GDPR-Compliant Privacy Policy for Flower Delivery Bromley
Introduction
This Privacy Policy explains how Flower Delivery Bromley collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and other relevant data protection legislation. This policy applies to all customers placing orders with Flower Delivery Bromley within Bromley and its surrounding districts. By using our services, you acknowledge and accept the practices described in this policy.
What Personal Data We Collect
To fulfil your flower delivery orders efficiently and provide a high standard of service, Flower Delivery Bromley may collect the following types of personal data:
- Contact Information: Such as your full name, delivery address, phone number, and any additional delivery contact details provided.
- Order Information: Including details about the products you order, recipient names and addresses, personalised messages, and delivery times.
- Payment Details: Partial payment information required to complete your purchase (note: full card details are not stored by Flower Delivery Bromley; these are processed securely by our payment processors).
- Account Credentials: If you create an account, we collect your username and an encrypted version of your password.
- Communication Records: Including emails, feedback, and correspondence related to orders or customer service requests.
- Technical Information: Such as IP address, browser type, device type, and cookies, which are collected to improve user experience and manage site functionality.
Lawful Bases for Data Processing
Flower Delivery Bromley processes your personal data based on the following lawful grounds under the GDPR:
- Contractual Necessity: Processing is required to fulfil our contract with you – for example, to process and deliver your order and handle payments.
- Legal Obligation: We may process your information to meet legal and regulatory requirements, such as records for financial and tax purposes.
- Legitimate Interests: We have a legitimate interest in processing your data for purposes like enhancing our services, preventing fraud, securing our website, and handling customer service communications, provided these interests are not outweighed by your rights and freedoms.
- Consent: Where applicable, such as for sending marketing communications, we may request your explicit consent. You can withdraw your consent at any time.
How We Use Your Personal Data
We use your personal data to:
- Process and deliver your flower orders accurately and efficiently.
- Send order confirmations, update you about delivery status, or address any issues concerning your order.
- Facilitate payments securely via our selected payment processors.
- Respond to your inquiries, requests, or feedback.
- Enhance the performance, security, and usability of our website.
- Comply with applicable laws and regulatory requirements.
- Send promotional materials or service updates if you have consented to receive them.
Who Accesses or Processes Your Data
We may share your data with trusted third parties in order to deliver our services effectively. These may include:
- Payment Processors: To handle payments securely and in compliance with PCI DSS standards.
- Delivery Partners: In order to successfully deliver your flower orders to the intended recipients.
- IT and Website Hosting Providers: For maintaining the security and operation of our website.
- Professional Advisors: Such as accountants or legal advisors, where required for business operations and compliance.
All processors and third-party service providers are contractually required to protect your data and only process it as directed by Flower Delivery Bromley. We do not sell or rent your information to third parties for their own marketing purposes.
Data Retention: How Long We Keep Your Information
Your personal data is retained only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting obligations. For example, order records may be kept for a period necessary to meet tax laws or resolve disputes, after which data will be securely deleted or anonymised. Data relating to your customer account will be kept as long as your account remains active or until you request its deletion.
Your Rights Under the GDPR
As a customer within Bromley and surrounding districts, you have specific rights regarding your personal data under the GDPR:
- Right of Access: You can request a copy of personal data we hold about you.
- Right to Rectification: You can ask for errors or inaccuracies in your personal data to be corrected.
- Right to Erasure: You may request that we delete your personal data where there is no overriding legal obligation for its continued processing.
- Right to Restrict Processing: You may ask us to restrict the use of your personal data in specific circumstances.
- Right to Data Portability: You have the right to receive your personal data in a commonly used and machine-readable format, and to request its transfer to another controller.
- Right to Object: You may object to how we use your personal data in certain situations, including for direct marketing purposes.
- Right to Withdraw Consent: Where data processing is based on your consent, you can withdraw that consent at any time.
To exercise any of these rights, please contact us using the methods provided on our website. We may require authentication or further information to verify and fulfill your request. All rights requests will be considered according to legal obligations and legitimate business requirements.
Security of Your Information
Flower Delivery Bromley takes security seriously and implements appropriate technical and organisational measures to protect your personal data from unauthorised access, accidental loss, destruction, or damage. These measures include secure data storage, encrypted connections, restricted access, and regular reviews of our security protocols.
Changes to This Privacy Policy
This privacy notice may be updated periodically to reflect changes in our processing, regulatory requirements, or the introduction of new services. We encourage you to review this policy regularly to stay informed of any updates.
How to Contact Us
If you have any queries or concerns about our use of your personal data, or if you wish to exercise your rights, please refer to the contact information available on our website. We will respond to your request as soon as possible and in accordance with applicable laws.
This policy was last reviewed and updated in June 2024.