Flower Delivery Surbiton GDPR Privacy Policy
Introduction
At Flower Delivery Surbiton, respecting and protecting your privacy is a top priority. This Privacy Policy outlines how we collect, use, store, and safeguard your personal data when you place an order with us for delivery in Surbiton and surrounding districts. We are committed to complying with the General Data Protection Regulation (GDPR) and ensuring transparency in how your data is handled.
Who This Policy Applies To
This policy applies to all customers who place orders with Flower Delivery Surbiton for delivery within Surbiton and neighbouring areas. By using our services, you agree to the collection and use of information as described in this policy.
What Data We Collect
We may collect and process the following categories of personal data to provide and improve our flower delivery services:
- Identity Information: Name, surname
- Contact Information: Delivery address, billing address, email address, phone number
- Order Details: Product selections, special delivery instructions, recipient name and address
- Payment Information: Transaction amount and payment method. Payment details are processed securely by third-party payment processors; we do not store your full card details.
- Communication Records: Correspondence between you and our customer service (messages, queries, feedback, complaints)
- Technical Data: IP address, browser type, and device identifiers (collected via cookies and similar technologies when you visit our website)
Lawful Basis for Processing Personal Data
Under the GDPR, we must have a lawful basis to process your personal data. The primary legal bases we rely upon are:
- Contractual Necessity: We process your data to fulfill your orders, manage delivery, and provide customer support as part of our contractual obligations.
- Legitimate Interests: We may process your data to improve our services, personalize your experience, and protect against fraud, provided these interests are not overridden by your rights.
- Legal Obligation: In some cases, we are required by law to process certain data, for example, for tax or accounting purposes.
- Consent: Where required, we will ask for your consent, for example, to send promotional communications. You may withdraw your consent at any time.
How We Use Your Data
We use your personal data to:
- Process and deliver orders to the specified addresses
- Communicate with you regarding your order status, delivery arrangements, and customer service queries
- Improve our website, products, and services based on customer feedback and usage analytics
- Meet our legal and regulatory obligations
- Prevent fraud and enhance the security of our services
- Send you direct marketing communications if you have consented to receive them
How Long We Keep Your Data (Retention)
We retain your personal data only as long as necessary to fulfill the purposes outlined in this Policy, including for satisfying legal, accounting, or reporting requirements. Typically:
- Order and contact details: Retained for up to 6 years to comply with accounting, tax, and contractual obligations
- Customer communications: Retained for up to 2 years from your last interaction with us
- Marketing data: Retained until you withdraw your consent or unsubscribe
- Technical and analytic data: Kept for a period as necessary to understand and improve website functionality, usually no longer than 26 months
When retention periods expire, or you request deletion, your information is securely deleted or anonymised.
Processors and Data Sharing
To provide our services efficiently, we may share your data with third-party service providers ("processors") who act strictly on our instructions and are bound by data protection and confidentiality obligations. Examples of processors include:
- Payment processors who handle your payments securely
- Delivery partners who assist in delivering your orders
- IT and cloud hosting providers who manage our website and store data
- Analytics service providers who help us understand how our website is used
We do not sell or rent your personal data to third parties. Where data processing occurs outside the UK or European Economic Area (EEA), we ensure adequate protection through legal safeguards such as Standard Contractual Clauses.
Your Rights Under the GDPR
As a customer, your rights regarding your personal data include:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of any incomplete or inaccurate data.
- Right to Erasure: Request deletion of your personal data where there is no good reason for us to continue processing it.
- Right to Restriction: Request to restrict how we process your personal data.
- Right to Data Portability: Request to transfer your data to another service provider.
- Right to Object: Object to processing your data where we are relying on legitimate interest, or to receiving direct marketing communications.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing before your withdrawal.
If you wish to exercise any of these rights, please contact us with proof of identity so we can respond appropriately. We strive to action all legitimate requests within one month.
Data Security
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, use, loss, or disclosure. This includes secure servers, encryption of sensitive information, and regular review of our policies and security practices.
Complaints and Further Information
If you have concerns about our use of your personal data or wish to make a complaint, please contact us in the first instance so we can address your concerns. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) or relevant supervisory authority in your country of residence.
Changes to Our Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal or regulatory requirements and our business practices. The latest version will always be available on our website. Please review this policy periodically to stay informed about how we are protecting your information.