This Privacy Policy sets out how Flower Delivery Highams Park ("we", "us", "our") collects, processes, stores, and protects personal data relating to customers who place flower delivery orders in Highams Park and the surrounding districts. This policy applies to all users accessing our services within these areas.
We collect and process different types of personal data, depending on how you interact with us and which services you use. The following categories of data may be collected when you place an order or contact us:
Under the UK General Data Protection Regulation (GDPR), we must have a valid reason (lawful basis) for using your personal data. We process your data under one or more of the following lawful bases:
We use your personal data for the following purposes:
We retain your data only for as long as it is necessary for the purposes described above, in accordance with our legal obligations and legitimate business needs. For example, order and transaction data is typically retained for up to seven years to satisfy tax or legal reporting requirements. Where your data is kept solely based on your consent (e.g., marketing), we will delete it promptly if you withdraw your consent.
We engage with third-party processors to assist in delivering our services and fulfilling your orders. These may include payment gateways, IT support providers, delivery partners, and cloud storage services. All third parties are carefully selected to ensure they meet GDPR standards and are contractually obliged to use your data only as instructed by us. We do not sell or lease your personal data to third parties for marketing purposes.
In certain circumstances, we may share your data with law enforcement agencies or regulators if required by law. Any third-party recipients are only given access to the information necessary to perform their contractually agreed service.
We have implemented appropriate technical and organisational measures to safeguard your personal data, including encryption, access controls, and regular security audits. Only authorised employees and processors have access to your data, and only for legitimate business purposes.
The GDPR provides you with specific rights regarding your personal data. You may exercise these rights subject to legal and practical obligations, and we are committed to enabling your rights. Your rights include:
To exercise any of your rights, please contact us using the details provided at the end of this policy. We aim to respond to all legitimate requests within one calendar month.
Your data is stored primarily within the United Kingdom or European Economic Area. If we need to transfer data outside these regions, we ensure appropriate safeguards are in place as required by GDPR.
We may update this Privacy Policy periodically to reflect changes in law, regulation, or our practices. The latest version will always be available to you, and material changes will be notified prominently where appropriate.
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, you are encouraged to contact us using the methods available on our website. We take your privacy seriously and will endeavour to assist you promptly and transparently.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
