Our GDPR-Compliant Customer Privacy Policy
Introduction
This Privacy Policy explains the principles guiding how Flower Delivery Cockfosters ("we," "us," or "our") collects, uses, stores, and safeguards your personal data when you place orders through our services in Cockfosters and the surrounding districts. We are committed to protecting your privacy and managing your information in accordance with the General Data Protection Regulation (GDPR).
Scope of this Policy
This policy applies to all personal data collected from our customers when placing flower delivery orders with Flower Delivery Cockfosters, whether via our website, by phone, or in person, across Cockfosters and neighboring districts. By ordering from us, you acknowledge and accept the practices described in this Privacy Policy.
Personal Data We Collect
We collect and process only the information necessary to provide and improve our flower delivery services. The data we collect includes:
- Contact Information: Your full name, recipient's name, delivery address, billing address, phone number.
- Order Details: Purchase history, bouquet/arrangement preferences, delivery instructions, desired delivery date and time.
- Payment Information: Card or payment details are processed securely by our payment processor and are not stored by us.
- Communication Records: Details of correspondence between you and us for customer support or service queries.
- Website Usage Data: IP address, device type, browser details, and cookies, to enhance your online experience and improve our website.
Lawful Basis for Data Processing
Under the GDPR, we must have a valid legal basis for processing your personal data. We rely on the following grounds:
- Performance of a Contract: We process your data to fulfill your flower delivery order, communicate with you about your purchase, and provide requested services.
- Legal Obligation: We may process your information to comply with applicable laws, such as invoicing and tax regulations.
- Legitimate Interests: We use data to improve our services, ensure security, and prevent fraud, provided such interests are not overridden by your data protection rights.
- Consent: Where required (such as for direct marketing), we obtain your explicit consent before processing your data.
How We Use Your Data
Your personal information is used for the following purposes:
- To process and deliver your flower orders efficiently and accurately.
- To communicate with you regarding your order status or to confirm delivery instructions.
- To manage payment transactions securely.
- To respond to customer enquiries, requests, or complaints.
- To improve our products, services, website functionality, and user experience.
- To comply with legal, accounting, and regulatory requirements.
- For internal record-keeping and service quality analysis.
Data Retention
We retain your personal data only as long as necessary for the purposes outlined in this policy or to comply with legal, regulatory, or accounting requirements:
- Order data is retained generally for up to seven years for tax and legal reasons.
- Customer service correspondence is kept for up to two years to manage follow-ups or repeat queries.
- Cookies and website analytics data are retained as per our cookie policy, generally no longer than 26 months.
Once your information is no longer required, it is securely deleted or anonymized.
Data Processors and Third Parties
To provide our services, we may share your personal data with trusted third-party processors. These include:
- Payment processors (to secure your transactions)
- Delivery partners or couriers (to complete deliveries)
- IT service providers (for secure website hosting, email, and support)
- Professional advisors (such as accountants and legal advisors, where required)
All third-party providers are obligated to handle your personal data in accordance with our instructions and GDPR requirements. We do not sell or rent your information to third parties for marketing purposes.
How We Protect Your Data
Your data security is paramount. We implement suitable technical and organisational measures to prevent unauthorised access, loss, or misuse of your data, including:
- Encryption of data during transmission and storage
- Secure payment gateways for transaction processing
- Regular staff training on data protection
- Restricted access to customer information within our company
Your Data Protection Rights
Under the GDPR, you have the following rights in relation to your personal data:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete information.
- Erasure: Request deletion of your personal data when there is no legal reason to keep it.
- Restriction: Limit or object to how we use your data in certain circumstances.
- Portability: Receive your data in a structured, commonly-used, machine-readable format.
- Withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, please contact us through our standard communication channels. We will respond to your requests in line with GDPR guidelines and within one month, unless a longer period is permitted by law in more complex cases.
International Data Transfers
We store and process your information within the United Kingdom and the European Economic Area (EEA). Should we need to transfer data outside the EEA, we ensure appropriate safeguards are in place to protect your rights to privacy.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, regulatory requirements, or for other operational reasons. Significant changes will be communicated to our customers. Please review this policy periodically for the latest information on our data protection practices.
Contact and Complaints
If you have questions about this Privacy Policy or how we handle your data, or if you wish to make a complaint, please reach out using our standard customer service channels. You are also entitled to lodge complaints with the Information Commissioner’s Office or your relevant supervisory authority.
This policy was last updated in June 2024.