to another provider.
- Right to Object: You can object to the processing of your personal data based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where we process data based on your consent, you can withdraw it at any time.
To exercise any of these rights, please contact us using the details provided on our website. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your data has been processed unlawfully.
Security Measures
We have implemented appropriate administrative, technical, and physical safeguards to protect your data from loss, misuse, and unauthorized access. Our staff are trained in best practices regarding data protection. Payment information is transmitted securely using encrypted channels, and access to personal data is restricted on a need-to-know basis.
International Transfers
In the unlikely event your personal data is transferred outside of the UK or European Economic Area (EEA), we will ensure such transfers are protected by appropriate legal safeguards, such as standard contractual clauses.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in practices, regulatory requirements, or business operations. Updates will be posted on our website with the effective date clearly noted.
Contact Information
If you have questions or concerns regarding this Privacy Policy or your data, please contact us using the details provided on our website.
This policy was last updated on 1st June 2024.