GDPR Privacy Policy for Flower Delivery Purfleet
Privacy Policy Overview
This Privacy Policy explains how Flower Delivery Purfleet ("we", "our", or "us") collects, uses, stores, and protects personal data of customers placing flower delivery orders from Purfleet and surrounding districts. It also details your rights in relation to your personal information and our lawful bases for processing under the General Data Protection Regulation (GDPR).
Who This Policy Applies To
This policy covers all individual customers who place or enquire about flower deliveries with Flower Delivery Purfleet, whether for themselves or on behalf of others, and regardless of the method of contact (website, phone, or in-person). The policy also applies to visitors who interact with our website and services from Purfleet and surrounding districts.
What Personal Data We Collect
We collect the following types of personal data directly from you when you place an order, make an enquiry, or interact with our services:
- Contact Details: Such as name, address (delivery and billing), phone number, and (if provided) email address.
- Order Information: Details of products ordered, messages to be included, delivery instructions, and recipient details (name, address, phone number).
- Payment Information: Details necessary to process your payment such as transaction reference, but not full payment card details (handled by secure payment processors).
- Communication Records: Correspondence via telephone, website form, or written letters.
- Website Usage Data: Information collected via cookies and similar technologies about how you use our website, including IP address, browser type, dates/times of visit, and pages viewed.
Lawful Basis for Processing
We process your personal data based on at least one of the following lawful bases as set out in Article 6 of the GDPR:
- Contractual Necessity: Processing your personal data is necessary to enter into or perform our contract with you. For example, processing your order and delivering flowers to the recipient.
- Legal Obligation: We may need to process certain data to comply with legal and regulatory requirements, such as tax or accounting rules.
- Legitimate Interest: We process data to improve our services, prevent fraud, and manage our business efficiently, as long as it does not override your fundamental rights and freedoms.
- Consent: In circumstances where you provide explicit consent (such as opting-in for marketing communications), we process your data accordingly. You may withdraw this consent at any time.
How We Use Your Data
We use your personal information to:
- Process and fulfill your orders and any special requests.
- Communicate regarding your orders, including confirmations, updates, and problem resolution.
- Deliver flowers to the recipient specified by you.
- Respond to your direct queries, requests, or feedback.
- Conduct administrative and internal business operations.
- Improve our website, customer service, and offerings through analysis of usage data.
- If consent is provided, inform you about new products, services, or events relevant to Flower Delivery Purfleet.
Sharing and Disclosure of Your Data
We only share your data when necessary, and always in accordance with GDPR requirements:
- Payment Service Providers: For secure payment processing. These providers are themselves data controllers or processors subject to GDPR.
- Delivery Suppliers: Third-party couriers or drivers engaged to fulfill your order. They receive only the necessary details for delivery (e.g., recipient name, address, and any delivery instructions).
- IT and Hosting Providers: Companies assisting with hosting our website and storing our digital data.
- Professional Advisors: Such as accountants or legal counselors, subject to confidentiality and legal obligations.
- Legal Authorities: Where required by law or to protect our legal interests, we may disclose information to police or relevant authorities.
We do not sell or rent your personal data to any third parties. All third-party service providers and processors are chosen for their commitment to data protection standards and are contractually obliged to process data only on our behalf and according to our instructions.
Data Retention
Your personal data is retained only for as long as is necessary for the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements.
Typically, order-related information is kept for a minimum of six years to comply with legal obligations and potential customer service issue resolution. Non-essential correspondence and cookies-related technical data may be held for shorter periods, in accordance with our management and retention schedules. After the retention period, data is securely deleted or anonymised.
Your Data Rights
Under GDPR, you have the following rights concerning your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any inaccurate or incomplete data.
- Right to Erasure ("Right to Be Forgotten"): Ask us to delete your data where there is no valid reason for us to retain it.
- Right to Restrict Processing: Ask us to temporarily restrict processing if you have contested its accuracy, or in certain other circumstances.
- Right to Data Portability: Receive your data (or ask us to transfer it directly) in a machine-readable format.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
To exercise any of these rights, you can contact us using the details provided when you placed your order or via our website contact form. Please note some rights apply only in certain circumstances and we may need to verify your identity before acting on a request.
Automated Decision Making
We do not conduct any automated decision-making or profiling that produces significant effects concerning you based solely on automated processing of your personal data.
Security of Your Information
We take appropriate technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. These measures include encryption of communications, access controls to IT systems, secure physical storage (where applicable), and ongoing staff training in data protection best practice.
Policy Changes
We may update this Privacy Policy from time to time. Any changes will be posted on our website and, where appropriate, notified to you. Please check periodically to ensure that you are aware of the most current version.
Contact and Complaints
If you have questions about this policy or how we handle your data, please contact us via the method you used when placing your order or through our website contact channels. If you believe your data protection rights have been breached, you have the right to complain to the Information Commissioner's Office (ICO) or your local data protection supervisory authority.