Your Privacy and Personal Data at Flowers North Kensington
  Introduction
This Privacy Policy explains how Flowers North Kensington collects, uses, and protects your personal information in accordance with the UK General Data Protection Regulation (GDPR). This policy applies to all customers who place orders with Flowers North Kensington from North Kensington and the surrounding districts. We are fully committed to safeguarding your privacy and ensuring transparency over the way your data is handled.
Personal Data We Collect
To process and deliver your flower orders, we may collect the following categories of personal data:
- Identity Data: Your full name and, if relevant, your recipient’s name.
- Contact Data: Billing and delivery addresses, telephone numbers, and limited postal information.
- Order Details: Information about the products you purchase, instructions related to your order, and preferences you provide.
- Payment Data: Payment confirmation data (such as transaction IDs). Please note: we do not store your credit or debit card information. All payment processing is securely managed by third-party processors.
- Correspondence: Records of communications, including messages related to enquiries, complaints, or after-sales support.
- Technical Data: Basic information automatically collected about your device, browser type, and usage patterns when you visit our website. This helps us improve our services but does not directly identify you.
Lawful Basis for Processing
Flowers North Kensington relies on several lawful grounds to process your personal data, as set out below:
- Performance of a Contract: Most of the data we collect is necessary to fulfil your flower order or respond to your requests.
- Legal Obligations: We may process certain data to comply with statutory obligations, such as tax and accounting requirements.
- Legitimate Interests: In some cases, we may process your data to pursue our legitimate interests, provided these do not infringe your rights (e.g., improve our offerings or prevent fraud).
- Consent: Where required (such as for direct marketing if used), we will seek your explicit consent and you may withdraw it at any time.
How We Use Your Information
Your information is only used for the purposes specified in this privacy policy, including:
- Processing and delivering your orders efficiently and accurately.
- Managing your customer relationship, including communications regarding your order status and delivery.
- Handling customer service enquiries, complaints, or feedback.
- Meeting our record-keeping, legal, and regulatory requirements.
- Improving our website and service experience through analysis of aggregated usage patterns.
Data Retention
We only retain your personal data for as long as necessary to fulfil the purposes for which it was collected and to meet any regulatory, legal, or accounting requirements. Typically, this means we keep personal data related to orders for up to seven years, in accordance with HMRC and financial record-keeping requirements. At the end of the retention period, your personal data will be securely deleted or anonymised.
Third-Party Processors
To deliver our services, we sometimes need to share your data with trusted third parties who act as data processors on our behalf. These include:
- Payment Service Providers: Securely process payment transactions.
- Delivery and Courier Partners: Receive necessary contact and delivery details to ensure successful fulfilment of your order.
- IT and Cloud Service Providers: Assist us with hosting, storage, and essential technical support to maintain website functionality.
All data processors are required to protect your information in compliance with GDPR and may not use your data for their own purposes. We do not sell, trade, or otherwise transfer your personally identifiable information to outside parties for marketing or unrelated activities.
Security of Your Data
We take your privacy seriously and implement appropriate security measures to protect your personal data from accidental loss, unauthorised access, alteration, or disclosure. Access to your data is restricted to staff and trusted partners who strictly require it to perform their roles.
Your Rights Under GDPR
Under data protection law, you have a number of rights in relation to your personal data:
- Right of Access: You can request a copy of the personal data we hold about you at any time.
- Right to Rectification: If your data is inaccurate or incomplete, you are entitled to have it corrected.
- Right to Erasure: You have the right to request deletion of your data in certain circumstances, such as when the data is no longer needed.
- Right to Restrict Processing: You can ask us to suspend processing of your personal data when you contest its accuracy or the reason for processing it.
- Right to Data Portability: You may request the transfer of your data to you or a third party in a commonly used electronic format.
- Right to Object: Where we process your data based on legitimate interest or direct marketing, you have the right to object to this processing.
- Right to Withdraw Consent: Where you have provided consent for a particular use of your data, you may withdraw it at any time.
Policy Scope and Changes
This Privacy Policy applies to all customers placing orders with Flowers North Kensington in North Kensington and nearby districts. We may revise this policy from time to time to reflect changes in law, technology, or business operations. Please check this page periodically for the latest updates. Continued use of our services will signify your acceptance of any changes.
Contact and Complaints
If you have any questions regarding this policy or how your data is handled, or if you wish to exercise any of your rights, please contact us through the usual customer service channels. If you are not satisfied with our response, you also have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection.
Flowers North Kensington thanks you for your trust and assures you of our ongoing commitment to upholding your privacy and data protection rights.