Privacy Policy for Customers of Flower Delivery Chalk Farm
Introduction
This Privacy Policy explains how Flower Delivery Chalk Farm collects, uses, and protects your personal data when you place an order with us, whether online or over the phone. The policy applies to all customers purchasing flower deliveries to Chalk Farm and surrounding districts. We are committed to processing your personal data securely and transparently, in accordance with the General Data Protection Regulation (GDPR) and UK Data Protection laws.
What Data We Collect
To fulfil your order and provide excellent customer service, Flower Delivery Chalk Farm may collect the following categories of personal data:
- Contact Information: Your name, delivery address, billing address, telephone number, and any contact details required for fulfillment and communication.
- Order Details: Information about the products you order, personalised messages, and delivery instructions.
- Payment Information: Details necessary to process your payment (e.g. payment card information), but we do not store full card details.
- Account Information: If you register an account with us, your username and password are stored securely.
- Communications: Records of your communications with us, including emails and telephone correspondence.
- Technical Information: Data such as your browser type, device type, IP address, and cookies if you visit our website, as necessary for website functionality and analytics.
Lawful Basis for Processing Data
Under GDPR, Flower Delivery Chalk Farm must have a lawful basis for processing your personal data. The main bases we rely upon include:
- Contractual Necessity: Processing your personal data as required to fulfil your order and deliver the requested services.
- Legal Obligation: Certain information may be retained to comply with applicable laws, such as record-keeping for tax purposes.
- Legitimate Interests: We may use your details to improve our services, enhance security, and carry out business operations, provided these interests are not overridden by your rights.
- Consent: If you sign up to receive marketing communications, we will only contact you in line with your preferences and where you have given explicit consent. You have the right to withdraw your consent at any time.
How We Use Your Data
Flower Delivery Chalk Farm uses your personal data for the following purposes:
- To process and deliver your orders efficiently.
- To communicate with you about your order, respond to your enquiries, or contact you about any issues or changes.
- To handle payments and prevent fraudulent transactions.
- To comply with our legal and regulatory obligations.
- With your consent, to send you news, promotions, or updates relevant to our flower delivery service.
- To improve our website, products, and overall customer experience through business analytics.
Retention of Your Data
We will retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of legal, accounting, or reporting requirements. For example:
- Order and delivery records are typically retained for up to 6 years, to comply with financial and legal obligations.
- Account details remain on file until you request deletion or close your account.
- If you have consented to marketing communications, your contact information is kept until you opt-out or withdraw your consent.
When data is no longer required, it is securely deleted or anonymised.
Our Data Processors and Third Parties
To provide our services, we may share limited information with trusted third-party service providers (data processors), including:
- Payment processing companies to securely process your payments.
- Delivery and courier services to fulfil your order and ensure timely delivery.
- IT and web hosting providers supporting our website and customer management systems.
- Professional advisers (such as accountants or legal consultants) where necessary for our business operations.
All processors are contractually obligated to process your data securely and only for the purpose indicated. Your data is never sold or shared with unauthorised third parties.
Your Data Protection Rights
As a customer within Chalk Farm and the surrounding districts, you are entitled to the following rights under GDPR:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct or update any inaccurate or incomplete information.
- Right to Erasure: You may ask for your personal data to be deleted where there is no good reason for us to continue processing it.
- Right to Restrict Processing: You have the right to ask us to restrict the processing of your data in certain circumstances.
- Right to Data Portability: You can request that we provide your data in a structured, commonly used format, and transfer it to another provider where feasible.
- Right to Object: You may object to the processing of your personal data based on our legitimate interests or for marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw this at any time.
- Right to Lodge a Complaint: If you believe your data has been mishandled, you may complain to the UK Information Commissioner's Office.
Security of Your Data
Protecting your personal data is our priority. Flower Delivery Chalk Farm uses secure systems, appropriate technical and organisational measures, and encryption where possible to safeguard your information against loss, misuse, and unauthorised access, disclosure, alteration, or destruction.
Policy Updates
We may update this Privacy Policy from time to time in response to changes in our services, legal requirements, or data protection standards. Updates will be made available on our website. If significant changes occur, we will notify customers by appropriate means where possible.
Contacting Us
If you have any questions about this Privacy Policy or wish to exercise your data protection rights, please contact us using our website’s contact form or postal address. We will respond to all legitimate requests within one month, as required by GDPR.