Flowers Stockwell GDPR Privacy Policy
Introduction
This Privacy Policy explains how Flowers Stockwell (“we”, “us”, “our”) collects, uses, manages, and protects the personal information of customers placing orders with us in the district of Stockwell and surrounding areas. We are committed to ensuring that your privacy is protected in compliance with the General Data Protection Regulation (GDPR). This Policy outlines the types of data we collect, the purpose and legal basis for processing, how long we retain your data, the third-party processors we use, and your rights regarding your personal information.
Scope of the Policy
This Privacy Policy applies to all customers who place orders with Flowers Stockwell, whether through our website, by telephone, or in person, and who are based in Stockwell and its neighbouring districts. By placing an order or communicating with us, you acknowledge the practices described in this Policy.
What Data We Collect
We collect and process personal data that is necessary for processing your order and providing our services. Depending on how you interact with us, this may include:
- Name: To identify you and address you appropriately.
- Contact Information: Such as your address, phone number, and, if applicable, email address, so that we can deliver your order and contact you with updates or issues related to your order.
- Order Details: Such as your purchase history, items ordered, delivery recipient information, delivery address, and special instructions for delivery.
- Payment Information: Payment card data is processed securely by third-party payment processors; we do not store full card details. We may retain payment confirmation or transaction IDs for our records.
- Correspondence: Any communications you have with us, such as feedback, complaints, or requests for information.
Lawful Basis for Processing Data
The GDPR requires that we have a lawful basis for processing your personal data. The specific lawful bases on which we rely are:
- Contractual Necessity: We use your data to fulfil our obligations to you, such as processing your orders, delivering products, and handling payments.
- Legal Obligation: We may retain information for accounting, tax, or regulatory compliance as required by law.
- Legitimate Interests: We may use your data to improve our services, resolve queries, or prevent fraud, provided this does not override your rights and freedoms.
- Consent: For certain marketing communications (if any), we may rely on your explicit consent. You may withdraw your consent at any time.
How We Use Your Data
Your personal information is used to:
- Process and deliver your flower orders.
- Communicate with you about your order status, changes, or queries.
- Respond to your requests, questions, or customer service needs.
- Handle payments and billing related to your purchases.
- Carry out record-keeping and comply with financial, legal, and accounting obligations.
- Improve our products, services, and customer experience.
Retention of Data
We retain your personal information only for as long as necessary to fulfil the purposes outlined in this Policy, unless a longer retention period is required or permitted by law. Specifically:
- Order and customer data is retained for up to six years to meet regulatory and accounting requirements.
- Correspondence and complaints may be kept for up to three years for customer service monitoring and improvements.
- If you exercise your rights regarding your data (such as a request for erasure), we will retain minimal data as needed to document compliance with data protection obligations.
Data Processors and Third Parties
To deliver our services effectively, we may share your information with trusted third-party service providers acting as data processors on our behalf. These may include:
- Delivery Partners: To ensure your order reaches the correct address.
- Payment Processors: For secure handling of your payments and to process transactions.
- IT and Website Service Providers: To support our website functionality and manage digital communications.
- Professional Advisors and Regulators: If required by law or to protect our legal rights.
All our processors are contractually obliged to handle your data securely and only in accordance with our instructions. We do not sell or rent your information to external companies.
Your Rights Under the GDPR
As a data subject, the GDPR grants you several rights regarding your personal information. These include:
- Right of Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You may ask us to correct any inaccurate or incomplete data.
- Right to Erasure: In certain circumstances, you can request that we delete your information.
- Right to Restriction of Processing: You may ask us to restrict processing if you contest the accuracy of data or object to its use.
- Right to Data Portability: You may request your data in a machine-readable format for transfer to another service provider.
- Right to Object: You can object to our use of your data based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: If processing is based on consent, you can withdraw this at any time.
If you wish to exercise any of these rights, please contact us using the details provided on our website or in our customer communications. We will respond within the timeframe set by law, typically within one month.
Data Security
We implement both technical and organisational measures to protect your data against unauthorised access, alteration, disclosure, or destruction. This includes secure storage systems, access controls, staff training, and regular review of our data protection practices.
Policy Updates
We may update this Privacy Policy periodically to reflect changes to our practices, legal requirements, or for other operational reasons. The most current version will always be available on our website, with the date of last revision stated clearly.
Contact and Complaints
If you have questions or concerns about our handling of your personal information, or if you wish to make a complaint, please use the contact details provided on our website. Should you remain unsatisfied, you also have the right to lodge a complaint with the relevant supervisory authority under the GDPR.
Effective Date
This Policy is effective from 1st June 2024 and applies to all customers placing orders from Stockwell and the surrounding districts.