Privacy Notice for Customers – Flower Delivery West Byfleet
Introduction
This Privacy Policy sets out how Flower Delivery West Byfleet collects, stores, processes, and protects your personal information in accordance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers placing Flower Delivery West Byfleet orders from West Byfleet and the surrounding districts. We are committed to ensuring that your privacy is protected, and that your personal data is handled transparently, fairly, and lawfully.
What Data We Collect
When you place an order with Flower Delivery West Byfleet, interact with our customer services, or use our website and related services, we may collect the following types of personal data:
- Contact Information: Your name, delivery address, billing address, email address, and telephone number(s).
- Order Details: Details relating to your flower orders, delivery instructions, product preferences, and payment confirmation (we do not process or store raw card details; payments are managed by secure third-party processors).
- Recipient Information: For delivery purposes, we may collect recipient name, delivery address, and contact number if different from the customer.
- Communication Records: Any correspondence or communications between you and our team including feedback, queries, and complaints.
- Technical Data: Information collected automatically via cookies and tracking technologies including browser type, IP address, device information, and usage data related to the browsing of our website.
Lawful Basis for Processing
Our processing of your personal data is always underpinned by a lawful basis as required by GDPR. The legal bases we rely on include:
- Contractual Necessity: Most data collection occurs because it is necessary for us to perform a contract with you (processing and delivering your order, communicating order status, managing payment).
- Legitimate Interests: We may use your data for our legitimate business interests (improving our services, preventing fraud, and handling customer feedback), provided your rights and interests do not override those interests.
- Legal Obligations: We may process and retain personal data to comply with legal requirements (such as taxation and consumer protection obligations).
- Consent: Where we use cookies (other than those strictly necessary for site operation) or send certain types of marketing communications, we do so only with your explicit consent. You can withdraw consent at any time.
How We Use Your Personal Data
We use your personal information for the following purposes:
- To process, fulfil, and deliver your flower or gift order accurately and on time
- To communicate with you about your order, delivery status, and any customer service queries
- To fulfil our contractual obligations and maintain proper records for accounting, compliance, and legal purposes
- To improve our products and services through customer feedback and analytics
- To enhance your experience using our website via analytics, security, and performance monitoring
- To send promotional material or service updates if you have opted in
Data Retention
We retain your personal data only as long as is necessary for the purposes stated in this policy, or as required by applicable law. The retention periods depend on the nature of the information and why it is collected:
- Order and Transaction Data: Typically retained for a minimum of six years for accounting and tax purposes from the date of your last order.
- Marketing Consent: Data used for marketing purposes is retained until you withdraw consent or opt out of receiving communications.
- Communication Records: Retained as long as necessary to resolve disputes and fulfil customer service obligations, typically up to two years after the last interaction.
- Technical Data and Cookies: Stored in accordance with our cookie management policy, which follows industry best practice and applicable legislation.
After these periods, your personal data is securely deleted or anonymised.
Processors & Data Sharing
We may share your personal data with trusted third-party processors when it is necessary for the operation of our business or fulfilment of our services. These include:
- Payment service providers to securely process your payments
- Delivery couriers and logistics partners for order delivery
- IT support and hosting providers to operate our website and manage data security
- Professional advisers and legal bodies for compliance and accountability
All third-party processors are carefully selected and operate under appropriate contractual and legal obligations to ensure your data is handled according to the requirements of the GDPR and this Privacy Policy. We do not sell or lease your data to third parties.
International Data Transfers
Your personal information is generally processed within the United Kingdom and European Economic Area. Where we use third-party service providers located outside these territories, we ensure appropriate safeguards are in place to protect your data in accordance with the GDPR, such as the use of standard contractual clauses or reliance on adequacy decisions.
Data Security
We have implemented suitable technical and organisational measures to safeguard your personal information against unauthorised access, disclosure, alteration, or destruction. These measures include secure servers, encryption, limited access controls, and regular security reviews. However, please note that no online transmission or storage is completely secure; we encourage you to exercise care when sharing information online.
Your Rights
Under the GDPR, you have several rights in relation to your personal data. These include:
- Access: Request a copy of the personal data we hold about you.
- Rectification: Ask us to correct inaccurate or incomplete data.
- Erasure ("Right to be Forgotten"): Request the deletion of your data where justified.
- Restriction of Processing: Ask us to limit how we use your data under certain conditions.
- Data Portability: Request your data in a portable format for transfer to another organisation where technically feasible.
- Objection: Object to processing based on legitimate interests or direct marketing.
- Withdraw Consent: Withdraw your consent to data processing where consent is the lawful basis.
To exercise any of these rights, or for questions concerning this privacy policy or your data, please contact us via the contact methods provided on our website.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or for legal or regulatory reasons. Any updates will be posted on this page with a changed revision date. Please review this Policy from time to time to ensure you remain informed about how we use and protect your information.
Contact & Complaints
If you have any concerns about the way your personal data is processed, you may contact us using the details provided on our website. Should you remain dissatisfied, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK supervisory authority for data protection issues.