Belgravia Flowers Privacy Policy
Introduction
This Privacy Policy describes how Belgravia Flowers collects, uses, stores, and protects your personal data when you place orders with us. We are committed to handling your information responsibly and in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers who place orders with Belgravia Flowers from Belgravia and the surrounding districts.
What Data We Collect
To fulfill your orders and provide you with the best possible service, we collect the following types of personal data:
- Identity Data: This includes your name and, if relevant, the recipient's name.
- Contact Data: This includes your home or delivery address, billing address, and contact details such as phone number (if provided).
- Order and Transaction Data: Details of the products you order and purchase, as well as delivery instructions.
- Payment Data: Your payment card information or other payment details. Note that payment processing is handled securely by third-party payment processors and we do not store your full payment card details.
- Communications Data: Any correspondence or feedback you share with us, including emails or notes accompanying your orders.
- Technical Data: IP address, browser type, and other technical information automatically collected when you interact with our website or online services.
Lawful Basis for Processing Your Data
We collect and process your personal data only when there is a lawful basis to do so. The legal grounds for processing your data are:
- Performance of a Contract: Most personal data we collect is necessary for the fulfillment of your order and ensuring successful delivery.
- Legal Obligations: We retain certain information to comply with statutory obligations, such as record-keeping for tax and accounting purposes.
- Legitimate Interests: We may process your data for our legitimate interests, such as conducting business analysis, fraud prevention, and improving our services, provided these do not override your rights.
- Consent: For marketing purposes, we only contact you if you have given explicit consent. You can withdraw your consent at any time.
Data Retention
We retain your personal data only as long as necessary for the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. In general:
- Order and transaction data are retained for up to 7 years to comply with financial and tax regulations.
- Marketing contact details are retained until you withdraw your consent or unsubscribe.
- Technical data may be retained for analytics and security purposes for a period of up to 2 years.
Once your data is no longer needed, it is securely deleted or anonymised.
Use of Data Processors
We sometimes engage third-party service providers ("processors") to assist with aspects of our business operations, which may include:
- Payment processing
- Order management systems
- Delivery and courier services
- IT and website hosting
- Email and marketing services (where you have provided consent)
We require all processors to adhere to GDPR standards, process your data solely on our instructions, and implement appropriate safeguards to protect your information. We never sell your data or allow our processors to use your data for their own purposes.
Data Security
We place high importance on your data security. Measures we use include password protection, encryption, access controls, and regular review of our systems. Payment transactions are processed through secure, PCI-compliant providers. While we strive to protect your personal data, no system is completely secure and you also play a vital role by keeping your account details confidential.
Your Rights Under GDPR
Under the GDPR, you have various rights relating to your personal data:
- Right of Access: You may request confirmation of what personal data we hold about you and obtain a copy.
- Right to Rectification: You may ask us to correct inaccurate data or complete incomplete data.
- Right to Erasure: You can request deletion of your personal data in certain circumstances (e.g. where it is no longer needed).
- Right to Restrict Processing: You may ask us to suspend processing your data if you contest its accuracy or object to processing.
- Right to Data Portability: You may request a copy of your data in a machine-readable format for transfer to another provider.
- Right to Object: You can object to processing based on legitimate interests or for direct marketing.
- Right to Withdraw Consent: Where we rely on your consent, you may withdraw this at any time, which will not affect any processing carried out before withdrawal.
Children's Privacy
Our services are not directed to individuals under the age of 16. We do not knowingly collect data from children. If we learn we have collected personal data from a child, we will take appropriate steps to delete such information.
Changes to This Policy
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The latest version will always be available when you place an order with us. We encourage you to review this policy from time to time.
Contact and Complaints
If you have any questions about this Privacy Policy or how we handle your data, or if you wish to exercise any of your rights, please contact us using the contact options provided on our website or in your order confirmation documents. If you have concerns about our data practices, you may also lodge a complaint with your local data protection authority.