Flower Delivery Kensington Privacy Policy
Introduction
This Privacy Policy explains how Flower Delivery Kensington collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). Our commitment is to your privacy and the proper handling of your information. This policy applies to all individuals who place Flower Delivery Kensington orders from Kensington and surrounding districts.
What Data We Collect
To process your orders and deliver flowers efficiently, we may collect and process the following types of personal data:
- Identity Data: Name, title, and, when necessary, proof of identity (e.g. for high-value transactions).
- Contact Data: Delivery address, billing address, phone number(s), and any delivery instructions or contact details provided for yourself or recipients.
- Order Data: Details about your orders including recipients’ names, messages, and order history.
- Payment Data: Payment transaction details (note: payment card information is processed securely by third-party providers and not stored by us).
- Communication Data: Any correspondence with our customer service team, feedback, and reviews you may provide.
- Technical Data: IP address, browser type, time zone setting, device identifiers, and information about how you access our website.
Lawful Basis for Processing
Our legal grounds under the GDPR for processing your personal data are as follows:
- Contractual Necessity: Processing your data is necessary to fulfil the contract between us — i.e., to process and deliver your order, communicate with you regarding your purchase, and respond to your enquiries.
- Legal Obligation: For compliance with applicable laws and regulations (e.g., tax and accounting requirements).
- Legitimate Interests: We process certain data to improve our services, ensure security, and perform analytics, provided these interests are not overridden by your rights and interests.
- Consent: In specific circumstances, such as for direct marketing purposes or where legally required, we will request your explicit consent before processing.
How We Use Your Data
We use your data for the following purposes:
- To process, fulfil, and deliver your flower orders, including contacting you or recipients regarding delivery.
- To handle enquiries, customer support requests, and disputes.
- To manage payments and billing.
- To keep accounting records and comply with legal obligations.
- To enhance our website’s user experience and security.
- With your consent, to send you offers, updates, or marketing communications.
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes for which we collected it, including for satisfying any legal, accounting, or reporting requirements. Typically:
- Order, identity, and contact data are retained for up to seven (7) years after your last transaction to comply with our regulatory obligations and for potential dispute resolution.
- Marketing data, if you have opted in, will be kept until you withdraw your consent or opt out.
- Technical log data may be retained for up to one (1) year for security and analytical purposes.
At the end of the retention period, your data is securely deleted or anonymised.
Data Processors and Sharing
To deliver our services, we may share your data with trusted third-party processors, such as:
- Payment processing companies (to securely handle transactions).
- IT and website hosting providers.
- Delivery partners or couriers (to deliver your orders).
- Professional advisers (such as accountants or legal advisers).
- Service providers for customer relationship management and analytics.
All our processors are vetted for GDPR compliance and may only process your data on our instructions. We do not sell your data to third parties for their own marketing use.
International Data Transfers
In some cases, your personal data may be processed outside the UK or European Economic Area (EEA) (for example, if our website providers use servers in other countries). When such transfers occur, we ensure that appropriate safeguards are in place, such as contractual clauses, to protect your information in line with legal requirements.
Your Rights Under GDPR
You have the following rights in connection with your personal data:
- Right of Access: Request a copy of the personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete information.
- Right to Erasure: Request deletion of your data in certain circumstances, such as where it is no longer needed, or you withdraw consent.
- Right to Restrict Processing: Temporarily limit the processing of your data under specific conditions.
- Right to Data Portability: Receive your data in a structured, commonly used machine-readable format for transfer to another provider, where technically feasible.
- Right to Object: Object to the processing of your data based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw your consent at any time without affecting the lawfulness of processing before withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the relevant data protection authority if you believe your privacy rights have been infringed.
Policy Updates
We reserve the right to update or amend this Privacy Policy. Any substantial changes will be communicated to you and will be reflected here so you always understand how your data is handled. We encourage customers to review this policy periodically.
Contact and Further Information
If you have any questions regarding this Privacy Policy or your rights under GDPR, please contact us through our website contact form or by postal mail at our registered business address. We take privacy concerns seriously and will respond to your requests in accordance with applicable data protection laws.