Flower Delivery Chessington Data Protection Policy
Scope of This Privacy Policy
This Privacy Policy describes how Flower Delivery Chessington collects, uses, stores, and protects your personal information in accordance with the General Data Protection Regulation (GDPR). The Policy is applicable to all customers placing orders with Flower Delivery Chessington within Chessington and the surrounding districts. By placing an order or using our services, you acknowledge and agree to the practices described herein.
What Data We Collect
When you place an order with Flower Delivery Chessington, or interact with our services, we may collect and process the following categories of personal data:
- Contact Information: such as your name, recipient’s name, delivery address, billing address, and phone number.
- Order Details: including types of flowers, messages on cards, preferred delivery dates, and any special instructions.
- Payment Information: transaction details required to complete your purchase; we do not directly store your card numbers, but our payment processors may retain necessary details to process the transaction.
- Communication Data: records of communication such as messages, calls, and feedback concerning your order or inquiries.
- Technical Data: such as IP address, browser type, and device information collected via our website for security, analytics, and service improvement.
Lawful Basis for Data Processing
We process your personal data in accordance with at least one lawful basis as defined under GDPR:
- Performance of Contract: Most data processing activities are necessary to fulfil your order and provide the requested services.
- Legal Obligation: We retain certain data to comply with applicable financial, tax, and legal obligations.
- Legitimate Interests: To enhance our services, prevent fraud, ensure security, and respond to communications, provided that these interests do not override your fundamental rights and freedoms.
- Consent: In specific cases, such as marketing communications, we will request your explicit consent before processing your information for such activities.
How We Use Your Data
Your information is used for the following purposes:
- Processing and delivering your flower orders, including order updates and customer service.
- Communicating with you in relation to your orders or inquiries.
- Processing payments and refunds.
- Improving our services and website functionality.
- Conducting necessary fraud checks and security measures.
- Complying with legal or regulatory requirements.
How Long We Retain Your Data
We will not retain your personal data for longer than is necessary for the purpose for which it was collected. The specific retention period depends on the nature of the data and the purpose of processing:
- Order Data: Retained for up to 7 years for accounting and legal compliance.
- Marketing Preferences: Retained until you withdraw your consent or update your preferences.
- Communication Records: Retained for up to 3 years to resolve disputes or for quality assurance.
- After the relevant retention periods expire, your data will be securely deleted or anonymized.
Data Processors and Third Parties
To provide our services, certain personal data may be shared with third-party service providers, also known as data processors. These may include:
- Payment Processing Providers: Securely handle transactions and protect payment information.
- Delivery Partners: Required to deliver your flowers efficiently and as instructed.
- IT Service Providers: Assist with website hosting, system maintenance, and data storage.
- Professional Advisors: Such as accountants or legal consultants, to fulfil legal obligations.
All processors act under written agreements and are required to adhere to the same standards of security and confidentiality regarding your data. We do not sell, trade, or rent your personal data to any third parties for marketing purposes.
Your Rights Under GDPR
As a customer in Chessington and its surrounding districts, you have rights under GDPR in relation to your personal data:
- Right of Access: You can request confirmation and a copy of the personal data we hold about you.
- Right to Rectification: You can request corrections to any inaccurate or incomplete data.
- Right to Erasure: You may ask for your personal data to be deleted when there is no legal or contractual necessity for us to retain it.
- Right to Restrict Processing: You can request that we temporarily suspend the processing of your data in certain situations.
- Right to Data Portability: You are entitled to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format.
- Right to Object: You can object to our processing of your personal data under specific circumstances, such as direct marketing.
- Right to Withdraw Consent: Wherever we rely on your consent, you may withdraw it at any time.
To exercise any of these rights, please contact us using the contact details provided when you placed your order or through our official channels provided on our website. We may require verification of your identity before proceeding with your request. Response to your request will be provided within one month as required by the GDPR regulations.
Data Security
We apply robust technical and organizational measures to ensure that your personal data is kept secure, accurate, and confidential. Measures include encryption, restricted access, regular security reviews, and staff training. Nevertheless, please note that no method of transmission over the Internet or storage is entirely secure, and we cannot guarantee absolute security of your data.
Policy Updates
This Privacy Policy may be subject to periodic updates in response to legal, technical, or business developments. Any changes will be clearly indicated on our website, and continued use of our services after such changes indicates your acceptance of the new terms. We encourage you to review this page regularly for any updates.
Contacting Us
If you have any questions regarding this Privacy Policy or your personal data, please contact our customer service team using the official channels listed on our website or in your order confirmation documents. We are committed to addressing your queries and supporting your rights as a data subject under GDPR.