Flower Delivery Barnet Privacy Commitment
Introduction
This Privacy Policy describes how Flower Delivery Barnet ('we', 'us', 'our') collects, uses, and protects the personal data of customers placing flower delivery orders in Barnet and surrounding districts. It ensures transparency in our practices and demonstrates compliance with the General Data Protection Regulation ("GDPR"). This policy applies to all data subjects interacting with our services, whether by phone, online, or in-person.
What Data We Collect
To provide our flower delivery services, we collect and process the following categories of personal data:
- Contact Information: Name, delivery address, billing address, and telephone number.
- Order and Transaction Details: Details of flower orders, purchase history, delivery preferences, and payment method (note that payment card data is collected and processed only in accordance with secure payment standards).
- Communication Data: Any correspondence with us (including queries, feedback, complaints, and instructions), and any messages attached to your orders.
- Website Usage Data: Information such as IP address, browser type, device information, and usage statistics, collected via cookies and similar technologies, to improve website experience and maintain security.
Lawful Bases for Processing
Our processing of your personal data relies on one or more of the following GDPR-compliant lawful bases:
- Contractual Necessity: To fulfil and deliver your order, manage payments, and provide customer services.
- Legal Obligation: To comply with laws regarding record-keeping, accounting, and fraud prevention.
- Legitimate Interests: To improve and secure our services, respond to customer queries, maintain business operations, and send customers relevant service communications.
- Consent: Where we seek your agreement, such as for sending marketing communications or processing certain optional data not essential to your order.
Data Retention Periods
Flower Delivery Barnet retains your personal data only as long as necessary for the purposes it was collected, including fulfilling orders, complying with legal obligations, addressing disputes, and enforcing agreements. Unless longer retention is required by law (e.g., for tax or accounting regulations), typical retention periods are as follows:
- Order Records: Retained for up to 7 years from the date of your last purchase, in line with legal and financial reporting obligations.
- Correspondence: Retained for up to 3 years after the resolution of your query or complaint.
- Marketing Preferences: Maintained until you withdraw consent or update your preferences.
- Website Usage Data: Anonymised data may be kept for analytics purposes; identifiable logs are kept for a maximum of 12 months unless further retention is necessary for security investigations.
Upon expiry of applicable retention periods, your data will be securely deleted or anonymised.
Data Processors and Sharing
We use carefully selected third-party processors who assist in delivering our services and maintaining operational standards. These processors handle data strictly according to our instructions and the requirements of GDPR. Categories of processors include:
- Payment Service Providers: For secure payment processing and fraud prevention.
- IT and Hosting Providers: For website hosting, maintenance, and data storage.
- Delivery Partners: For coordinating and ensuring timely delivery of your flowers.
- Professional Advisors: Such as accountants and auditors, under confidentiality agreements, where required for compliance or business operations.
We never sell or rent your personal data. Data may also be disclosed when required by law or to protect our legal interests (e.g., to authorities or regulatory bodies).
How We Protect Your Data
We are committed to ensuring your information is secure. We apply appropriate technical and organisational measures, including encryption, firewalls, access controls, and staff training, to protect data against unauthorised access, loss, or misuse. Our service providers are selected based on their ability to comply with our security requirements.
Your Rights Under GDPR
You have a range of rights regarding your personal data, which you can exercise at any time. These include:
- Right of Access: To request confirmation of the data we hold and receive a copy.
- Right to Rectification: To correct inaccurate or incomplete data.
- Right to Erasure: To request deletion of your data where it is no longer required or you withdraw consent (subject to legal obligations).
- Right to Restrict Processing: To request a restriction on how your data is used in certain circumstances.
- Right to Data Portability: To request your data in a commonly used format for your own use or to transfer it to another provider.
- Right to Object: To object to processing, especially for direct marketing or when processing is based on our legitimate interests.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time, without affecting previous processing.
- Right to Lodge a Complaint: To raise concerns with a supervisory authority if you believe your data protection rights are being infringed.
We take requests regarding your data seriously and will respond in accordance with GDPR timeframes. To exercise your rights, please contact us using the details provided on our website or at our premises.
Policy Updates
We may update this Privacy Policy to reflect changes in our practices, technology, or legal obligations. When significant changes are made, we will notify customers via our usual communication channels. The date of the most recent update will always appear at the start of this policy. Customers are encouraged to review this policy regularly to stay informed about how their data is managed.
Who This Policy Applies To
This Privacy Policy applies to all Flower Delivery Barnet customers placing orders from Barnet and surrounding districts. By accessing our services and placing orders, you acknowledge and accept the practices described in this policy.