Flower Delivery Oxted Privacy Commitment
Introduction and Scope
This Privacy Policy describes how Flower Delivery Oxted ('we', 'us', 'our') collects, uses, stores, and protects your personal data. It applies to all customers placing Flower Delivery Oxted orders from Oxted and the surrounding districts. We are committed to respecting your privacy and abiding by the General Data Protection Regulation (GDPR) and relevant UK data protection laws.
What Personal Data We Collect
When you place an order or interact with Flower Delivery Oxted, we collect and process personal data necessary to fulfill your order and provide our services. The categories of personal data that we may collect include:
- Identity Data: Your first and last name.
- Contact Data: Billing and delivery addresses, email address, and telephone number.
- Order Data: Details of products ordered, recipient information, delivery instructions, and messages attached to orders.
- Payment Data: Details needed to process your payment, such as payment card information (handled securely by third-party processors and never stored by us) and transaction references.
- Technical Data: IP address, browser type and version, time zone setting, browser plug-in types and versions, operating system and platform (collected automatically when you browse our website).
- Communication Data: Records of correspondence when you contact us by any method.
Lawful Basis for Processing
Under the GDPR, every processing activity must have a lawful basis. Flower Delivery Oxted relies on the following lawful grounds for collecting and processing your personal data:
- Performance of Contract: To process and deliver your order and provide related customer service.
- Legal Obligations: To comply with our legal and regulatory responsibilities such as tax and accounting requirements.
- Legitimate Interests: To pursue our legitimate business interests, for instance, to improve our services, enhance security, and prevent fraud, provided your interests and fundamental rights do not override those interests.
- Consent: Where you have given us explicit permission, such as for receiving marketing communications. You may withdraw consent at any time.
How We Use Your Personal Data
We use your data for the following purposes:
- To process and deliver your flower orders, including communicating with you and the recipient as necessary for delivery.
- To manage your payments and prevent fraudulent transactions.
- To provide customer support and respond to your inquiries.
- To comply with legal obligations such as keeping records for tax and accounting purposes.
- To improve our services and maintain the security of our website.
- To send you service-related communications, and, with your consent, updates or special offers.
Cookies and Automated Data Collection
Our website may use cookies or similar technologies to enhance your browsing experience, gather statistical information about website usage, and help us improve our services. You can manage your cookie preferences through your browser settings.
Data Retention Periods
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements. In most cases:
- Order, identity, and contact data are generally retained for up to seven years to meet tax and contractual obligations.
- Where data is held based on consent (such as for marketing), it is retained until you withdraw your consent.
After these periods, data will be securely deleted or anonymized.
Our Data Processors and Transfers
Sometimes we use trusted third-party suppliers (‘processors’) to process personal data on our behalf. These may include:
- Payment service providers (for secure payment processing).
- IT and cloud hosting service providers (to host our website and email systems).
- Delivery or courier partners (for logistical fulfillment of your order).
All processors are thoroughly vetted to ensure they comply with GDPR and only process data as instructed by us. We do not sell or trade your personal information to any third parties. If personal data is transferred outside the UK or the European Economic Area (EEA), we ensure appropriate safeguards are in place to protect your data in compliance with data protection law.
User Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can request correction of any inaccurate or incomplete data.
- Right to Erasure: You may ask to have your personal data deleted (subject to legal obligations).
- Right to Restriction: You have the right to restrict how we process your data in certain circumstances.
- Right to Data Portability: You can receive your personal data in a structured, commonly used format and transmit it to another controller.
- Right to Object: You may object to our processing where we rely on legitimate interests or consent (such as for marketing).
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw this at any time.
To exercise any of these rights, please contact us using the details provided on our website. We may need to verify your identity before fulfilling your request.
Security of Your Data
We implement appropriate technical and organizational measures to protect your personal data from loss, misuse, unauthorized access, disclosure, alteration, or destruction. This includes secure storage, restricted access, encryption of sensitive data, and regular review of our security practices.
Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or the law. The most current version will always be available on our website, and any significant changes will be communicated to you where appropriate.
Contact and Complaints
If you have any questions or concerns about this Privacy Policy or your personal data, please get in touch using the contact details provided on our website. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe your data protection rights have been violated.