Flowers Bermondsey Privacy Policy
Introduction
This Privacy Policy sets out how Flowers Bermondsey collects, uses, stores, shares, and protects your personal data when you place an order with us. It also explains your rights under the General Data Protection Regulation (GDPR). The policy applies to all individuals who order products or services from Flowers Bermondsey within Bermondsey and surrounding districts, regardless of the method of order (website, phone, or in-person).
What Data We Collect
When you place an order or interact with Flowers Bermondsey, we may collect the following categories of personal data:
- Identity Data: Name, title, and, if applicable, recipient name.
- Contact Data: Delivery and billing addresses, telephone numbers, and in some cases, alternative contact details for delivery updates.
- Transaction Data: Details of the products and services you have purchased from us, order dates, and amounts paid.
- Payment Data: Payment method details such as card type (note: card numbers and security codes are processed securely by payment providers and not stored by Flowers Bermondsey).
- Communications Data: Your communications or correspondence with us, including order instructions, special requests, or customer service interactions.
- Technical Data: When using our website, we may collect IP addresses, browser type, operating system, and browsing activity through essential cookies for site functionality and security.
We do not intentionally collect special category data (e.g. health, ethnicity, or religious beliefs). If you provide such data in your order (e.g. in a message for a floral tribute), we will treat it with the utmost confidentiality.
Lawful Basis for Processing
Under GDPR, our processing of your personal data is based on the following lawful bases:
- Contractual necessity: To process and deliver your order, fulfill our service obligations, and manage any related customer service needs.
- Legitimate interests: To improve our products and services, prevent fraud, ensure network and information security, and maintain accurate business records.
- Legal obligations: To comply with relevant UK and EU laws, including tax, accounting, and regulatory requirements.
- Consent: We will request your consent before sending you direct marketing communications, where required by law. You may withdraw this consent at any time.
How We Use Your Data
The main purposes for which we use your personal data include:
- Processing and delivering your flower orders, including arranging delivery and payment.
- Contacting you about your order, if necessary.
- Verifying your identity where required.
- Managing payments and refunds.
- Providing customer support and responding to your enquiries.
- Maintaining our business records for accounting and legal purposes.
- Evaluating and improving our customer service and product offerings.
Data Retention
Your personal data is retained only for as long as is necessary to fulfill the purposes for which it was collected and to comply with our legal and regulatory obligations. In general:
- Order and payment data is retained for seven years from the date of transaction in accordance with tax and accounting requirements.
- Contact and communication records are retained for up to two years, unless a longer retention is required due to an ongoing query or complaint.
- Website technical data is held for no longer than one year, after which it is deleted or anonymised.
Once data is no longer required, we undertake appropriate measures to securely delete or anonymise it.
Processors and Data Sharing
To operate our business efficiently, Flowers Bermondsey may share your data with trusted third-party processors, who process data on our behalf under strict contract and only as necessary to fulfill our services. These include:
- Payment processors for secure payment handling.
- IT hosting and maintenance providers to ensure website functionality.
- Delivery partners responsible for fulfilling customer orders.
- Professional advisers (such as accountants or legal advisers), only if necessary for compliance or dispute resolution.
We ensure that all processors comply with relevant data protection laws and process your data for specific purposes and under our instruction. Your data is not transferred outside the United Kingdom or European Economic Area unless adequate safeguards are in place.
Flowers Bermondsey does not sell your personal data to third parties for marketing or any other purposes.
Your Rights Under GDPR
As a Flowers Bermondsey customer, you have several rights under the GDPR concerning your personal data:
- Right to access: Request a copy of the personal data we hold about you.
- Right to rectification: Correct inaccurate or incomplete personal data.
- Right to erasure: Request deletion of your personal data where there is no justification for its ongoing processing.
- Right to restrict processing: Ask us to restrict processing of your personal data under certain circumstances.
- Right to data portability: Receive a copy of your data in a commonly used, machine-readable format or request that we transmit it to another controller where technically feasible.
- Right to object: Object to processing based on legitimate interests or direct marketing.
- Right to withdraw consent: Withdraw consent where we rely on it for processing (this does not affect prior lawful processing).
To exercise these rights, you can submit a written request identifying yourself and the specific data in question. We will respond to all rights requests in accordance with legal requirements and timelines.
Data Security
Flowers Bermondsey takes data security seriously and implements appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or loss. Such measures include secure servers, encrypted data transmission for sensitive information, controlled access, and staff training on data protection.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect legal requirements, changes in our practices, or improvements in our services. The current version will always be available to customers. Please review this policy regularly to stay informed about how we protect your data.
Contact and Complaints
If you have questions about this Privacy Policy or are not satisfied with our response to a data protection issue, you have the right to lodge a complaint with the Information Commissioner's Office (ICO) or your local supervisory authority.