Flowers Baldock Privacy Policy
Introduction
This Privacy Policy explains how Flowers Baldock ("we", "us", or "our") collects, uses, and safeguards your personal information. The policy is designed to ensure transparency and full compliance with the UK General Data Protection Regulation (GDPR). It applies to all customers placing orders with Flowers Baldock in Baldock and surrounding districts.
What Data We Collect
We collect personal information necessary to process and fulfill your flower orders, improve our services, and comply with legal obligations. The types of personal data we may collect include:
- Identity details: Name, title.
- Contact information: Delivery address, billing address, and postcode.
- Contact details: Phone number and any alternative contact numbers supplied, such as for the recipient.
- Email address (when provided, such as for receipts or confirmations).
- Order details: Specific product selections, messages for greeting cards, delivery instructions.
- Payment information: Transaction details, payment method (Note: We do not directly store or process complete card numbers; these are handled securely by our payment processors).
- Communications: Any queries, feedback, or correspondence you have with us.
We do not intentionally collect sensitive personal data such as health information, racial or ethnic origin, political opinions, or religious beliefs unless you explicitly provide such data (for example, in a message attached to an order) and consent to its processing.
Lawful Basis for Processing
Flowers Baldock processes personal data based on the following lawful bases under the GDPR:
- Contractual Necessity: Processing your data is essential for the fulfillment of your order and provision of our services (e.g., delivering flowers to the correct recipient).
- Legal Obligation: Certain data processing activities are required for us to comply with the law (such as keeping transaction records for tax purposes).
- Legitimate Interest: We may use your data for our legitimate business interests (such as service improvement, fraud prevention, or administrative purposes), provided your rights and interests do not override these.
- Consent: Where required, we will ask for your explicit consent, for example, before sending marketing communications.
How We Use Your Data
We use your personal data to:
- Process your orders, including handling payment and delivering flowers to your chosen recipient.
- Communicate with you regarding your order status, delivery or any issues that may arise.
- Respond to your enquiries and provide customer service.
- Comply with accounting and legal requirements.
- Improve and enhance the delivery and quality of our services.
- With your consent, send you promotional offers, seasonal information, or surveys (you may opt out at any time).
Data Processors and Data Sharing
To deliver our services, we may share your data with certain third parties acting as data processors. These may include:
- Payment processors: Securely process your payment details when you place an order.
- IT and web hosting providers: Support our website and electronic systems.
- Delivery partners or drivers: Fulfill the delivery of your floral order to the specified address.
All third-party processors are contractually bound to protect your personal information and may not use it for purposes other than fulfilling their obligations to Flowers Baldock. We do not sell or rent your personal data to third parties.
International Data Transfers
Your personal data is primarily stored and processed within the United Kingdom. If, in exceptional circumstances, your data must be transferred outside the UK or the European Economic Area (EEA), we will ensure appropriate safeguards are in place to protect your rights and interests as required by law.
Data Retention
We retain personal data only as long as necessary for the purposes for which it was collected and in accordance with applicable laws and regulations. In practice, this means:
- Order and transaction data are typically retained for six years to fulfill accounting and tax obligations.
- Contact and delivery information is kept only as long as needed to process current orders and any potential queries or complaints arising from your order.
- Marketing consent records are retained until you withdraw your consent or unsubscribe from communications.
At the end of the retention period, your personal data will be securely deleted or anonymised.
Your Rights Under GDPR
As a customer, you have the following rights over your personal data under the GDPR:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct any inaccurate or incomplete data.
- Right to erasure: You can request deletion of your data when it is no longer required for the purposes collected or if you withdraw consent (where applicable).
- Right to restriction: You can ask us to restrict processing under certain circumstances.
- Right to data portability: You are entitled to receive your personal data in a structured, commonly used format.
- Right to object: You can object to processing based on legitimate interests or to direct marketing at any time.
- Right to withdraw consent: Where processing is based on consent, you can withdraw it at any time without affecting prior processing.
If you wish to exercise any of the above rights, please contact us using the details provided on our website or in your order confirmation materials. We will respond within the timeframes set out by law.
How We Protect Your Data
We take appropriate technical and organisational security measures to protect your personal data from accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. These include secure payment processing, data encryption, and restricted staff access on a need-to-know basis.
Updates to This Policy
This policy may be updated from time to time to reflect changes in legal requirements or our business practices. Any significant changes will be communicated to you via an update on our website or other appropriate means.
Contact and Complaints
If you have any questions, concerns, or complaints regarding this Privacy Policy or how your data is handled, you can contact us using the details found on our website or your order confirmation. You also have the right to lodge a complaint with the Information Commissioner’s Office (ICO) if you believe that we are not meeting our data protection obligations.