Flower Delivery Ascot: Data Protection and Privacy Policy
Introduction
This Privacy Policy explains how Flower Delivery Ascot ('we', 'us', 'our') collects, processes, and protects your personal data when you place an order for flower delivery within Ascot and the surrounding districts. We are committed to safeguarding your privacy and complying with the General Data Protection Regulation (EU) 2016/679 ('GDPR'). This policy explains your rights and our obligations in relation to your personal information.
Who This Policy Applies To
This policy applies to all customers who place orders with Flower Delivery Ascot, whether online, by phone, or in person, for deliveries within Ascot and the surrounding areas. By ordering from us, you acknowledge that you understand and accept the terms outlined in this policy.
What Personal Data We Collect
We only collect data essential to processing and fulfilling your orders and providing customer service. The types of personal data we collect include:
- Identity Data: Name, and if provided, title.
- Contact Data: Delivery address, billing address, phone number, and (if provided) email address.
- Order Details: Product selections, card messages, delivery instructions, and transaction information (purchase date, delivery date, gift notes).
- Payment Data: Payment method details (e.g., credit/debit card information). Please note that we do not store full payment card details after transaction completion. Payments are handled securely by our payment processors.
- Technical Data (website visitors): IP address, browser type, device details, and anonymized cookies for website operation and analytics.
- Communication Records: Correspondence and service requests via supported communication methods.
Lawful Basis for Data Processing
Under GDPR, we must have a lawful basis to process your personal data. The lawful bases on which we rely include:
- Contract: Most of our data processing is necessary to fulfil your order contract (e.g., processing payment and delivery).
- Legal Obligation: Retaining invoice and transaction records to fulfil our obligations with regulatory authorities.
- Legitimate Interests: For our internal record-keeping, customer service, service improvement, and fraud prevention, where these interests are not overridden by your privacy rights.
- Consent: Where required (such as for marketing communications), we will seek your explicit consent; you have the right to withdraw this at any time.
How We Use Your Data
We use your data for the following purposes:
- To process and deliver your flower order as requested.
- To communicate with you regarding your order status, questions, and support requests.
- To handle payments securely and prevent fraudulent transactions.
- To comply with legal and regulatory requirements.
- To improve our services, website, and customer experience.
- If you have opted-in, to send you relevant marketing information (you may opt out at any time).
Data Retention
We only retain your personal data for as long as necessary to fulfil the purposes outlined above, meet legal requirements, and resolve any disputes. Specifically:
- Order and transaction data: Kept for up to 6 years for accounting and tax reasons.
- Contact and communication records: Typically retained for up to 2 years after your last inquiry or order.
- Technical website data: Cookies and analytics are anonymized and retained for up to 26 months, in line with industry standards.
- If you have consented to marketing: Retained until you withdraw consent.
After these periods, your data is securely deleted or anonymized.
Data Processors and Third Parties
In some cases, we need to share your data with third-party service providers ('processors') who assist with processing orders, payments, deliveries, IT, and communications. These include:
- Payment processors to handle transactions securely.
- Delivery and courier services for fulfilment of your flower orders.
- IT and website hosting providers for secure data storage.
- Customer service and communication platforms as needed.
All our partners and processors are chosen for their commitment to data protection and GDPR compliance. We do not sell or rent your personal information to third parties for marketing or other purposes.
International Data Transfers
In general, your data is stored and processed within the United Kingdom or the European Economic Area (EEA). If we need to transfer your data outside the EEA (for example, for technology provider support), we will ensure that adequate safeguards and legal protections are in place to protect your rights.
Your Rights Under GDPR
Under the GDPR, you have several important rights regarding your personal data:
- Right to Access: You can request confirmation and a copy of the personal data we hold about you.
- Right to Rectification: You can request to correct any inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your data where there is no lawful basis for us to continue processing it.
- Right to Restrict Processing: You can ask us to suspend processing of your data in certain circumstances.
- Right to Data Portability: You may request to receive your data in a commonly used format and/or have it transferred to another controller.
- Right to Object: You can object to our processing of your personal data where our lawful basis is legitimate interests or consent (including for direct marketing).
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time, without affecting the lawfulness of processing before your withdrawal.
To exercise any of these rights, please contact us using your preferred supported communication method. We may ask you to verify your identity for your security and protection.
Data Security
We implement appropriate technical and organizational measures to protect your personal information from unauthorized access, misuse, loss, or alteration. This includes secure payment gateways, encrypted data storage, access controls, and regular review of our security protocols.
Policy Updates
We may update this Privacy Policy to reflect changes in legal requirements or the way we handle your data. Any material changes will be brought to your attention where required. We encourage you to review this policy periodically to stay informed of how we protect your information.
Contacting Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us via the methods specified on our website or your order confirmation. We take your privacy seriously and will address your concerns promptly and transparently.