Flowers Whitechapel Privacy Policy
Introduction
This Privacy Policy describes how Flowers Whitechapel processes and safeguards the personal data of customers placing orders from Whitechapel and the surrounding districts. We are committed to complying with the UK General Data Protection Regulation (GDPR) and ensuring all personal information is handled in accordance with legal obligations and best practices. This policy explains what data we collect, the lawful grounds for processing, how long we keep it, details about any processors we engage, and your rights as a customer.
The Data We Collect
We collect and process the following types of personal data when you place an order with Flowers Whitechapel:
- Identity Data: Your full name.
- Contact Data: Delivery address, billing address, and contact phone number.
- Order Data: Details of your order, such as flower selection, delivery date, and any notes for the recipient.
- Payment Data: Payment method and partial payment details (handled securely via our payment processor; card details are not stored by us).
- Correspondence Data: Any communications you may have with us regarding your order or enquiries.
- Technical Data: Device, browser type, and anonymised usage data collected through essential website cookies for service functionality and security.
We do not collect or process special category data such as racial or ethnic origin, health status, or biometric data.
Lawful Basis for Processing
Under the GDPR, we must have a lawful basis to process your personal data. Flowers Whitechapel relies on the following bases:
- Contractual necessity: Processing your information is necessary for fulfilling your order and delivering our services.
- Legal obligation: Some personal data processing is required to comply with laws relating to taxation, accounting, and consumer rights.
- Legitimate interest: We may use certain data to improve our customer service, secure our systems, and prevent fraud, where these interests do not override your fundamental rights and freedoms.
- Consent: Where appropriate, we obtain your explicit consent, for example if you sign up for marketing communications. You may withdraw consent at any time.
How We Use Your Data
We use your personal data to:
- Process and deliver your flower order
- Contact you with order updates or to resolve queries
- Comply with legal and regulatory obligations
- Improve our website and service offerings
- Handle any complaints, refunds, or customer support matters
- If you consent, to send you news, offers, or recommendations about products and services
Data Retention
We retain your personal data only for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal, accounting, or reporting requirements. The typical retention periods are:
- Order and transaction data: retained for up to 7 years to comply with accounting and tax regulations.
- Correspondence data: retained for 2 years from the date of your last communication with us.
- Technical and usage data: retained only as long as strictly required for system operations, performance analytics and troubleshooting.
- Marketing or newsletter data: retained until you withdraw your consent.
After these periods, data will be securely erased or anonymised so that it is no longer identifiable.
Data Processors and Third-Party Access
We may share or store your data with trusted third-party service providers (data processors) who assist us in delivering our services. Examples include:
- Payment processing companies (for secure handling of your payments)
- Website and IT hosting providers (for running our website and servers)
- Courier or delivery service partners only for the purpose of delivering your orders
- Professional advisors (such as accountants), where required by law
These processors are contractually obligated to handle your data securely, in line with GDPR requirements, and may not use your information for their own purposes. We do not sell or trade your personal data.
Wherever possible, data is stored and processed within the UK or European Economic Area. Where data is transferred outside these territories, we ensure equivalent data protection safeguards are in place.
Your Rights
Under the GDPR, you have a number of rights in respect of your personal data. You can:
- Access – Request a copy of the personal data we hold about you.
- Rectification – Ask us to correct any inaccurate or incomplete information.
- Erasure ("right to be forgotten") – Request that your data be deleted in certain circumstances.
- Restriction – Ask us to restrict the processing of your personal data in certain situations.
- Portability – Receive your personal data in a structured, commonly used format.
- Objection – Object to processing, especially regarding direct marketing or where our legitimate interests are relied upon.
- Withdraw consent – Where processing is based on your consent, you have the right to withdraw it at any time.
- Lodge a complaint – You can complain to the UK Information Commissioner’s Office (ICO) if you believe your data protection rights have been violated.
We will respond to your requests to exercise your rights within one month, unless the request is complex, in which case we will inform you of any delay.
Policy Scope and Updates
This policy applies to all customers placing orders with Flowers Whitechapel, including residents or recipients located in Whitechapel and the surrounding districts. We may update this policy from time to time in response to changes in legislation or our data protection practices. The most current version will always be available via our website or upon request.
Contact and Further Information
If you have any questions about how Flowers Whitechapel uses your personal data, or to exercise any of your rights, please contact us using the details provided on our website. We are happy to address your privacy concerns and assist with any requests in line with our legal obligations.