Flowers Redhill Privacy Policy
Introduction
This Privacy Policy outlines how Flowers Redhill ("we", "us", "our") collects, uses, stores, and protects your personal data when you place an order with us. This policy is relevant to all customers placing orders from Redhill and surrounding districts. Our responsibility is to process your information in line with current UK data protection legislation, including the General Data Protection Regulation (GDPR).
What Data We Collect
To process and fulfil your order, we may collect the following types of personal data:
- Identity Data: Name, title, and your relationship to the recipient (if relevant).
- Contact Data: Delivery address, billing address, phone number (if provided), and postal code.
- Order Details: Product or bouquet ordered, messages included with the order, and delivery instructions.
- Payment Information: Payment method, transaction amount, and billing confirmation (we do not store your full card details; these are handled securely by our payment processor).
- Technical Data: Device type, IP address, browser type and necessary cookies required for ordering and security.
- Correspondence: Records of communications including order enquiries, feedback, or complaints, if any.
The Lawful Basis for Processing Your Data
We only process your personal information when we have a legal basis under GDPR. Our lawful bases include:
- Contractual Necessity: We require certain information to fulfil your order, provide customer service, process payment, and deliver flowers as requested. Without this data, we would be unable to provide our services.
- Legal Obligation: Some records such as transaction data and invoices must be retained to comply with accounting and tax regulations.
- Legitimate Interests: We may use your data to respond to your enquiries, improve our service, or prevent fraud, provided such use does not override your rights and interests.
- Consent: Where we rely on consent (e.g., for sending marketing communications), you will be asked to opt-in and may withdraw consent at any time.
How We Use Your Data
Your personal information is used only for the stated purposes below:
- Processing and fulfilling your flower order, including delivery to the recipient.
- Processing payments securely.
- Contacting you in relation to your order or resolving any issues.
- Maintaining necessary records for legal obligations (such as taxation and accounting).
- Ensuring website functionality and security.
- With your permission, sending information about our offers or services (if you have opted in).
Your Data and Third Parties
In certain circumstances, we share your data with trusted third parties ("processors") solely for the purposes of providing and improving our service. These include:
- Payment Processors: To securely handle your card payments.
- Delivery Partners: To deliver your orders to the requested addresses.
- IT Service Providers: For website hosting, email communication, and data storage.
- Professional Advisors: Such as accountants for legal and financial compliance.
All processors are contractually obliged to protect your data, use it only as instructed by us, and comply with GDPR standards. Personal data will never be sold or rented to third parties for marketing purposes.
Data Retention
We retain your data only as long as necessary for the purposes described in this policy, including to satisfy any legal, accounting, or reporting requirements. Generally:
- Order data and contact details are retained for up to six years to comply with tax and record-keeping obligations.
- Communications data is retained for up to two years after resolution of your enquiry or complaint.
- Marketing consent records are retained until you withdraw consent or unsubscribe.
After the retention period concludes, your data will be securely deleted or anonymised.
How We Protect Your Data
We implement a range of technical and organisational measures to ensure that your data is kept secure. These include:
- Encrypting data where it is transmitted or stored electronically.
- Limiting access to your data strictly to those employees or processors with a need to know.
- Performing regular reviews and audits of our data security standards.
- Ensuring that any third parties processing information on our behalf also meet or exceed GDPR security requirements.
Your Rights as a Data Subject
Under GDPR, you have the following rights regarding your personal data:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You may request correction of inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your personal data under certain circumstances ('the right to be forgotten').
- Right to Restrict Processing: You may ask us to limit how we use your data.
- Right to Data Portability: Request a transfer of your personal data to another service provider in a machine-readable format.
- Right to Object: You have the right to object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw this at any time.
To exercise any of these rights or for questions regarding your personal data, please contact us through our standard communication channels. We may need to confirm your identity to ensure your data is only disclosed to you.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in regulations, our practices, or improvements to our processes. Updated versions will be effective from the date they are published. We encourage you to review this policy periodically.
Applicability
This Privacy Policy applies to all customers placing orders with Flowers Redhill from Redhill and surrounding districts. By using our services and providing your data, you acknowledge and accept the terms set out in this policy.