Flowers Aldgate Privacy Policy
Introduction
At Flowers Aldgate, we are committed to safeguarding the privacy and personal data of everyone who places an order with us in Aldgate and the surrounding districts. This Privacy Policy outlines what personal information we collect, how we use it, our legal basis for its processing, how long we retain it, the role of third-party processors, and your rights under the General Data Protection Regulation (GDPR).
Scope of This Policy
This policy applies to all customers who order flowers and related products from Flowers Aldgate for delivery or collection within Aldgate and adjacent areas. The policy pertains to all interactions on our website, over the phone, or in our physical stores.
What Data We Collect
Flowers Aldgate collects and processes various types of personal data to ensure we can deliver our products and services effectively. The types of data we may collect include:
- Identity Data: Your first and last name.
- Contact Data: Delivery address, billing address, telephone number, and postal code.
- Order Data: Ordered products, recipient’s details (name, address, and phone number if provided by you), preferred delivery date and time, and any order-specific notes.
- Payment Data: Payment card details (through secure third-party processors), transaction records, and billing information.
- Communication Data: Correspondence with our support team, including feedback, complaints, or queries via contact forms or by phone.
- Technical Data: IP address, browser type, operating system, device identifiers, and website usage statistics (collected via cookies and analytics tools).
We do not knowingly collect or process the personal information of minors under the age of 16, unless explicit consent is given by a parent or legal guardian for the purpose of placing an order.
Lawful Basis for Processing Personal Data
Under GDPR, we must have a lawful basis for each aspect of data processing we carry out. The main lawful bases on which Flowers Aldgate relies include:
- Contractual Necessity: When processing your personal data is required for us to fulfill our contract with you, such as fulfilling your flower order and communicating about your purchase.
- Legal Obligation: When processing is necessary for us to comply with applicable legal requirements under UK and EU law, such as tax or accounting obligations.
- Legitimate Interest: When processing is necessary for our legitimate interests (or those of a third party), provided your interests and fundamental rights do not override those interests. For example, to improve our services, secure our online platform, or prevent fraud.
- Consent: When you have given us clear consent to process your data for a specific purpose, such as subscribing to newsletters or marketing communications. You may withdraw your consent at any time.
How We Use Your Data
Your personal information may be used to:
- Process and deliver your flower orders.
- Update you about order progress, confirmations, and delivery notifications.
- Respond to your enquiries, feedback, or support requests.
- Personalise your shopping experience.
- Maintain our business records for accounting, auditing, and legal compliance.
- Improve our products, services, and website performance through aggregated analytics.
- Send you marketing communications, if you have opted in to receive them.
How Long We Retain Your Data
Personal data is retained only for as long as necessary to fulfil the purposes outlined in this policy. Typically, Flowers Aldgate will keep:
- Order and transactional data for up to 7 years, to comply with accounting and legal obligations.
- Marketing data until you choose to unsubscribe or withdraw your consent.
- Correspondence and support requests for up to 2 years after resolution.
- Technical data for analytics and security purposes, generally no longer than 26 months.
Once your data is no longer needed, it will be securely deleted, anonymised, or archived as required by applicable law.
Processors and Data Sharing
To provide our services efficiently, we rely on selected third-party service providers who may act as "processors" of your data on our behalf. These may include:
- Payment processing companies to securely handle card payments.
- IT hosting, support, and cloud service providers for website and data management.
- Delivery services or couriers to complete your flower order deliveries.
- Providers of analytics and website performance tools.
All processors are contractually required to keep your data secure, process it only as instructed by us, and comply with applicable data protection laws. We do not sell or rent your personal information. We will only disclose your data to law enforcement or regulatory authorities if required by law.
International Data Transfers
Where your data is processed outside of the UK or European Economic Area (EEA), we will ensure appropriate safeguards are in place to maintain its protection in line with GDPR requirements.
Your Rights Under GDPR
Under GDPR, you have the following rights regarding your personal data:
- Access: You have the right to request a copy of the personal information we hold about you.
- Rectification: You may correct inaccurate or incomplete personal data.
- Erasure: In certain circumstances, you have the right to request deletion of your data ("the right to be forgotten").
- Restriction: You may request us to limit processing of your data in certain cases.
- Data Portability: You can ask for your data to be transferred to you or another provider in a structured, commonly used format.
- Objection: You may object to processing of your data, particularly for direct marketing.
- Withdraw Consent: Where processing is based on your consent, you can withdraw this at any time.
All requests will be considered and responded to in accordance with GDPR obligations and applicable exemptions.
Data Security
We employ robust physical, technical, and organizational measures to protect your personal data against accidental loss, unauthorized access, or misuse. This includes secure servers, encryption of sensitive information, regular staff training, and strict access controls.
Changes to This Policy
Flowers Aldgate may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. Any significant changes will be communicated to customers placing orders, and continued use of our services will indicate your acceptance of any updates.
Contact and Queries
If you have questions, concerns, or would like to exercise your rights regarding your personal data, please contact our customer service team. Details on how to contact us are available on our website and at our store. We are committed to addressing your request promptly and transparently, and you have the right to lodge a complaint with the relevant supervisory authority if you believe your data has not been handled in accordance with the law.