Flowers Forest Gate Privacy Policy
Introduction
This Privacy Policy explains how Flowers Forest Gate collects, uses, stores, and shares your personal information when you place an order for flower arrangements or related services. Our commitment to privacy is consistent with the General Data Protection Regulation (GDPR) and addresses your rights and protections under this law. This policy applies to all customers placing orders with Flowers Forest Gate from Forest Gate and the surrounding districts.
What Data We Collect
To process your orders and deliver a seamless service, we may collect and process the following types of personal data:
- Identity Data: Name, title, and, if provided, the names of recipients for flowers or gifts.
- Contact Data: Delivery address, billing address, and any other address provided for order fulfillment, as well as any contact instructions given.
- Order Data: Details of the products or services you have ordered, purchase history, amounts paid, and payment confirmation references (we do not store payment card numbers).
- Communications Data: Requests, feedback, complaints, delivery instructions, correspondence, or other communications between you and Flowers Forest Gate.
- Technical Data: IP address, device type, browser information, and basic analytics derived from your use of our website (used to ensure site security and functionality).
We do not intentionally collect sensitive personal data (such as health information, ethnicity, or religious beliefs) unless you voluntarily provide it to us as part of a custom order or request. If you do, it will be handled with additional care and always in accordance with this policy.
Lawful Basis for Processing Personal Data
We rely on the following lawful bases under GDPR to process your personal data:
- Contractual Necessity: Many processing activities, such as collecting delivery information and processing payments, are performed to fulfill our contractual obligation to you as a customer.
- Legal Obligation: We may process and retain your personal data as required by law, including for accounting, tax, or recordkeeping purposes.
- Legitimate Interest: We may use your data to improve our products and services, enhance security, conduct analytics, or resolve disputes, provided those interests do not override your privacy rights.
- Consent: Where required, we will obtain your consent before processing your personal data – for example, if you would like to receive promotional offers or newsletters. You may withdraw your consent at any time.
How We Use Your Information
Your personal data is used only for specific and legitimate purposes, including:
- Fulfilling and delivering your orders.
- Confirming payment and sending order updates.
- Managing customer communication and responding to your inquiries.
- Improving our services, products, and website experience.
- Complying with legal, regulatory, and accounting duties.
- Preventing fraud and enhancing security.
How Long We Keep Your Data (Data Retention)
We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, including to satisfy legal, accounting, or reporting requirements. As a guide:
- Order and transaction data are retained for up to seven years to comply with financial and tax legislation.
- Customer account information is retained as long as you maintain an account with us. If you delete your account or request data erasure, we will delete your data unless retention is required by law.
- Correspondence and queries may be retained for up to three years after resolution to defend against potential claims or for staff training purposes.
After these timeframes, your data will be securely deleted or anonymised so that it is no longer associated with you.
Third-Party Processors
We work with carefully selected third-party service providers (processors) to help us operate our business and deliver your orders. These may include:
- Payment processing companies (to handle your transactions securely).
- Delivery and logistics partners (for order fulfillment and tracking).
- Website hosting, analytics, and IT support services.
- Accountancy and legal advisors (if required for compliance or dispute resolution).
All third-party processors are contractually obligated to comply with GDPR, maintain the security of your data, and use it only for the specific purposes stated. We do not sell or rent your data to marketing companies or unrelated third parties.
International Data Transfers
We strive to ensure that your personal data is processed within the United Kingdom and the European Economic Area (EEA). If it becomes necessary to transfer data outside of these areas, such as when engaging a processor in another country, we will ensure that appropriate safeguards are in place to protect your data in accordance with GDPR.
Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right to Access: Request a copy of your personal data that we hold.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data where there is no longer a justification for retaining it.
- Right to Restrict Processing: Ask us to suspend processing your data in certain scenarios.
- Right to Data Portability: Receive your personal data in a structured, commonly used, and machine-readable format to transfer to another provider.
- Right to Object: Object to processing based on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you have the right to withdraw it at any time.
To exercise any of these rights, you may contact us using the details provided on our website or by writing to our customer service team. We are committed to addressing your request in accordance with GDPR, and typically respond within one month.
Data Security
We take the security of your personal data seriously. We use physical and technological safeguards (including encryption, firewalls, password protection, and secure servers) to protect your data against unauthorised access, misuse, or disclosure.
Updates to This Policy
This Privacy Policy may be updated periodically to reflect changes in the law, technology, or our business operations. Any changes will be posted on this page with an updated revision date.
Contact and Complaints
If you have any questions, concerns, or wish to make a complaint about the way we handle your personal data, please get in touch through the contact details provided on our website. You are also entitled to lodge a complaint with the UK Information Commissioner's Office (ICO) if you are not satisfied with our response to your concerns.