GDPR-Compliant Privacy Policy for Flower Delivery Aldgate
Introduction
This Privacy Policy describes how Flower Delivery Aldgate collects, uses, retains, and protects your personal data in accordance with the General Data Protection Regulation (“GDPR”). This policy applies to all customers placing orders with Flower Delivery Aldgate from Aldgate and surrounding districts, whether orders are placed online, by phone, or in person. We are committed to handling your data transparently, ethically, and lawfully.
1. What Data We Collect
We collect and process various types of personal data to provide our flower delivery services, fulfil our contractual obligations, and improve your experience. The categories of data we collect include:
- Identity Data: First name, last name.
- Contact Data: Delivery address, billing address, postcode, phone number.
- Order and Transaction Data: Products ordered, order notes, special instructions, date and time of order, payment information (processed securely via third-party payment processors), and transaction history.
- Recipient Data: Name, address, and contact number of the person receiving the flowers (if different from the customer).
- Communication Data: Records of communications with us, including messages and call logs when interacting with customer service.
- Technical Data: IP address, browser type, device information, and cookies (for online orders only), as necessary for site functioning and security.
We do not intentionally collect or store sensitive personal data (special category data) such as health, religious, or biometric information.
2. Lawful Basis for Processing
Under GDPR, we rely on the following lawful bases to process your personal data:
- Contractual Necessity: Processing data is necessary to enter into and fulfil the contract for your flower delivery order, including processing payment, fulfilling delivery, and communicating updates.
- Legitimate Interests: We may process data for our legitimate business interests, such as improving services, maintaining security, or responding to your queries, provided these interests do not override your fundamental rights and freedoms.
- Legal Obligation: We may process or retain data where required to comply with legal obligations, such as maintaining tax records.
- Consent: For certain purposes, such as marketing communications (if applicable), we will seek your explicit consent. Consent is voluntary and can be withdrawn at any time.
3. How We Use Your Data
Your personal data is used strictly for the purposes for which it was collected. Specifically, we use it to:
- Process and fulfil your flower delivery orders, including handling payment and confirming delivery details.
- Contact you or the recipient regarding delivery updates, order issues, or queries.
- Respond to your customer service requests and maintain service quality.
- Maintain records for accounting and legal purposes.
- Enhance our website functionality and user experience (if you order online).
- (If agreed) Send you relevant news, promotions, or updates about our services.
4. Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes described above and to meet our legal or regulatory obligations.
- Order and transaction data will typically be kept for up to seven years for tax and accounting purposes.
- Contact and communication records are retained while active or as required for dispute resolution, then securely deleted.
- Marketing data (where consented) is retained until you unsubscribe or withdraw consent.
After such periods, data will be securely deleted or anonymised so you cannot be identified.
5. Data Processors and Sharing
We may share your data with trusted third-party service providers (“processors”) strictly for the purposes of providing our services. This may include:
- Payment processors for handling secure payments.
- Delivery partners or couriers to carry out flower deliveries.
- IT and hosting providers for website management and data security.
- Professional advisors (e.g., accountants), only if legally required.
We ensure all processors comply with GDPR and impose strict data protection and confidentiality obligations. Your personal data is not sold or shared for unrelated marketing purposes.
Your data may be transferred and processed outside the UK or European Economic Area if necessary, but always subject to appropriate safeguards as required by law.
6. Security of Your Data
We take data security seriously. We implement appropriate organisational and technical measures to protect your data from loss, theft, unauthorised access, or disclosure. Access to your data is strictly limited to personnel with a legitimate need as part of their role. Where third-party processors are used, we ensure they meet equivalent security standards.
7. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure: You can ask us to delete your data where it is no longer needed or if you withdraw consent.
- Right to Restrict Processing: You can request to limit the processing of your data in specific circumstances.
- Right to Data Portability: You can request to receive your data in a structured, machine-readable format or have it sent to another controller.
- Right to Object: You can object to processing where we rely on legitimate interests.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw this consent at any time without affecting prior processing.
- Right to Complain: You have the right to lodge a complaint with the Information Commissioner’s Office or your local supervisory authority.
8. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law, our practices, or service offerings. Any significant updates will be clearly indicated on our website. We recommend that you review this policy periodically.
9. Contacting Us
If you have questions about this Privacy Policy, your data rights, or would like to exercise your rights, please contact us by using the official channels listed on the Flower Delivery Aldgate website. We will respond as required under GDPR and aim to resolve all concerns promptly and transparently.