Florist Dagenham Privacy Policy
Introduction
This Privacy Policy explains how Florist Dagenham ('we', 'us', or 'our') collects, stores, uses, and safeguards your personal data in compliance with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. The policy applies to all customers placing orders with Florist Dagenham, whether for delivery or collection, from Dagenham and the surrounding districts.
What Data We Collect
When you place an order or interact with our services, we may collect the following types of personal data:
- Contact Information: Name, delivery address, billing address, telephone number, and contact preferences.
- Order Details: Order history, product preferences, special requests, delivery instructions.
- Payment Information: Payment method, transaction records (note: card data is processed securely by payment processors and not stored by us).
- Website Usage Data: IP address, browser type, device information, and interaction logs (through cookies or analytics tools).
- Correspondence: Records of communications with our customer service, including queries and complaints.
Lawful Basis for Processing
We process your personal data for the following lawful bases under GDPR:
- Contractual necessity: To fulfill and manage your order, arrange delivery, process payments, and provide customer service.
- Legal obligation: To meet requirements such as fraud prevention, tax, and accounting regulations.
- Legitimate interests: To analyse and improve our services, manage business operations, and prevent misuse or fraudulent activity.
- Consent: Where you provide voluntary consent, for example, for receiving marketing updates. You may withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- Processing and fulfilling your orders, including delivering floral products to you or your recipients.
- Responding to your enquiries, complaints, or feedback.
- Processing payments and refunds securely.
- Customising your experience and personalising recommendations.
- Complying with legal and regulatory requirements.
- Where permitted, sending you marketing communications about our services (subject to your preferences).
- Monitoring and improving our services and website performance.
Retention of Your Data
We keep your personal data only as long as necessary for the purposes it was collected, including to fulfill orders, meet legal and accounting obligations, resolve disputes, and enforce our agreements. Typically:
- Order and transactional data is kept for up to seven years to comply with tax and accounting laws.
- Customer enquiries and correspondence are retained for up to two years after resolution.
- Marketing preferences are maintained until you update them or withdraw consent.
- Website analytics and cookie data are retained in accordance with our Cookie Policy, generally not beyond two years.
Data Processors and Data Sharing
To provide our services, we may share your information with trusted third parties (data processors), who process data on our behalf under written contracts and strict confidentiality. These may include:
- Delivery partners: To ensure flowers are delivered to the correct recipient.
- Payment service providers: For secure handling of financial transactions.
- IT service providers: For website hosting, order management, analytics, and support.
- Professional advisers: For legal, accounting, or insurance purposes where required.
We do not sell or rent your personal data to third parties. We require all data processors to comply with the UK GDPR and to use your data only for the specified purposes.
International Data Transfers
Personal data is primarily stored and processed within the UK. Where we may need to transfer data outside the UK (for example, if a processor is based outside the UK), we ensure appropriate safeguards are in place as required by law, such as standard contractual clauses or other legal mechanisms.
Keeping Your Data Secure
We employ appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. This includes encryption, password protection, secure data storage, regular reviews of our security practices, and staff training. Despite our efforts, no system is completely secure, and we cannot guarantee absolute security; however, we act promptly in the event of any data breach.
Your Rights Under GDPR
As an individual within the UK, you have the following rights regarding your personal data:
- Right to access: You may request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete data.
- Right to erasure: You may request deletion of your data in certain situations.
- Right to restrict processing: You can ask us to limit how we process your data.
- Right to data portability: You can request to receive your data in a portable format.
- Right to object: You can object to the processing of your data for direct marketing or on grounds related to your particular situation.
- Right to withdraw consent: Where processing is based on your consent, you have the right to withdraw it at any time.
To exercise your rights, please contact us through the contact methods provided on our website. Requests are generally responded to within one month.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our data processing practices. The most recent version will always be available on our website with the effective date noted.
Contact and Complaints
If you have any questions or concerns about this Privacy Policy or how we handle your data, please get in touch using the details provided on our website. If you are not satisfied with our response, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
This Privacy Policy is effective as of June 2024 and applies to all customers placing Florist Dagenham orders from Dagenham and neighbouring areas.