Kingston upon Thames Flowers Privacy Policy
Introduction and Scope
This Privacy Policy outlines how Kingston upon Thames Flowers ("we", "our", "us") collects, processes, stores, and shares personal data of customers placing orders from Kingston upon Thames and the surrounding districts. We are committed to complying with the General Data Protection Regulation (GDPR) and safeguarding your privacy. This policy applies to all individuals and organisations who order floral arrangements and related services from us, whether online, by phone, or in person.
What Personal Data We Collect
When you place an order or interact with Kingston upon Thames Flowers, we may collect and process the following categories of personal data:
- Contact Information: Name, delivery address, billing address, and postcode.
- Communication Details: Order notes, card messages, and preferences shared with us via website forms or conversations (including phone or in-person).
- Transaction Data: Details of floral orders placed, purchase history, transaction value, and payment confirmation (note: credit/debit card information provided online is processed directly by our payment processor and not stored by us).
- Technical Data: IP address, browser type, operating system, device identifiers, and information collected via cookies (for website security, analytics, and functionality purposes).
Lawful Basis for Processing Your Data
We process your personal data according to the lawful bases under the GDPR:
- Contractual Necessity: To fulfil and deliver your order, handle payments, process refunds, and provide customer service.
- Legitimate Interests: For business operations such as record keeping, ensuring the security of our transactions, preventing fraud, improving our service, or sending service communications related to your order.
- Legal Obligation: To comply with applicable financial, accounting, and tax regulations.
- Consent: Where required, for marketing communications or using certain cookies. You will only receive marketing material if you opt in and can withdraw your consent at any time.
How We Use Your Personal Data
Your information is used for the following purposes:
- Processing and delivering flower orders including communicating with you about your purchase and any delivery updates
- Managing payment and delivery arrangements
- Responding to your enquiries and resolving issues
- Meeting our legal and regulatory obligations, including record retention
- Improving our products, customer service, and website functionality
- Sending newsletters or promotions (only with your explicit consent or subscription)
Personal Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected, including for the purposes of satisfying any legal, accounting, or reporting requirements:
- Order-related data: Kept for up to seven years to comply with financial and tax regulations.
- Marketing preferences: Retained until you unsubscribe or withdraw your consent.
- Enquiry records: Typically held for up to two years from resolution of the enquiry.
Once data is no longer required, it is securely deleted or anonymised.
Processors and Sharing of Personal Data
We do not sell or rent your personal information. We may need to share certain data with trusted third parties ("processors") in order to operate our business and provide services:
- Payment Processors: For secure payment transactions. They are compliant with relevant security standards and do not share card information with us.
- IT and Web Hosting Providers: Who assist with website management, email delivery, and secure data storage.
- Delivery Partners: For delivering your orders to the provided address, only necessary information is shared.
- Professional advisors and legal authorities: When required for compliance or legal claims.
All processors are contractually obligated to safeguard your data, act only on our instructions, and comply with GDPR requirements. We do not transfer personal data outside the UK or European Economic Area unless adequate protection is in place.
Your Rights Under GDPR
Under the GDPR, you have a range of rights in relation to your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right of Rectification: Request correction of any inaccurate or incomplete data.
- Right of Erasure: Request that we delete your personal data in certain circumstances.
- Right to Restrict Processing: Ask us to limit how we use your data.
- Right to Data Portability: Receive your data in a commonly used format and transfer it to another provider.
- Right to Object: Object to processing based on legitimate interests or direct marketing.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time.
If you wish to exercise these rights, or have concerns about your data, you may contact us using the details on our website or order confirmation materials. We will respond within one month of receiving your request. You also have the right to complain to the UK Information Commissioner's Office (ICO) if you believe your data has not been handled according to GDPR requirements.
Data Security
We implement appropriate security measures to protect your personal data from unauthorised access, loss, misuse or alteration. These include secure servers, up-to-date software, and restricted access to data. Despite our best efforts, no system can guarantee absolute security, but we actively monitor and improve our protections as necessary.
Policy Updates
We may review and update this Privacy Policy periodically to reflect changes in our practices, technology, or legal requirements. When changes are made, the revised policy will be posted on our website with an updated "Effective Date." We encourage you to review this policy regularly.