Privacy Policy for Flower Delivery Ruislip
Privacy Statement
This Privacy Policy explains how Flower Delivery Ruislip collects, uses, stores, and protects your personal data when you place orders from Ruislip or nearby districts. We are committed to handling your information securely and transparently in accordance with the General Data Protection Regulation (GDPR).
Scope of This Policy
This policy applies to all customers placing orders for flower delivery services through Flower Delivery Ruislip within Ruislip and surrounding districts, whether online, by phone, or in person. By engaging our services, you agree to the terms outlined in this Privacy Policy.
What Data We Collect
We collect various types of information to process your orders efficiently and deliver your flowers as requested. The categories of personal data we may collect include:
- Contact Details: Name, telephone number, and delivery address of the sender and recipient.
- Order Information: Details of flower arrangements and accompanying messages.
- Payment Details: Billing address, payment method, and transaction confirmation (please note, we do not store full payment card details).
- Communication Records: Correspondence related to orders, queries, complaints, or feedback.
- Technical Data: IP address, browser type, device information, and cookies related to your engagement with our website.
Lawful Basis for Processing Your Data
Under GDPR, we must have a valid reason, known as a lawful basis, for processing your personal data. We rely on the following bases:
- Contractual Necessity: Most of the data we process is necessary to fulfil your order and provide our services.
- Legitimate Interests: We may use data to improve our services, prevent fraud, or ensure the security of our platform, provided your rights do not override our interests.
- Legal Obligations: At times, we may need to process data to comply with legal or regulatory requirements (for example, for tax purposes).
- Consent: We will request your explicit consent before sending you direct marketing communications where required by law. You can withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing and delivering flower orders and related services
- Communicating with you regarding your order status or queries
- Improving our products, services, and user experience
- Maintaining legal and financial records
- Ensuring the security of our website and operations
- Sending promotional materials, only if you have provided consent
Data Sharing and Processors
We do not sell or rent your personal information to third parties. However, in order to carry out our business operations, your data may be shared with trusted entities as follows:
- Payment Processors: Secure payment providers process your payment information on our behalf according to strict data security standards.
- Delivery Partners: Courier or logistics services may require recipient and order details to fulfil the delivery.
- IT Service Providers: Companies that support our website and information systems may have limited access to data for maintenance and support purposes.
- Regulatory Authorities: Where we are legally required, we may share necessary data with government authorities.
All third parties that act as data processors on our behalf must adhere to confidentiality agreements and process your data in accordance with GDPR.
Data Retention
We retain your personal information only for as long as necessary for the purposes for which it was collected, including to fulfil orders, meet legal obligations, resolve disputes, and enforce our agreements. The specific retention period depends on the nature of the data:
- Order and contact information are typically retained for up to six years to comply with financial and record-keeping requirements.
- Technical and analytical data may be kept in anonymised form for a longer period to help us improve our services.
- Marketing consent records are retained until you withdraw consent or request removal.
When data is no longer necessary, it will be securely deleted or anonymised.
Your Data Protection Rights
Under GDPR, you have several important rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can correct any inaccuracies or incomplete data.
- Right to Erasure ('Right to be Forgotten'): You may request removal of your data in certain circumstances.
- Right to Restrict Processing: You can ask us to restrict processing of your data if you contest accuracy or object to processing.
- Right to Data Portability: You may request your data be transferred to another organisation or directly to you.
- Right to Object: You can object to processing of your data for direct marketing purposes or where processing is based on legitimate interests.
- Right to Withdraw Consent: If processing is based on consent, you may withdraw this at any time, without affecting the lawfulness of processing conducted prior to withdrawal.
Data Security
We employ appropriate technical and organisational measures to protect your data from unauthorised access, disclosure, alteration, or destruction. These measures include access controls, encryption where appropriate, regular security reviews, and staff training on data protection requirements.
Cookies and Tracking
Our website uses cookies and similar tracking technologies to enhance your user experience, analyse site usage, and provide tailored content. Where legally required, you will be asked for consent to use non-essential cookies. More information about the types of cookies and your choices can be found in our Cookies Policy.
Changes to This Policy
We may amend this Privacy Policy from time to time to reflect changes in law, technology, or our business practices. Any updates will be posted promptly. Your continued use of our services signifies your acceptance of these updates.
Contact and Queries
If you wish to exercise your data protection rights or have questions about this Privacy Policy, you can contact us by using the contact form on our website or via postal mail to our registered business address. We will respond to your request in accordance with GDPR requirements.