Privacy Policy for Flowers Sutton
Our Commitment to Your Privacy
At Flowers Sutton, we are dedicated to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, protect, and share your personal data when you place an order with Flowers Sutton in Sutton and its surrounding districts. The policy also explains your rights under the General Data Protection Regulation (GDPR) and how you can exercise those rights.
Who This Policy Applies To
This Privacy Policy applies to all customers and users who place orders with Flowers Sutton or interact with us in the context of flower orders or related inquiry services. This includes individuals ordering for themselves, on behalf of others, or as recipients of our services, within Sutton and the surrounding districts.
What Data We Collect
To fulfill your flower order and ensure our services run smoothly, we may collect the following types of personal data:
- Contact Information: Full name, address (delivery and billing), phone number(s), and, where applicable, methods of communication such as social media handles.
- Order Details: Items purchased, delivery instructions, notes, or preferences included in your order.
- Payment Information: Details necessary to process your purchase, such as payment card data or transaction references. We do not store your payment card details; these are processed securely by our chosen payment providers.
- Correspondence: Any communications you have with us, including queries and feedback.
- Recipient Information: Name, address, and (if provided) contact number for the intended recipient, supplied by you as part of your order.
- Technical Information: Where relevant, information on how you interact with our website, such as IP address, browser type, and browsing activity. This is usually collected through cookies or similar technologies.
Lawful Basis for Processing
Our collection and use of your personal data are based on the following lawful bases under the GDPR:
- Contractual Necessity: Most data we process is required to fulfill our contract with you; for example, to process your order, arrange delivery, or handle payment and refunds.
- Legitimate Interests: We may process your data for our legitimate business interests, such as improving our services, preventing fraud, or communicating service updates not directly related to marketing.
- Legal Obligation: In certain circumstances, we are required by law to retain specific information, for example, for tax or accounting purposes.
- Consent: If we need to process your data for purposes outside those listed above, such as direct marketing by email, we will seek your explicit consent, which can be withdrawn at any time.
How We Use Your Personal Data
Your data is used to:
- Process and fulfill your flower orders
- Communicate with you regarding your orders, invoicing, and delivery details
- Improve and develop our products and services
- Handle customer service requests, feedback, or disputes
- Comply with legal and regulatory requirements
How We Retain Your Data
We retain your personal data only as long as necessary to fulfill the purposes for which it was collected, including to satisfy any legal, accounting, or reporting requirements. Usually, personal data related to financial transactions is retained for up to 7 years for tax and record-keeping purposes. Non-financial order information may be retained for a shorter period, unless you have consented to ongoing communications (such as updates or marketing). After these periods, your data will be securely deleted or anonymised.
Our Data Processors
We may share your personal data with selected third parties providing services on our behalf (data processors), such as:
- Payment processing companies used to handle your payments securely
- Delivery partners or couriers who deliver your orders
- IT service providers who host our website or provide technical support
- Professional advisors (accountants, legal advisors) when required for compliance and to safeguard our business interests
All third-party processors are required to respect the security of your personal data and to process it in accordance with the law. We do not permit our third-party service providers to use your personal data for their own purposes.
How We Protect Your Data
We have implemented appropriate technical and organisational measures to protect your personal data from unauthorised access, alteration, disclosure, or destruction. These measures include restricting access to personal data to only those employees, agents, and contractors who need it to provide our services, as well as using secure systems and, where appropriate, encrypted communications.
Your Rights Under GDPR
Under the GDPR, you have rights regarding your personal data we hold. These include:
- Right to Access: Request confirmation and copies of the personal data we hold about you.
- Right to Rectification: Request that we correct any inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data where there are no overriding grounds for its continued processing.
- Right to Restrict Processing: Ask us to suspend the processing of your personal data in certain circumstances.
- Right to Data Portability: Receive your personal data, or have it transmitted to another data controller, where technically feasible.
- Right to Object: Object to our processing of your personal data in certain circumstances, including for direct marketing purposes.
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw consent at any time.
- Right to Lodge a Complaint: If you have concerns about our use of your data, you have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO).
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our services or legal obligations. The most current version will always be available on request or may be supplied with your order confirmation materials. We encourage you to review this policy periodically.
Contact Us
If you have any questions, concerns, or requests relating to this Privacy Policy or your personal data, please do not hesitate to contact us using the methods provided on our website or physical correspondence addresses as listed in order confirmations and invoices. We are committed to responding to your queries and addressing your concerns promptly and transparently.