This Privacy Policy outlines how Flower Delivery Hampstead ('we', 'us', or 'our') collects, uses, stores, and protects your personal data when you place orders with us. It applies to all customers making use of our flower delivery services in Hampstead and surrounding districts, in accordance with the General Data Protection Regulation (GDPR).
We collect a range of personal data necessary to provide our flower delivery services, fulfill orders, and enhance customer experience. The categories of data that we may collect include:
Under GDPR, we process your personal data only if we have a valid lawful basis for doing so. The lawful bases relevant to our flower delivery services include:
Your data is used in the following ways:
We retain your personal data only as long as necessary for the purposes for which it was collected, or as required by law. Typically, we keep order and transaction records for up to seven years to comply with financial and accounting standards. Communication and customer service records may be retained for up to three years from your last interaction with us. When data is no longer required, we securely erase or anonymize it.
In delivering our services, we use trusted third-party service providers (data processors) such as payment processors, delivery couriers, IT service providers, and website analytics firms. These data processors are contractually obliged to process your data securely and in compliance with GDPR, and may only use your data on our instructions.
We do not sell or disclose your personal data to external companies for their own marketing purposes. Where transfers outside the UK or European Economic Area (EEA) are required (for example, for IT support), we ensure appropriate safeguards are in place.
As a customer of Flower Delivery Hampstead, you have several important rights under GDPR. These include:
To exercise any of these rights, please contact us using the details provided on our website. We will respond to your request within one month, subject to verification of your identity.
We take data security seriously and have implemented appropriate organisational and technical measures to guard against unauthorised access, loss, or misuse of your personal data. These measures include secure database storage, encrypted website traffic (HTTPS), and regular staff training on data protection.
We may update this policy from time to time to reflect changes in our practices or to remain compliant with the law. We encourage you to review this policy periodically for any updates. The date of the latest revision will be stated at the top of the policy.
If you have questions or concerns regarding this Privacy Policy or the way your data is processed, please contact us using the details on our website. Should you feel that your data protection rights have not been upheld, you also have the right to lodge a complaint with the relevant supervisory authority.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
