Flower Delivery Deptford Privacy Policy
  Overview
This Privacy Policy explains how Flower Delivery Deptford ('we', 'us', 'our') collects, uses, retains, and protects the personal data of customers ('you', 'your') who place orders for flower deliveries in Deptford and the surrounding districts. We are dedicated to handling your personal information responsibly, transparently, and in accordance with the requirements of the General Data Protection Regulation (GDPR).
Scope of This Policy
This Privacy Policy applies to all customers who order flower deliveries from us, whether directly via our website, by telephone, or through other ordering platforms serving Deptford and neighbouring districts. By using our services, you acknowledge and consent to the practices described in this policy.
What Personal Data We Collect
We collect only the data necessary to fulfil your flower delivery orders and improve your experience. The categories of personal data we collect may include:
  - Contact details: Name, address, email address, and telephone number.
- Order information: Delivery address, order details, special instructions.
- Payment details: Payment method and transaction information (note: we do not store full card details; secure payment processors manage these).
- Communications: Any correspondence or feedback you provide to us relating to your order or our services.
- Technical information: IP address, browser type, and device information, collected automatically when you use our website for security and analytics purposes.
Lawful Basis for Processing Your Data
We process your personal data in accordance with the GDPR's lawful bases, including:
  - Contractual necessity: We need your personal data to fulfil your flower delivery order, process payments, and provide customer service.
- Legitimate interests: For quality assurance, analytics, business improvement, fraud prevention, and to ensure reliable delivery of our services. Our legitimate interests do not override your fundamental rights and interests.
- Legal compliance: Where necessary to comply with legal obligations such as tax or financial record-keeping.
- Consent: Where we require your permission to process data, for example, for direct marketing communications. You can withdraw your consent at any time.
How We Use Your Personal Data
We use your personal information for purposes including but not limited to:
  - Processing and delivering your flower orders.
- Processing payments and managing invoices.
- Communicating with you about your order, delivery timing, or service updates.
- Handling customer service requests and resolving issues.
- Improving our products, website, and services through internal analysis.
- Complying with our legal duties as a business.
Data Retention
We keep your personal data only for as long as necessary to fulfil the purposes for which it was collected, including satisfying any legal, regulatory, accounting, or reporting requirements. Typically, we retain:
  - Order and transaction records for up to seven years in line with tax and accounting obligations.
- Customer communications and service records for up to three years.
- Data held with your consent (such as for marketing) until you withdraw your consent or request erasure.
Once data is no longer needed, we either delete it securely or anonymise it from our systems.
Processors and Data Sharing
We do not sell or rent your personal data. To deliver our services, we may share your data with selected third parties ('processors') who act on our behalf, including:
  - Payment processing providers to handle secure card payments.
- Delivery couriers for making timely and accurate deliveries.
- IT service providers supporting our website, database, and communication systems.
- Professional advisors (such as accountants, auditors) for compliance and business governance.
All our processors are required to comply with GDPR, process your data only as instructed, and ensure its security. We ensure any data transferred outside the UK or EEA is protected under recognised data protection frameworks.
Your Rights Under GDPR
You have a range of rights under the GDPR regarding your personal information, which includes:
  - Right of access: You can request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct or complete inaccurate or incomplete data.
- Right to erasure: Also known as the ‘right to be forgotten’, you may ask us to delete your data in certain circumstances.
- Right to restrict processing: You can ask us to limit how we use your data.
- Right to object: You can object to our processing of your data for certain purposes, such as direct marketing.
- Right to data portability: Where applicable, you can request a copy of your data in a structured, commonly used, and machine-readable format.
- Right to withdraw consent: If processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
- Right to lodge a complaint: You have the right to complain to the relevant supervisory authority if you believe we are mishandling your data.
If you wish to exercise any of your rights, you may contact us using the methods set out on our website or sales documentation. Please provide sufficient information for us to verify your identity before processing your request.
Security of Your Data
We have implemented appropriate physical, technical, and organisational measures to protect your personal data against accidental, unlawful, or unauthorised loss, destruction, alteration, disclosure, or access. Our website operates using secure HTTPS protocols, and we train our staff on data protection and privacy principles.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time in response to changes in regulations, technology, or our business operations. If we make substantial changes, we will notify customers via our website or, where appropriate, by other means. We encourage you to review this policy periodically to stay informed about how we protect your privacy.
Contact Us
If you have any questions, concerns, or requests regarding your personal information or this Privacy Policy, please refer to our contact methods as outlined on our website or in your order confirmation materials. We are committed to maintaining your trust and will respond to your queries as promptly as possible.