Flowers Roehampton Customer Privacy Policy
Introduction
This Privacy Policy explains how Flowers Roehampton (“we”, “us”, or “our”) collects, uses, stores, and protects your personal data when you place orders with us. Flowers Roehampton is committed to safeguarding your privacy and handling your information in a transparent manner in compliance with the General Data Protection Regulation (GDPR) and applicable UK data protection laws.
This policy applies to all individuals placing flower orders for delivery or collection in Roehampton and the surrounding districts. By placing an order, you acknowledge and agree to the terms set out in this policy.
What Data We Collect
When you interact with Flowers Roehampton, we may collect the following categories of data:
- Identity Data: such as your name, and if applicable, the recipient’s name.
- Contact Data: including your address, phone number, and any alternative contact details you provide (such as for recipients).
- Order Data: specific information regarding your flower order, delivery instructions, card messages, and purchase history with us.
- Payment Data: details required for processing your transaction, such as payment confirmation, but not your full credit/debit card numbers.
- Communication Data: records of correspondence, feedback, and queries submitted to us.
- Technical Data: such as IP address, browser type, and access times, collected automatically through our website for security and analytics.
Lawful Basis for Processing
Flowers Roehampton processes your personal data only where permitted by law and in accordance with GDPR. The lawful bases include:
- Contractual Necessity: We require certain personal information to process and deliver your order, provide customer support, and fulfil the contract with you.
- Legal Obligation: We may be required to retain and process certain data to comply with accounting, tax, and regulatory requirements.
- Legitimate Interests: We may use your information to improve our services, protect our business against fraud, and to keep records of sales for business purposes, provided that such interests are not overridden by your rights.
- Consent: In some cases, such as when you opt-in to receive marketing communications, we will collect and process your data based on your explicit consent. You may withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following primary purposes:
- To process, confirm, and complete your flower order.
- To arrange for flower delivery or collection as specified by you.
- To communicate with you regarding your order status, delivery, or any customer support issues.
- To keep records for internal business administration and compliance with legal requirements.
- If you have consented, to send you information about our products, promotions, or updates.
- To improve and maintain the security and functionality of our services.
How Long We Retain Your Data
Flowers Roehampton will retain your personal data for as long as is necessary to fulfil the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Typically:
- Order and delivery details are kept for up to 7 years to comply with accounting and tax legislation.
- Communication data is retained for as long as is necessary to resolve your queries or complaints.
- If you unsubscribe from marketing communications, we will retain your opt-out request to ensure you are not contacted further.
Once your data is no longer needed, it will be securely deleted or anonymised.
Processors and Data Sharing
Your personal data may be shared with trusted third-party service providers, known as data processors, who act solely on our instructions. These include:
- Payment processors that handle your payment securely.
- IT service providers supporting our website and order processing systems.
- Delivery couriers and logistics agents involved in fulfilling your order.
- Professional advisors and legal entities when required for auditing or compliance purposes.
All third-party processors are required to implement adequate safeguards to protect your information and are not permitted to use your data for any purpose other than to provide their contracted services to Flowers Roehampton.
We do not sell or otherwise share your personal information with third parties for their own direct marketing.
International Data Transfers
Your personal data is generally processed within the United Kingdom. Should we engage processors located outside the UK or EEA (European Economic Area), we will ensure your data receives an equivalent level of protection through appropriate safeguards.
Your Rights under GDPR
You have a number of rights concerning your personal data as provided by data protection law. These include:
- Right of Access: Obtain a copy of your personal data that we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Ask us to delete your personal data where there is no valid reason for us to continue processing it.
- Right to Restrict Processing: Request the restriction or suppression of your data in certain circumstances.
- Right to Data Portability: Receive the personal data you have provided to us, in a structured, commonly used format, and to transmit it to another controller.
- Right to Object: Object to our use of your data for direct marketing or where we rely on legitimate interests.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time.
To exercise your rights or to raise a complaint regarding your personal data, please contact us using our standard communication channels. We may request proof of identity to verify your request.
Security of Your Data
We take appropriate technical and organisational measures to safeguard your personal data against loss, theft, unauthorised access, disclosure, or destruction. This includes encryption, restricted access, and regular reviews of our data handling practices.
Updates to This Policy
This Privacy Policy may be updated from time to time to reflect changes to our practices, legal requirements, or for other operational reasons. Any changes will be effective immediately upon publication of the updated policy on our website. We encourage you to review this policy periodically.
Contacting Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us via our normal store enquiry channels or by visiting our premises.
This policy is effective as of June 2024.