Flowers Camden Privacy Statement
Privacy Policy Overview
This Privacy Policy explains how Flowers Camden (“we”, “our”, or “us”) collects, uses, processes, and protects your personal data when you place an order, make an enquiry, or interact with our services from Camden and the surrounding districts. We are committed to safeguarding your privacy and ensuring compliance with the General Data Protection Regulation (GDPR).
Scope of This Policy
This policy applies to all individuals placing orders for flowers and related services with Flowers Camden, whether directly through our website, by telephone, or in person, from Camden as well as the surrounding districts. By engaging with our services, you acknowledge you have read and understood this Privacy Policy.
What Data We Collect
We may collect and process the following categories of personal data about you:
- Identity Data: Name and, if required, business details (when placing corporate orders).
- Contact Data: Delivery address, billing address, telephone numbers, and, where applicable, email addresses.
- Order Details: Information about the products or services you order, delivery instructions, and special requests.
- Payment Details: Limited payment information where required to process your order (such as transaction references). Full payment details (e.g., credit/debit card numbers) are processed securely by our payment processors and are not stored by Flowers Camden.
- Correspondence: Records of communications, including order confirmations, queries, and feedback.
- Technical Data: Browser type, device identifiers, and IP address when you access our website (collected via cookies and analytics tools).
Lawful Basis for Processing
Flowers Camden processes your personal data in accordance with GDPR, relying on one or more of the following lawful bases:
- Contractual Necessity: Processing necessary for the performance of a contract to which you are a party, such as fulfilling your flower order.
- Legal Obligations: Processing required to comply with tax, accounting, or other legal duties.
- Legitimate Interests: Where processing is necessary for our legitimate business interests, for example, improving our services or preventing fraud, and where such interests are not overridden by your rights.
- Consent: Where you have provided clear consent for us to process your data in specific ways, such as for receiving marketing communications. You may withdraw your consent at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- To process and fulfil your orders, including arranging delivery and invoicing.
- To communicate with you regarding your order, delivery status, or in response to your queries.
- To improve our products, services, and overall customer experience.
- To comply with applicable laws, regulations, and legal obligations.
- To send you updates and marketing communications, where you have opted in.
- For security purposes, including fraud prevention and record keeping.
How Long We Retain Your Data
We retain your personal data only as long as necessary to fulfil the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Our typical retention periods are as follows:
- Order and transaction details: Generally retained for up to seven years to comply with tax and accounting obligations.
- Contact and identity details: Retained for as long as your customer account remains active, or until you request erasure, unless retention is required for legal purposes.
- Marketing communications: Kept until you opt-out or withdraw consent.
- Website analytics and technical data: Retained in anonymised form for website analysis and improvements for up to two years.
Data Processors and Third Parties
To provide our services, we may share your personal data with trusted third-party service providers who process data on our behalf (“data processors”). These include:
- Payment processing providers (for secure transaction handling).
- Delivery and courier services (to arrange the delivery of your orders).
- IT, website hosting, and customer management systems providers.
- Analytics service providers (for website usage analysis).
We ensure that all processors handle your data safely and in line with GDPR, under strict contractual obligations. Your data is not transferred outside the UK or European Economic Area unless adequate safeguards are in place.
Your Rights Under GDPR
You have a number of rights in relation to your personal data, subject to certain limitations. These include:
- Right to Access: Request confirmation of whether we process your personal data and receive a copy of that data.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data in certain circumstances ("right to be forgotten").
- Right to Restrict Processing: Require us to limit processing in specific cases.
- Right to Data Portability: Receive your data in a commonly used format and transmit it to another controller, where applicable.
- Right to Object: Object to processing where we rely on legitimate interests, including direct marketing.
- Right to Withdraw Consent: Where you have given consent, you have the right to withdraw it at any time.
- Right to Lodge a Complaint: You can raise concerns with a supervisory authority if you feel your data rights have not been upheld.
Updates to This Policy
We may update this Privacy Policy from time to time, with changes taking effect when posted on our website or made available upon request. We recommend you review this policy periodically to stay informed about our data protection practices.
Contact and Queries
If you have any questions about this Privacy Policy or how your data is handled, please get in touch using the contact information provided on our website or in your order documentation. We will respond to any requests in accordance with applicable data protection laws.