Flowers Teddington GDPR Privacy Policy
Introduction
This Privacy Policy explains how Flowers Teddington ('we', 'us', 'our') collects, uses, stores, and protects your personal information when you place an order with us. This policy applies to all customers making purchases or queries through our services within Teddington and surrounding districts. We are committed to complying with the UK General Data Protection Regulation (GDPR) and ensuring your privacy is protected.
What Personal Data We Collect
When you interact with Flowers Teddington, we may collect, use, and process the following personal data:
- Identity Data: First and last name, delivery recipient’s name.
- Contact Data: Delivery address, billing address, and postcode; contact preferences; information provided for delivery instructions.
- Order Data: Purchase details, order history, payment confirmation information (note: we do not store payment card data; transactions are processed via secure third-party providers).
- Communication Data: Messages, queries, correspondence, and feedback submitted by you.
- Technical Data: IP address, device information, browser type, access times (collected via cookies and analytics tools when you use our website).
We do not intentionally collect any special category or sensitive personal data about you.
Lawful Basis for Processing Your Data
We process your personal data only when we have a lawful basis for doing so, as defined by GDPR. The legal bases include:
- Contractual Necessity: To process and deliver your flower order, communicate with you about your purchase, handle payments, and provide after-sales support.
- Legal Obligation: To comply with applicable laws and regulations, including tax and accounting requirements.
- Legitimate Interests: To enhance customer experience, improve our products and services, manage our relationship with you, and maintain business records. When relying on this basis, we balance our legitimate interests against your rights and freedoms.
- Consent: Where you have opted in to receive marketing communications from us, we rely on your consent, which you can withdraw at any time.
How We Use Your Personal Data
Your personal data is used for the following purposes:
- Processing orders, payments, and deliveries.
- Providing customer service and responding to your requests or queries.
- Managing your account and purchase history.
- Keeping you informed about your order status.
- Sending you news and special offers if you have opted in for marketing communications.
- Improving our website, services, and user experience through analytics and feedback.
- Complying with legal obligations and resolving disputes.
Data Retention
We retain your personal data only as long as necessary for the purposes it was collected, including:
- Order-related data: Retained for up to 6 years after your most recent purchase to comply with legal and tax obligations and to support after-sales service or queries.
- Marketing data: Retained only as long as you wish to receive marketing communications or until you opt out.
- Technical data: Retained in anonymised or pseudonymised format for analytical purposes to improve our business; personal identifiers are removed where possible.
Once we no longer need your personal information, we will delete or anonymise it securely.
Third-Party Processors
We may use trusted third-party processors to help us provide our services, such as payment processors, delivery services, IT hosting providers, and analytics services. These processors only process your data on our instructions and are bound by contractual obligations to safeguard your information in compliance with GDPR. We do not sell or rent your personal information to any other organisations, nor do we share your data for unrelated third-party marketing.
Security of Your Data
We take the security of your personal information seriously. We maintain appropriate technical and organisational measures to prevent loss, misuse, unauthorised access, disclosure, alteration, or destruction of your personal data. Access to your personal information is restricted to employees and processors who require it for operational purposes and are trained in data protection principles.
Your Data Protection Rights
Under GDPR, you have rights regarding your personal data, which include:
- Right to Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct incomplete or inaccurate information about you.
- Right to Erasure: You may request deletion of your personal data in certain circumstances.
- Right to Restrict Processing: You can request we restrict how we use your data under certain conditions.
- Right to Object: You may object to processing of your data for direct marketing or where processing is based on legitimate interests.
- Right to Data Portability: You can request a copy of your data in a format that allows you to transfer it elsewhere.
- Right to Withdraw Consent: When we process your data on the basis of consent, you can withdraw this at any time.
- Right to Lodge a Complaint: If you have any concerns, you may contact the UK Information Commissioner’s Office (ICO).
Applicability of This Policy
This Privacy Policy applies to all individuals ordering flowers from Flowers Teddington within Teddington and the surrounding districts. By placing an order, you acknowledge and agree to the practices outlined in this policy. We may review and update this policy from time to time to reflect changes in the law, our business operations, or data processing practices. The latest version will always be available upon request and on our website.
Contacting Us
If you have any questions about this Privacy Policy or how we handle your personal data, please contact Flowers Teddington through the usual channels listed on our website or at our shop premises during business hours.