Your Data Protection Rights with Flowers Putney
Introduction
This Privacy Policy sets out how Flowers Putney (“we”, “us”, or “our”) collects, stores, uses, and shares your personal information in accordance with the UK General Data Protection Regulation (GDPR) and relevant data protection laws. This policy applies to all customers placing orders with Flowers Putney from Putney and the surrounding districts. We are committed to safeguarding your privacy and ensuring transparency in our processing of your data.
What Personal Data We Collect
To fulfil your orders and offer our services, Flowers Putney collects and processes the following categories of personal data:
- Identification Data: Name, contact number, and delivery address for recipient and orderer.
- Communication Data: Messages included in your order, correspondence with our staff or customer service.
- Order and Transaction Data: Details of your orders, delivery preferences, and payment status.
- Payment Data: While payments are processed by third-party providers, we may retain transaction references, confirmation status, and method used. We do not store your card details on our systems.
- Website Usage Data: When you visit our website, we may use cookies and similar technologies to collect details about how you use the site, browser information, and anonymised analytics data. We do not use this information to identify you personally unless you provide details during your order or account creation.
Lawful Basis for Processing
Under GDPR, we process your personal data on the following lawful bases:
- Contract: Processing necessary to fulfil your order, including delivery, communication, and handling payments.
- Legitimate Interests: Processing for purposes such as improving our services, communicating important notices, and preventing fraud, provided that these interests are not overridden by your rights and interests.
- Legal Obligations: Where we are required to retain certain information to meet legal or regulatory requirements (for example, accounting records).
- Consent: For optional uses such as marketing communication (which you may opt into or out of at any time).
How We Use Your Personal Data
Your personal data is used to:
- Process and deliver your flower orders to Putney and surrounding areas.
- Contact you about your order or to respond to your enquiries.
- Process payments and issue order confirmations or receipts.
- Improve our services and customer experience, including the trouble-shooting of issues and analysing feedback.
- Comply with legal and regulatory obligations.
- Send you marketing information about products where you have consented.
Who Processes Your Data
Your data is processed by Flowers Putney’s team and authorised employees who are trained and aware of data protection requirements. Where necessary, we may share your data with third-party service providers (known as “processors” under GDPR) strictly for the purposes described above. These include:
- Payment processors: Secure third-party services that manage online card and digital payments. Flowers Putney does not store your card information on-site or in records.
- Delivery partners: Couriers and logistics companies engaged to deliver your flowers across Putney and surrounding locations.
- IT and data storage providers: Companies providing website hosting, cloud storage, and data management systems necessary for our operations.
All processors are required to act only on our instructions and to implement appropriate security measures to protect your personal data. Your data is not sold or disclosed for unrelated marketing purposes.
Data Retention
We only keep your personal information for as long as necessary for the purposes for which it was collected, including for fulfilling your order, legal and accounting requirements, and resolving disputes. Generally:
- Customer and order data are retained for up to six years to comply with tax and accounting regulations, unless a longer retention period is required by law.
- Marketing preferences are stored until you withdraw consent or request erasure.
- Correspondence and enquiry records are retained for a maximum of two years from the date of last contact.
Once the retention period has expired, your personal data will be securely deleted or anonymised.
Your Rights Under GDPR
As a resident in the UK or EU, you have significant rights regarding your personal information. Specifically, you have the right to:
- Access: Request a copy of personal data we hold about you.
- Rectification: Ask us to correct or update any incomplete or inaccurate data.
- Erasure (the “right to be forgotten”): Request deletion of personal data under circumstances set out in the GDPR.
- Restriction: Ask us to suspend processing of your data in certain situations.
- Data Portability: Request that your data be provided in a usable, electronic format, or transferred to another organisation.
- Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Withdraw Consent: Where processing is based on your consent, you are free to withdraw that consent at any time.
If you wish to exercise any of these rights, please contact us using the details provided on our website or written correspondence sent to our business address. We aim to respond to requests within one calendar month, as permitted by law.
Data Security
Flowers Putney takes appropriate technical and organisational measures to protect your personal information. This includes the use of secure servers, data encryption, access controls, and staff training in data confidentiality. We regularly review our practices to maintain a high standard of protection and to prevent data loss, misuse, or unauthorised access.
Children’s Privacy
Flowers Putney does not knowingly collect or process personal information from children under the age of 16 without the explicit consent of a parent or guardian. If we become aware that such information has been inadvertently collected, we will take steps to delete it promptly.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our procedures or applicable laws. The latest version will always be available on our website, including the date of the most recent amendment. We encourage you to review this policy periodically.
How to Contact Us
If you have any questions or concerns about this Privacy Policy, our data practices, or wish to exercise your data protection rights, please refer to the contact section on our official website or write to us at our registered business address. If you are not satisfied with our response, you may lodge a complaint with the Information Commissioner’s Office (ICO) or your local data protection authority.