Flower Delivery Isle of Dogs Privacy Policy
Introduction
This Privacy Policy sets out how Flower Delivery Isle of Dogs ('we', 'us', or 'our') collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable UK data protection legislation. This policy applies to all customers placing Flower Delivery Isle of Dogs orders from Isle of Dogs and the surrounding districts.
What Data We Collect
When you place an order or use our services, we collect specific personal data required to process and deliver your order efficiently. The types of personal data we may collect include:
- Contact Details: Full name, delivery address, billing address, phone number.
- Order Details: Details of products ordered, special requests or messages, recipient information.
- Payment Data: Payment method (card details are processed securely by third-party providers and are not stored by us).
- Communication Data: Any correspondence with us, feedback, or complaints.
- Website Usage Data: Information on how you use our website, such as IP address, browser type, and pages visited, collected via cookies and analytics tools.
Lawful Basis for Processing Your Data
We process your personal data under the following lawful bases as outlined by GDPR:
- Contractual Necessity: To perform our contract with you when you place an order with us, including confirming, processing, and delivering your flowers.
- Legal Obligation: To comply with any legal requirements (such as tax or accounting obligations).
- Legitimate Interests: To carry out market analysis, improve our products and services, prevent fraud, and ensure the security of our systems.
- Consent: When you explicitly opt-in to receive marketing communications or subscribe to newsletters. You can withdraw your consent at any time.
How We Use Your Personal Data
Your personal data is used only for the specific purposes for which it was collected. These include:
- Processing and fulfilling your orders, including delivery arrangements.
- Communicating with you about your orders or responding to your queries.
- Improving our website, products, and services through customer feedback and data analysis.
- Complying with legal and regulatory requirements.
- Sending you updates, promotions, or newsletters, if you have consented.
Data Retention
We retain your personal data only as long as is necessary for the purposes outlined in this policy, or as required by law. Specifically:
- Order-related data is stored for a period consistent with legal requirements for accounting and tax purposes, usually up to 6 years after your last order.
- Customer communications are kept for up to 2 years for quality assurance and complaint resolution.
- Consent-based marketing data is held until you withdraw your consent or opt out.
At the end of the relevant retention periods, your data will be securely disposed of or anonymised so it can no longer be associated with you.
Processors and Data Sharing
We may share your personal data with trusted third-party service providers (processors) who perform functions on our behalf, such as:
- Payment processors and gateways to securely handle transactions.
- IT and website hosting providers to operate our website and maintain system security.
- Analytics and marketing services to understand website performance and customer needs (where consent has been given).
- Delivery partners to ensure your flowers arrive safely and on time.
All external processors are carefully selected and are required to handle your data in line with GDPR and applicable privacy laws. We do not sell or rent your personal data to any third parties.
Your Data Protection Rights
Under GDPR, you have several important rights regarding your personal information:
- Right to Access: You can request access to the personal data we hold about you.
- Right to Rectification: You have the right to correct any inaccuracies in your data.
- Right to Erasure: Also known as the 'right to be forgotten', you can ask us to delete your personal data in certain circumstances.
- Right to Restriction: You can request us to limit the processing of your data in specific cases.
- Right to Data Portability: You may request a copy of your personal data in a structured, commonly used digital format.
- Right to Object: You may object to the processing of your personal data where the basis is our legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time without detriment.
To exercise your rights, please contact us through our website or by writing to the address published on our contact page. We aim to respond promptly and in compliance with GDPR timelines.
Security of Your Data
We are committed to ensuring the security and confidentiality of your personal data. We implement appropriate technical and organisational measures to protect against accidental or unlawful loss, alteration, unauthorised disclosure, or access. Our staff and external partners are bound by strict data protection obligations.
International Data Transfers
Your data is primarily stored and processed within the UK and the European Economic Area (EEA). If we transfer your data outside of the EEA, we ensure that suitable safeguards are in place, such as standard contractual clauses, to protect your information.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in law or our services. The most recent version will always be available on our website. We encourage you to review this policy periodically to stay informed about how your data is protected.
Contact Us
If you have any questions about this Privacy Policy or our data practices, please use the contact information provided on our website to get in touch. We value your privacy and are dedicated to handling your personal data with care and transparency.