Flower Delivery Harlow Privacy Policy
Privacy Policy Overview
This Privacy Policy explains how Flower Delivery Harlow collects, uses, protects, and processes your personal data when you place an order with us. This policy is relevant if you are a customer placing Flower Delivery Harlow orders from Harlow or its surrounding districts. Our privacy practices are designed to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. We value our customers' privacy and are committed to handling your data securely and transparently.
Personal Data We Collect
When you place an order with Flower Delivery Harlow, or interact with our service, we may collect the following types of personal data:
- Contact Information: such as your name, delivery address, billing address, and phone number.
- Order Details: including recipient’s name, delivery address, requested delivery time, flower preferences, and any special instructions.
- Payment Information: such as transaction details (order amount, payment method, and payment status). Note: actual card details are processed only by secure payment processors and are not stored by us.
- Correspondence: records of your communications with us (including complaints, customer service inquiries, and order confirmations).
- Technical Data: such as IP addresses, device type, web browser, operating system, and usage data collected through cookies when you visit our website.
Lawful Basis for Data Processing
We process your personal data under the following lawful bases, in line with GDPR:
- Contractual necessity: Processing your data is required to fulfil our contract with you, such as delivering your flower order, processing payment, and handling support queries.
- Legal obligations: We may be required to process certain data to comply with legal and tax regulations, such as retaining transactional information for tax purposes.
- Legitimate interests: We may use your data to improve our services, prevent fraud, or provide customer support, unless your rights override our interests.
- Consent: Where required (e.g. for certain marketing communications), we will ask for your consent. You can withdraw this at any time.
How We Use Your Information
We use your personal data for the following purposes:
- Processing and fulfilling your flower delivery orders.
- Communicating order status updates, confirmations, and delivery notifications.
- Managing your customer account (where applicable).
- Providing customer support, resolving issues, and responding to your requests.
- Maintaining security and preventing fraud.
- Complying with legal obligations (such as bookkeeping and tax reporting).
- Improving our products, services, and customer experience.
- Sending occasional marketing messages, if you have opted in to receive them.
Data Retention
We retain your personal data only for as long as necessary for the purposes it was collected, or as required by law. Typically, order details, delivery records, and related communications are kept for up to 6 years to comply with accounting and tax obligations. Customer accounts are retained as long as you remain a customer or have not requested deletion. Technical data used for analytics may be retained in aggregated, anonymised form.
Third-Party Processors
To operate our business effectively, we may share your data with trusted third-party partners (‘processors’) under strict contractual terms. These include:
- Payment Providers: To process payments securely for your orders.
- IT and Hosting Services: To enable the secure storage and transmission of your order data.
- Delivery Partners: To arrange and execute the delivery to your specified address.
- Analytics and Customer Support Providers: To help us improve our service, detect fraud, and respond to customer requests.
All processors are required to act only on our instructions and protect your data in compliance with the UK GDPR. We do not sell your personal data to any third parties.
International Data Transfers
We primarily store and process your data within the United Kingdom. If data is transferred outside the UK or the European Economic Area for technical reasons, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses or reliance on adequacy decisions.
Data Security
We implement appropriate organisational and technical measures to protect your personal data from unauthorised access, misuse, loss, or destruction. This includes secure servers, data encryption, firewall protection, and regular reviews of our data handling procedures.
Your Rights Under the GDPR
You have several rights regarding your personal data under the GDPR:
- Right to Access: You can request a copy of your personal data that we hold.
- Right to Rectification: You can have incomplete or inaccurate data corrected.
- Right to Erasure ('Right to be Forgotten'): You can request deletion of your personal data, provided there is no overriding legal obligation to retain it.
- Right to Restrict Processing: You can ask us to limit how we use your data in certain circumstances.
- Right to Data Portability: You may request a copy of your personal data in a machine-readable format for transfer to another provider.
- Right to Object: You may object to our processing where we rely on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw it at any time.
To exercise your rights, please write to us using our contact form or by post. We will aim to respond within one month, as required by law.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to ensure that it stays accurate with current practices or legal requirements. Please review this page regularly for the latest information. Where material changes are made, we will notify you accordingly.
Contact Information and Concerns
If you have any questions or concerns about this Privacy Policy or our data practices, please contact us using our online contact form or by writing to our registered address. If you are not satisfied with our response, you have the right to raise a complaint with the Information Commissioner's Office (ICO), the UK's independent authority for data protection.