Ealing Flowers Privacy Policy – Customer Data and Rights
Overview
This Privacy Policy sets out how Ealing Flowers collects, processes, stores, and protects your personal data when you place an order with us. We are committed to handling your information responsibly and lawfully in accordance with the UK General Data Protection Regulation (GDPR) and all other applicable privacy laws. This policy applies to all customers who place orders with Ealing Flowers, whether the purchase is for delivery or collection, in Ealing and the surrounding districts.
What Data We Collect
When you interact with Ealing Flowers to place an order or make an enquiry, we may collect and process the following types of personal data:
- Contact details: This includes your name, address, phone number, and delivery address for both you and, where applicable, the recipient of the flowers.
- Order information: Details of the products or services you purchase, order history, messages to include with your flowers, and transaction information.
- Payment details: We process payment information via secure third-party payment processors. Ealing Flowers does not retain your full card details.
- Communication records: Any correspondence you have with us via our website forms, telephone, or in writing, including any complaints, queries, or feedback.
- Website usage information: Data collected by cookies and analytics technologies when you visit our website, such as IP address, device type, browser type, and browsing behavior.
Our Lawful Basis for Processing Your Data
Under the UK GDPR, we process your personal data on the following lawful bases:
- Contractual necessity: To fulfill your order, process your payment, deliver flowers to you or your recipient, and provide customer service relating to your purchase.
- Legitimate interests: For business administration, fraud prevention, record-keeping, direct marketing of similar products, and to improve our products and services.
- Legal obligation: Where required by law, such as maintaining financial records for tax purposes.
- Consent: If you opt in to receive marketing communications, we will rely on your explicit consent, which you may withdraw at any time.
How We Use Your Data
Your personal data is used for the following purposes:
- To process and fulfill your orders, including delivery to the specified recipient.
- To communicate with you regarding your order, including confirmations, updates, and any queries we may have.
- To manage payments, refunds, and verify your identity where required.
- To comply with legal, tax, and accounting requirements.
- For internal business analysis, customer service improvements, and fraud prevention.
- To send direct marketing about our products and relevant special offers, only where you have not opted out or have provided consent.
Sharing Your Data: Third-party Processors
Ealing Flowers shares your personal data only when necessary and only with trusted third-party processors who help us deliver our services. These include:
- Payment processors: Secure third-party platforms that handle your payment transactions.
- Delivery partners: Couriers and delivery drivers for fulfilling your orders in Ealing and surrounding areas.
- IT service providers: Companies that support our website, store data for us, or provide analytics services to help improve our business and customer experience.
All third-party processors are contractually obligated to safeguard your information and to use it only for specified purposes on our behalf. They may only process your data in accordance with our instructions and applicable data protection laws.
Data Retention: How Long We Keep Your Data
Ealing Flowers only retains your personal information for as long as is necessary to fulfill the purposes for which it was collected, including to meet any legal, accounting, or reporting requirements. Typically, we keep:
- Order and transaction data for up to 7 years to comply with UK tax and accounting regulations.
- Customer correspondence for up to 3 years after the last interaction to help resolve any ongoing issues or disputes.
- Marketing consent records until you withdraw your consent or unsubscribe.
- Website analytics data is retained in aggregate form for up to 2 years for analysis and improvement purposes.
Once your data is no longer required, we will securely delete or anonymise it.
Security of Your Information
We take the security of your personal information seriously. Appropriate technical and organisational measures have been implemented to prevent unauthorised access, loss, alteration, or disclosure of your data. This includes encryption, secure storage, and regular reviews of our security practices.
Your Rights under GDPR
As a data subject, you have the following rights regarding your personal data:
- Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You can ask us to correct or update inaccurate or incomplete information.
- Right to erasure: You may request deletion of your data, subject to certain legal and contractual obligations.
- Right to restrict processing: You can request the restriction or suppression of your personal data in some circumstances.
- Right to data portability: You have the right to receive your data in a structured, commonly used, and machine-readable format.
- Right to object: You have the right to object to certain uses of your data, such as direct marketing.
- Right to withdraw consent: Where we rely on your consent for processing, you can withdraw consent at any time without affecting the lawfulness of processing before withdrawal.
- Right to complain: You can lodge a complaint with the UK Information Commissioner's Office (ICO) if you believe your data protection rights have been violated.
To exercise your rights, please contact us using the details provided at the end of this policy or on our website. We aim to respond to all requests within one month.
Changes to This Privacy Policy
Ealing Flowers may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or for other operational reasons. Any significant changes will be communicated clearly on our website. We encourage you to review this policy regularly.
Contact and Further Information
If you have any questions about how we handle your personal data or wish to exercise your GDPR rights, please contact us through the contact form available on our website or by writing to us at our business address. We are committed to ensuring your privacy and addressing any concerns promptly and transparently.