Flowers Gants Hill Privacy Policy
Introduction
This Privacy Policy outlines how Flowers Gants Hill collects, processes, and protects your personal data in accordance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Flowers Gants Hill, whether from Gants Hill or the surrounding districts. We are committed to maintaining your trust and protecting your privacy at all stages of your interaction with us.
What Personal Data We Collect
Flowers Gants Hill collects the following categories of personal data from customers in the course of our business:
- Identity Information: Your name and, if applicable, recipient's name.
- Contact Information: Your address, delivery address, and postcodes; and in some cases, contact phone number.
- Order Details: Specific requests, messages, or instructions, as well as details of floral products and arrangements purchased.
- Payment Information: Payment methods, transaction details, and limited information required to process your payment securely (we do not store full debit or credit card information).
- Correspondence: Any communications you send to us, including feedback, queries, or complaints.
- Technical Information: When applicable, anonymised data such as IP address, browser type, and device information used for website optimization and security.
Lawful Basis for Processing Your Personal Data
Under the GDPR, we are required to ensure that all personal data processing is supported by a lawful basis. Flowers Gants Hill processes your personal data under the following lawful grounds:
- Contractual Necessity: We process personal data to fulfil our contract with you—specifically, to process, deliver, and manage your flower orders.
- Legal Obligations: We may collect and retain certain records as required by law, such as financial transactions for tax or accounting purposes.
- Legitimate Interests: We may use your information to improve our services, manage customer relationships, or protect our business from fraud—carefully balancing our interests with your rights and freedoms.
- Consent: Where required—for example, if we wish to send you marketing communications unrelated to your order—we will seek and record your explicit consent. You are free to withdraw consent at any time.
How We Use Your Personal Data
Your personal data is used for the following purposes:
- Processing and delivering your order to the correct address or recipient.
- Managing your customer account and responding to queries or requests.
- Managing payments and processing refunds where applicable.
- Complying with applicable legal, tax, and regulatory obligations.
- Improving the quality and relevance of our floral products and customer service.
- Providing tailored customer support when needed.
Data Retention
We only retain your personal data for as long as necessary to fulfil the aforementioned purposes, including satisfying any legal, accounting, or reporting requirements. Specifically:
- Order and delivery information is retained for up to seven years to comply with tax and accounting regulations.
- Customer correspondence is typically held for two years after your last interaction with us, unless further retention is required for dispute resolution or legal purposes.
- Where personal data has been processed based on consent (for example, for marketing preferences), we will retain this information until you withdraw your consent, but no longer than five years from your last communication with us.
After these periods, information is deleted or anonymised unless we are required to retain it for legitimate legal reasons.
Data Processors and Transfers
Flowers Gants Hill may employ third-party service providers (processors) to deliver certain services, such as:
- Payment processing companies to handle secure financial transactions.
- Delivery partners to ensure accurate and timely flower delivery in Gants Hill and the surrounding districts.
- IT service and hosting providers that enable our website and manage customer data with adequate security measures.
All external processors utilised by Flowers Gants Hill are contractually required to comply with GDPR and are only permitted to use your data as necessary to provide the contracted services. We do not transfer your data outside the UK or European Economic Area (EEA) unless adequate safeguards are in place, such as Standard Contractual Clauses approved by the UK or EU authorities.
Your Rights Under GDPR
Under the GDPR, you have a range of rights concerning your personal data held by Flowers Gants Hill:
- The right to be informed: To know how and why we collect and use your data (as set out in this policy).
- The right of access: To request a copy of the personal data we hold about you.
- The right to rectification: To have inaccuracies in your personal data corrected.
- The right to erasure: To request the deletion of your personal data when it is no longer necessary for the purposes collected.
- The right to restrict processing: To request that we limit the use of your data in certain circumstances.
- The right to data portability: To receive your data in a commonly used, machine-readable format and request it to be transferred to another service provider.
- The right to object: To object to certain types of processing, such as direct marketing.
- Rights related to automated decision making: Flowers Gants Hill does not use automated decision-making or profiling.
To exercise any of these rights, please contact us using the details provided on our website or in-store. We take your privacy rights seriously and aim to respond to your requests promptly, normally within one month.
Security and Data Protection
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, misuse, loss, or disclosure. These measures include secure payment gateways, data encryption, regular system updates, staff training, and restricted access to customer records.
Updates to This Privacy Policy
This policy is reviewed regularly and updated to reflect changes in legal obligations and our data processing practices. Significant changes will be communicated through our website or, where appropriate, by direct notification. Please review this policy periodically for the latest information on our privacy practices.
Contact and Further Information
If you have any questions or concerns about how your personal data is handled, require further information about our data protection practices, or wish to exercise your rights under GDPR, you can contact us through the methods provided on our website or visit our shop in person. We are dedicated to responding to your queries and ensuring that your privacy is respected at all times.