Privacy Policy for Bexleyheath Flowers Customers
Introduction
At Bexleyheath Flowers, we are committed to safeguarding your personal information. This Privacy Policy outlines how we collect, use, store, and protect your data in compliance with the General Data Protection Regulation (GDPR) and other applicable data protection laws. The policy applies to all customers placing Bexleyheath Flowers orders from Bexleyheath and surrounding districts.
What Personal Data We Collect
When you order from Bexleyheath Flowers, we collect information necessary to process and fulfill your order, provide customer support, and comply with legal obligations. Depending on your interactions with us, the types of personal data we may collect include:
- Contact Information: Name, delivery address, and billing address.
- Order Details: Order preferences, instructions, and floral card messages.
- Transaction Information: Payment method (note: we do not collect or store complete payment card details), order amount, and transaction history.
- Communication Data: Correspondence with customer service (such as feedback or complaints).
- Technical and Usage Data: Where applicable, information about device type, IP address, and browsing patterns when ordering through our website.
Our Lawful Basis for Processing Your Data
Bexleyheath Flowers collects and uses your data based on several lawful grounds as defined under GDPR:
- Performance of a Contract: We require your data to process, fulfill, and deliver your orders, and to contact you regarding your purchase.
- Legal Obligations: We may retain and disclose information where required by law, such as for accounting, fiscal, or regulatory compliance purposes.
- Legitimate Interests: Where necessary for our legitimate interests (for example, to improve customer service or prevent fraud), provided these are not overridden by your rights and interests.
- Consent: In cases where we rely on your consent (for example, for marketing communications), you are free to withdraw your consent at any time.
How We Use Your Data
Your personal information may be used for the following purposes:
- Processing and delivering your orders.
- Communicating order status, delivery updates, or responding to your questions.
- Conducting customer service follow-up and handling inquiries or complaints.
- Meeting legal record-keeping requirements.
- Improving our services based on feedback and usage patterns.
- With your consent, sending you occasional updates or marketing information about Bexleyheath Flowers.
Who Processes or Receives Your Data
We only share your data where necessary and in line with this policy. The types of third parties who may process or access your data include:
- Delivery Partners: To facilitate the delivery of your orders, we share necessary details such as recipient name and address.
- Payment Providers: Secure payment gateway providers process your payments; as noted, we do not retain your full payment card information.
- IT and System Administrators: Where our website or ordering system support teams access data for the purposes of maintenance or troubleshooting.
- Legal and Regulatory Authorities: Where required by law for tax, accounting, or regulatory compliance.
We select processors and service providers that adhere to data protection standards. Your data will not be sold or used for purposes unrelated to your relationship with Bexleyheath Flowers.
Data Retention
We retain personal data only as long as necessary to fulfill the purposes described in this policy, unless a longer retention period is required or permitted by law. Typically, the retention periods are as follows:
- Order information and relevant communications -- retained for up to six years from the date of your order, in line with accounting and tax requirements.
- Customer service related correspondence -- retained for a maximum of three years after resolution.
- Marketing consent records -- retained until you withdraw consent or for as long as is necessary to demonstrate compliance with data regulations.
Once the relevant retention periods have expired, your personal data will be securely deleted or anonymised.
Your Data Protection Rights
Under GDPR, you have a number of important rights in relation to your personal data:
- Right of Access: You may request access to the personal data we hold about you.
- Right to Rectification: You can ask us to correct or update inaccurate or incomplete information.
- Right to Erasure: You may request that we delete your personal data where there is no longer a legal basis for us to retain it.
- Right to Restriction: You may ask us to restrict processing of your data in certain circumstances.
- Right to Data Portability: You can request that we provide your data to you or to another service provider in a commonly used electronic format.
- Right to Object: You may object to certain processing activities, such as direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.
To exercise any of your rights, please contact us with sufficient information to identify yourself and specify your request. We will respond in line with GDPR timeframes.
How Your Data is Secured
We take the security of your information seriously. Procedural, technical, and physical measures are implemented to protect your data from loss, misuse, or unauthorized access. Examples include limiting staff access, using secure online ordering systems, and reviewing our data protection practices on a regular basis.
Changes to This Privacy Policy
This policy may be updated from time to time to reflect legal requirements or changes in how we process personal data. Where the changes are significant, we will notify customers via our usual communication channels or at the point of order. The latest version of this Privacy Policy will always be available from Bexleyheath Flowers.
Contact and Complaints
If you have any concerns about how your data is processed or wish to make a complaint, you can contact us using our published postal or contact form details. If you are dissatisfied with our response, you can also contact the relevant Data Protection Authority in the United Kingdom.