Flower Delivery Pimlico Privacy Policy
Introduction
This Privacy Policy explains how Flower Delivery Pimlico ("we", "us", or "our") collects, uses, discloses, and protects your personal data in compliance with the General Data Protection Regulation (GDPR). This policy applies to customers placing Flower Delivery Pimlico orders within Pimlico and the surrounding districts. We are committed to ensuring that your privacy is protected and that you are informed about how your data is managed.
What Personal Data We Collect
When you place an order with Flower Delivery Pimlico, we collect certain information necessary to process and fulfill your order. The types of personal data we collect include:
- Identity Data: Name, delivery recipient name.
- Contact Data: Delivery address, correspondence address (if different), and where relevant, contact telephone numbers.
- Order Data: Details about your order, delivery instructions, and order history.
- Payment Data: Transaction details (note: payment processing is conducted by trusted third-party processors; we do not store your full payment card details).
- Communications Data: Records of emails or communications with our customer service regarding orders, enquiries, or feedback.
Lawful Basis for Processing
We process your data in accordance with the principles of the GDPR, and only where there is a lawful basis to do so. The lawful bases under which we may process your personal data include:
- Contract: Processing your order and delivering products involves the collection and use of data as part of fulfilling our contract with you.
- Legal Obligation: Some data is required to satisfy legal or regulatory obligations, such as financial record keeping.
- Legitimate Interests: We may collect and use information for legitimate business interests, such as improving services, responding to feedback, or direct marketing (where permitted by law).
- Consent: Where you have explicitly agreed, we may use your details for additional communications, such as news or offers. You may withdraw this consent at any time.
How We Use Your Data
Your data is used for the following purposes:
- Processing, confirming, and delivering flower orders to specified addresses.
- Contacting you about the status of your order or delivery.
- Responding to enquiries, feedback, or customer service matters.
- Handling payments securely via trusted third-party payment processors.
- Complying with accounting and other statutory obligations.
- With your consent, sending occasional promotions, offers, or updates (which you can opt out of at any time).
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. As a general guideline:
- Order and Contact Details: Retained for up to six years to cover potential legal claims and our obligations under accounting regulations.
- Payment Data: We do not retain full payment card details. Payment information is processed securely by payment processors and not stored by us beyond transaction confirmation.
- Marketing Data: Contact details used for marketing will be retained until you opt-out or withdraw your consent.
After these periods, your data will be securely deleted or anonymised.
Processors and Data Sharing
We use trusted third parties to help us deliver our services. These may include:
- Payment processors for secure handling of card payments.
- IT and hosting providers for website operation and order management.
- Delivery partners to assist in completing your orders, where required.
These third parties process your personal data only according to our instructions, and we ensure that appropriate technical and organisational safeguards are in place. We do not sell or share your personal information with unaffiliated third parties for their marketing purposes.
International Transfers
Your personal data is generally processed within the United Kingdom or European Economic Area (EEA). If, in exceptional cases, data is transferred outside the EEA, we ensure that suitable data protection safeguards are in place in compliance with GDPR requirements.
Data Security
We are committed to securing your data from unauthorised access, alteration, disclosure, or destruction. Measures include restricted access, regular security reviews, and staff training. While no method of transmission over the Internet is completely secure, we take appropriate precautions to protect personal data.
Your Rights
Under the GDPR, you have certain rights regarding your personal data held by us, including:
- Access: The right to request a copy of the personal data we hold about you.
- Rectification: The right to request correction of inaccurate or incomplete data.
- Erasure: The right to request deletion of your data where it is no longer necessary or where consent is withdrawn (subject to legal limitations).
- Restriction: The right to ask us to limit the processing of your data in certain circumstances.
- Data Portability: The right to receive your data in a commonly used, machine-readable format or to request its transfer to another provider.
- Objection: The right to object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw Consent: Where we process your data on the basis of consent, you have the right to withdraw it at any time.
If you wish to exercise any of these rights, please contact us using our usual communication channels. We may require verification of your identity before acting upon your request.
Changes to This Privacy Policy
We may update this Privacy Policy occasionally. Any changes will be effective as of the "last updated" date stated at the start of this notice. We encourage you to check back periodically to remain informed about how your data is handled.
Contacting Us
If you have questions about this Privacy Policy or our data practices, please contact us using the methods provided on our website or through your normal customer communication channels. We are happy to address any concerns and provide further details about how your data is used and protected.