Flower Delivery Weybridge GDPR Privacy Policy
Introduction
This Privacy Policy explains how Flower Delivery Weybridge collects, uses, stores, and protects the personal data of customers who place orders from Weybridge and neighbouring districts. We are committed to safeguarding your privacy and complying with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018.
This policy applies to all individuals placing Flower Delivery Weybridge orders either for themselves or on behalf of another recipient within Weybridge and the surrounding areas.
What Personal Data We Collect
In order to process your order and provide our floral delivery services, we may collect and process the following categories of personal data:
- Identifying Details: Name, delivery address, billing address, and postcode.
- Contact Information: Telephone number and, where provided, alternate contact numbers.
- Email Address: For sending you order confirmations and status updates.
- Payment Information: Details such as transaction date and time. Please note that payment card details are never stored by Flower Delivery Weybridge and are processed securely by our appointed payment processor.
- Order Information: Items ordered, delivery instructions, order message cards, or notes attached to your order.
- Recipient Details: Where you order flowers for another person, we collect their name, delivery address, and contact number for delivery purposes.
- Communication Records: Correspondence or feedback provided via forms, letters or during telephone conversations with our team.
Lawful Basis for Data Processing
Our lawful bases for collecting and processing your personal data under the GDPR are as follows:
- Contract: The majority of the data we collect is necessary to fulfil the contract entered into when you place an order. Without this information, we can neither process nor deliver your flower order.
- Legitimate Interest: We may process your data to ensure the effective operation of our business, for quality assurance, or to prevent fraudulent transactions. This will always be balanced with your rights and interests.
- Legal Obligations: In some cases, we are legally required to retain certain transaction details for accounting and record-keeping purposes.
- Consent: If, in the future, we request to use your data for marketing communications, your explicit consent will always be sought in advance, and you may withdraw it at any time.
How We Use Your Data
Your personal data is processed mainly for the purposes of:
- Processing your flower order and handling payment transactions securely.
- Delivering goods accurately to the recipient and updating you on the order status.
- Contacting you about changes to your order or delivery details, if necessary.
- Managing customer enquiries, feedback, and resolving issues as part of our customer service.
- Fulfilling our legal and financial record-keeping obligations.
Data Retention
We retain personal data for as long as is necessary to fulfil the purposes for which it was collected, including for the purpose of satisfying contractual, legal, regulatory, and accounting requirements. Order and transaction records are typically retained for up to six years in line with HMRC requirements.
We regularly review the data we hold and will securely delete or anonymise information that is no longer required. Where data has been anonymised, it may be retained for business analytics and statistical purposes only.
Sharing and Data Processors
Flower Delivery Weybridge does not sell or trade your personal data with third parties. We share your data only where necessary, in connection with providing our services:
- Payment Processors: Secure PCI-DSS compliant payment service providers process all online payments. We do not store your card details.
- Couriers and Delivery Partners: Your name, address, and contact number may be shared only with trusted couriers for the purpose of completing the delivery.
- IT and System Providers: Our website and customer order platform may be supported by IT support partners who process your data on our behalf under strict contractual obligations.
All third-party data processors are contractually required to respect the security and confidentiality of your data and to process it only in accordance with our instructions and in compliance with data protection laws.
Security of Your Data
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, accidental loss, or destruction. These may include:
- Encrypted connections (SSL) for online order forms and checkouts.
- Restricted access to your data, limited only to authorised employees and essential service providers.
- Regular review and testing of our data protection and cybersecurity processes.
Your Rights as a Data Subject
Under the GDPR, customers of Flower Delivery Weybridge have several key rights concerning their personal data:
- Right of Access: You have the right to request a copy of the personal data we hold about you.
- Right to Rectification: You can request that incorrect or incomplete information about you is corrected.
- Right to Erasure: Also known as 'the right to be forgotten', you may request that your data be deleted, subject to our retention obligations.
- Right to Restrict Processing: You can request that we limit the processing of your personal data in certain circumstances.
- Right to Data Portability: You may request a copy of your data in a commonly used format to transfer to another provider.
- Right to Object: You have the right to object to how we use your data in certain situations, such as for direct marketing.
To exercise any of these rights, or if you have questions relating to your data, you can contact us in writing. We will respond to your request within one month, as provided by the GDPR. If you are dissatisfied with our response, you may raise the matter with the Information Commissioner's Office (ICO).
Changes to This Privacy Policy
Flower Delivery Weybridge may update this policy from time to time to reflect changes in our services or legal requirements. We encourage you to review this page regularly to stay informed about how we process and protect your information.
Contact and Further Information
If you require further details regarding this policy or your personal data, or if you wish to exercise any of your rights under GDPR, please contact us through the official channels provided on our website or in your order confirmation. We are happy to address any concerns you may have regarding your privacy and the handling of your personal data.