Privacy Policy for Flower Delivery Bishops Stortford Orders
Scope of this Privacy Policy
This Privacy Policy applies to all customers placing orders with Flower Delivery Bishops Stortford, whether for delivery within Bishops Stortford or the surrounding districts. It explains how we collect, use, disclose, and protect your personal data in compliance with the General Data Protection Regulation (GDPR) and applicable UK data protection laws.
Data We Collect
We collect personal data necessary to process your order, deliver flowers, provide customer service, and comply with our legal obligations. The types of data we may collect include:
- Contact Information: Name, delivery address, billing address, phone number.
- Order Details: Items purchased, delivery instructions, recipient details (name, address, phone number).
- Payment Information: Cardholder name and payment confirmation details. (Note: Payment details are processed securely via third-party payment processors. We do not store full card information.)
- Communication Records: Correspondence or any queries you submit to us regarding your order.
- Technical Information: IP address, browser type, device information, and usage statistics collected via cookies or analytics tools when you visit our website.
Lawful Basis for Data Processing
We process your personal data only where permitted by the GDPR. The lawful bases for our data processing are as follows:
- Contractual Necessity: We process your data to fulfill our contract with you—namely, to process, confirm, and deliver your order.
- Legal Obligation: We retain transaction records for tax and regulatory compliance.
- Legitimate Interests: We use your data to improve our services, prevent fraud, and resolve disputes, provided these interests do not override your rights and freedoms.
- Consent: Where you provide explicit consent—such as for marketing communications—we process your data only for that specific purpose.
How We Use Your Personal Data
We use your personal data for the following purposes:
- To process and deliver flower orders accurately and efficiently.
- To communicate with you regarding orders, delivery updates, or customer service enquiries.
- To handle returns, refunds, or complaints as necessary.
- To comply with legal, regulatory, or accounting obligations.
- To monitor website performance, improve user experience, and safeguard against fraud.
- With your consent, to send updates, offers, or promotional information (you may opt-out at any time).
Data Sharing and Processors
We share your personal data only where necessary to fulfill your order or comply with the law. This may involve sharing data with carefully selected third-party service providers acting on our behalf (data processors), such as:
- Payment Processors: To securely process your payments.
- Delivery and Courier Services: To ensure your order is delivered to the correct address.
- IT and Web Hosting Providers: To manage our website and data storage securely.
- Professional Advisors: For legal, tax, or accounting purposes where required.
All data processors act strictly in accordance with our instructions under data processing agreements and are required to implement appropriate technical and organizational security measures to protect your personal data.
We do not sell, rent, or trade your personal information to any third parties for marketing purposes.
Data Retention
We retain personal data only for as long as necessary to fulfill the purpose for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. Generally:
- Order and transaction data are kept for a maximum of 7 years to comply with tax and accounting requirements.
- Customer service communications are retained for up to 3 years after resolution.
- Marketing data is retained until you withdraw your consent.
- Technical and website usage data may be retained up to 2 years for analytics and security purposes.
Once the applicable retention periods have expired, your data is securely deleted or anonymized.
International Data Transfers
In general, we process and store your personal data within the UK or European Economic Area (EEA). Where data processing by external providers outside these areas is unavoidable, we ensure appropriate safeguards and protections are in place, such as Standard Contractual Clauses approved by the UK Information Commissioner’s Office.
Your Rights Under GDPR
You have legal rights regarding your personal data as set out by the GDPR:
- Right to Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data under certain circumstances.
- Right to Restrict Processing: Request restriction of processing in specific situations.
- Right to Data Portability: Receive your data in a structured, commonly used, and machine-readable format or transfer it to another controller.
- Right to Object: Object to our processing based on legitimate interests, or withdraw your consent at any time.
- Right to Lodge a Complaint: Raise concerns with the Information Commissioner’s Office if you believe your data rights have been violated.
It is your responsibility to ensure your data is accurate and up-to-date. Please notify us of any changes.
Keeping Your Data Secure
We take the security of your data seriously and implement suitable technical and organisational measures to protect it, including encryption of sensitive data, access controls, secure servers, and staff training. While we take every precaution, no transmission over the Internet is completely secure. We therefore encourage you to contact us promptly if you believe your data security has been compromised.
Policy Updates
We may update this Privacy Policy periodically to reflect operational or legal changes. The most current version will always be available on our website. Significant changes will be notified to you where required by law.
Contact and Queries
For questions about this Privacy Policy, to exercise your rights, or to make a complaint, please contact us through the methods provided on our Contact page or within your order confirmation documents.