Privacy Policy for Flower Delivery Egham
Introduction
This Privacy Policy explains how Flower Delivery Egham (‘we’, ‘our’, ‘us’) collects, uses, processes, and protects the personal data of customers ordering flower deliveries from Egham and the surrounding districts. We are committed to processing your data transparently, fairly, and in accordance with the UK General Data Protection Regulation (UK GDPR).
Scope
This policy applies to all individuals placing an order with Flower Delivery Egham, whether online, by phone, or in person, for delivery to addresses within Egham and adjacent areas. By using our services, you acknowledge your understanding of how your data will be handled as described below.
What Personal Data We Collect
To provide our services, we may collect the following types of personal data from you:
- Identification and Contact Details: Full name, delivery address, phone number, and billing address.
- Order Details: Purchase history, delivery preferences, and any special instructions supplied with your order (such as messages for bouquets).
- Payment Information: Payment card details provided at checkout. Payments are securely processed and Flower Delivery Egham does not store complete card details after processing your transaction.
- Communication Data: Your interactions with us regarding enquiries, order confirmations, complaint resolutions, or feedback.
- Technical Data: Device and browser information, IP addresses, and cookies necessary for the secure operation and functionality of our website.
Lawful Basis for Processing Personal Data
Under the GDPR, we must have a lawful basis to process your personal information:
- Contractual Necessity: We process your information to fulfil the contract with you when you place an order. This includes processing payments, arranging delivery, and keeping you updated about your order status.
- Legal Obligation: We retain certain records and process data as required by applicable financial, consumer, and tax regulations.
- Legitimate Interests: We may use your data for purposes such as quality control, analytics, and customer service improvement, provided these interests do not override your fundamental rights and freedoms.
- Consent: Where required (e.g., for marketing communications), we will seek your explicit consent. You can withdraw consent at any time.
How We Use Your Personal Data
We use your information to:
- Process and deliver your orders accurately.
- Verify your identity and prevent fraudulent transactions.
- Respond to your enquiries and resolve issues.
- Improve our products, website experience, and customer support.
- Comply with legal and regulatory obligations.
- Send updates about your order, or marketing (if you have agreed to receive it).
How Your Data is Shared and Processed
Flower Delivery Egham may share certain personal data with third parties as necessary to provide our services and comply with the law, always ensuring your data is protected. These include:
- Payment Processors: Securely process your payment information for order fulfilment.
- Delivery Partners: Share relevant delivery information to ensure your flowers arrive at the correct address.
- IT and Website Hosting Providers: To securely store and manage data, preventing unauthorised access or loss.
- Professional Advisors: Legal, tax, or regulatory advice when required.
All our third-party service providers are required to process your personal information only in accordance with our instructions and not for their own purposes.
International Data Transfers
Your personal data may, in limited circumstances, be transferred to and processed in countries outside the UK and the European Economic Area (EEA). Where we do so, we ensure appropriate safeguards such as Standard Contractual Clauses or equivalent legal protections are in place to maintain data protection standards.
How Long We Keep Your Data (Retention Policy)
Flower Delivery Egham retains your personal data only for as long as necessary for the purposes outlined in this Privacy Policy, including:
- Order Records: Typically kept for up to seven years to comply with accountancy and legal obligations.
- Marketing Preferences: Retained until you withdraw consent or opt out.
- Website Analytics: Retained as outlined in our cookie policy, for no longer than necessary.
Once data is no longer needed, we ensure it is securely deleted or anonymised.
Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Ask us to correct incomplete or inaccurate information.
- Right to Erasure: Request deletion of your data, provided legal obligations do not require retention.
- Right to Restrict Processing: Ask us to restrict the use of your data in certain circumstances.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Data Portability: Request the transfer of your personal data to you or another service provider.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.
If you wish to exercise any of these rights, please contact us using the details provided on our website.
Data Security
We use technical and organisational measures to protect your data against unauthorised access, theft, loss, or destruction. This includes encryption, secure servers, and regular review of our data protection practices.
Policy Updates
We regularly review and may update this Privacy Policy to reflect changes in our processing or legal requirements. Please check this page periodically for the latest information.
Contact and Complaints
If you have questions about this policy or are concerned about how your personal data is processed, please refer to the contact details provided on our website. You also have the right to lodge a complaint with the relevant supervisory authority.