Privacy Policy for Flower Delivery Watford Customers
Introduction
This Privacy Policy sets out how Flower Delivery Watford collects, processes, and protects personal data of customers placing orders in Watford and the surrounding districts. We are committed to complying with the General Data Protection Regulation (GDPR) and safeguarding your privacy. Please read this policy carefully to understand how your personal information is handled when you use our services.
Scope of This Policy
This policy applies to all individuals who place orders with Flower Delivery Watford for delivery within Watford and its surrounding districts. By using our services, you acknowledge and agree to the practices described within this Privacy Policy.
Personal Data We Collect
When you place an order with Flower Delivery Watford, we may collect the following types of personal data:
- Contact Information: Name, delivery address, billing address, phone number, and name of the recipient.
- Order Details: Details of the products or services ordered, delivery instructions, gift messages, and preferences.
- Payment Information: Payment method and transaction details (note: payment card information is handled by secure third-party payment processors and is not stored on our systems).
- Account Details: If you create an account, we store your order history and login credentials.
- Communication Data: Any correspondence between you and Flower Delivery Watford, including queries and feedback.
- Technical Data: IP address, browser type, operating system, and device information collected via cookies for website functionality and security.
Lawful Basis for Data Processing
We process your data in accordance with GDPR principles. The primary lawful bases for our processing activities are:
- Contract Performance: Processing is necessary to fulfil your order and deliver our products and services.
- Legal Obligation: We may process your data as required to comply with applicable legal and tax obligations.
- Legitimate Interests: We process data to improve our services, prevent fraud, and ensure the security of our website, while balancing these needs with your privacy rights.
- Consent: Where required, we may seek your explicit consent before processing data (e.g., for marketing communications). Consent can be withdrawn at any time.
How We Use Your Personal Data
We only use your information for specific purposes, including:
- Processing and fulfilling your orders, including confirming purchase, arranging delivery, and providing customer support.
- Contacting you regarding your order or responding to your queries.
- Managing our relationship with you if you have an account.
- Complying with legal and regulatory requirements.
- Improving our website and customer experience through analytics and feedback.
- Sending you promotional communications, with your consent where required.
How We Store and Protect Your Information
Your data is stored in secure environments, protected by appropriate technical and organisational measures to prevent unauthorised access, disclosure, or loss. Access to your personal data is limited to those employees, agents, and processors who require it for carrying out their duties.
Retention of Personal Data
Flower Delivery Watford retains personal data only for as long as is necessary for the purposes for which it was collected:
- Order and transaction records are generally retained for up to six years to comply with tax and accounting regulations.
- Account and communication data are retained for as long as your account is active or as needed to provide you with support.
- Where data is processed on the basis of your consent, it is retained until you withdraw consent unless a longer retention period is required for legal purposes.
Processors and Data Sharing
In order to fulfill your orders and provide our services, we may share your data with trusted third parties who process data on our behalf. These include:
- Payment processors for secure transaction handling.
- Delivery partners to ensure flowers are delivered to the correct address.
- IT service providers for website hosting, maintenance, and support.
All processors are required to adhere to GDPR and provide adequate safeguards for protecting personal data. Your personal data is not shared, sold, or transferred to any third parties for their own marketing purposes. Personal data is only shared or disclosed to authorities if required by law.
Your Rights as a Data Subject
Under GDPR, you have specific rights regarding your personal data. These include:
- Right of Access: You can request confirmation of whether we hold personal data about you, and request a copy of the data we hold.
- Right to Rectification: You can ask us to correct inaccurately recorded data about you.
- Right to Erasure: Also known as the ‘right to be forgotten’, you may ask us to delete your data in certain circumstances.
- Right to Restriction: You can request that processing of your personal data is suspended under certain conditions.
- Right to Data Portability: You may request your data in a structured, commonly used, and machine-readable format.
- Right to Object: You may object to certain kinds of processing, including direct marketing.
- Right to Withdraw Consent: Where we process data based on your consent, you have the right to withdraw this at any time.
Children’s Privacy
Our services are not directed towards individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we may have collected data from a child, please contact us so we can take appropriate measures.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our processing practices. Updates will be posted on this page, and where significant changes occur, we will take reasonable steps to inform you.
Contact and Queries
If you have questions about this Privacy Policy or need to exercise your data rights, please contact us through the customer service channels provided on our website.