Richmond upon Thames Flowers Privacy Policy
Introduction
This Privacy Policy describes how Richmond upon Thames Flowers ('we', 'us', or 'our') collects, uses, and protects your personal data when you place orders with us. The policy applies to all customers placing orders with Richmond upon Thames Flowers from Richmond upon Thames and the surrounding districts. We are committed to maintaining the privacy and security of your information in line with the General Data Protection Regulation (GDPR).
What Data We Collect
We collect and process a variety of personal data to provide our floral products and services. The types of data we may collect include:
- Contact Information: Such as your full name, delivery address, billing address, and telephone number.
- Order Details: Information about your flower order, including recipient details (name, address, and contact details if different from your own), messages to include with the flowers, and product selections.
- Payment Information: Details necessary to process your payment, excluding full card details which are handled securely by our payment processors.
- Communication Records: Any correspondence with us (such as queries, complaints, or feedback).
- Website Usage Data: Information automatically collected when you use our website, such as IP address, browser type, device identifiers, and browsing actions. This is collected via cookies and similar technologies for analytics and service improvement purposes.
Lawful Basis for Processing
We process your personal data on the following lawful bases, as defined by the GDPR:
- Contractual necessity: Most of the personal data we collect is necessary to fulfill the contract of sale and deliver your flower order.
- Legal obligation: We may need to process your data to comply with applicable laws (for example, tax or accounting regulations).
- Legitimate interests: We process some data to improve our services, prevent fraud, and ensure website security, provided these interests are not overridden by your privacy rights.
- Consent: In cases where required by law, such as for certain marketing activities, we will request your explicit consent before processing your personal data.
How We Use Your Data
We use your personal information to:
- Process, fulfill, and deliver your orders;
- Communicate with you regarding your orders or any queries you may have;
- Process payments and refunds through secure, authorized payment service providers;
- Comply with legal obligations and resolve disputes;
- Improve our products, services, and website functionality;
- Where you have opted in, to send information or promotions regarding our products, events, and offers.
Retention of Your Data
We will retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, including for the purposes of fulfilling orders, satisfying any legal, accounting, or reporting requirements, and addressing disputes or customer service matters.
In general:
- Order and transaction data are typically retained for up to seven years, in accordance with legal and tax obligations.
- Contact and communication data may be kept for up to three years after your last order or engagement with us, unless you ask us to remove your data where we do not have a legal obligation to retain it.
- Website analytics and cookie data may be retained in anonymized or aggregated form, not tied to an identifiable individual, for up to two years.
Disclosure and Processors
We do not sell your personal data. However, we may share your information with third-party service providers ('processors') who assist us in delivering our services. They are authorized only to use the information necessary to perform their specific functions, under strict obligations of confidentiality and data protection. Such processors may include:
- Payment processing providers for secure handling of transactions;
- Delivery and courier services for fulfilling your order;
- IT and website support providers ensuring proper operation and security of our systems;
- Professional advisors (such as accountants or legal counsel) strictly for compliance and legitimate business purposes.
All third-party processors are required to comply with GDPR data protection regulations. Where data is processed outside the UK or European Economic Area, we ensure adequate safeguards are in place.
Security of Your Personal Data
We employ appropriate technical and organizational measures to safeguard your personal data against unauthorized access, alteration, disclosure, or destruction. Access to your data is limited to personnel who need to know it for the purposes described in this policy. We regularly review our security protocols to ensure your information remains protected.
Your Rights Under GDPR
You have the following rights regarding your personal data:
- Right to access: You may request details about the data we hold about you.
- Right to rectification: You can ask us to correct inaccurate or incomplete information.
- Right to erasure: You may request deletion of your personal data, subject to legal or contractual restrictions.
- Right to object: You can object to certain processing activities based on legitimate interests or direct marketing.
- Right to restriction: You may ask us to restrict our processing of your data under certain circumstances.
- Right to data portability: You can request a copy of your data in a commonly used, machine-readable format.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time.
To exercise your rights, please contact us using the channels provided on our website.
Policy Updates
We may update this Privacy Policy from time to time to reflect changes in legal requirements, our data processing practices, or our service offerings. The most recent version will always be available on our website, and significant changes will be communicated as appropriate.
Contact and Complaints
If you have any questions about this Privacy Policy, or wish to exercise your rights, please contact Richmond upon Thames Flowers using the communication methods published on our website. If you are not satisfied with how we process your personal data, you have the right to lodge a complaint with the Information Commissioner's Office or your local supervisory authority.