Flowers Hackney Marshes Privacy Policy

Privacy Policy Overview

This Privacy Policy explains how Flowers Hackney Marshes (“we”, “us”, “our”) collects, uses, stores, and protects your personal data when you place an order with us. This policy applies to all customers ordering flowers from us for delivery or collection within Hackney Marshes and the surrounding districts. We are committed to upholding your privacy and handling your personal data transparently and in compliance with the General Data Protection Regulation (GDPR).

1. What Data We Collect

When you place an order with Flowers Hackney Marshes, we may collect the following types of personal data:

  • Identity Information: Name and, if provided, company name
  • Contact Details: Delivery address, billing address, phone number, and (if applicable) email address
  • Order Details: Products ordered, occasion or special requests, delivery date and timing
  • Payment Information: Payment method and confirmation (Note: Payment details such as card numbers are processed securely via our payment provider and are not stored by us)
  • Correspondence: Any communication with us, including queries or feedback related to your order

We do not collect more personal data than is necessary for the purposes set out in this policy.

2. Lawful Basis for Processing

We process your personal data under the following lawful bases as defined by GDPR:

  • Contractual Necessity: For processing and fulfilling your orders, including delivery or collection, payment processing, and handling order-related communications
  • Legal Obligation: To comply with applicable laws, such as keeping records for tax and accounting purposes
  • Legitimate Interests: For improving our services, responding to inquiries, and tailoring offerings to better serve our customers. Where we rely on legitimate interests, we ensure these do not override your rights and interests
  • Consent: We may rely on consent in limited circumstances, such as when you opt in to receive marketing communications. You may withdraw your consent at any time

3. Data Retention

We retain your personal data only as long as necessary for the purposes for which it was collected and to comply with applicable legal, regulatory, or accounting requirements. Generally, customer order data is retained for up to 6 years from the date of your last order to comply with UK tax and bookkeeping laws. Data used for direct marketing purposes (with your express consent) is retained only until you withdraw your consent or request erasure.

Once your data is no longer required, it is securely deleted or anonymised.

4. Data Processors

To deliver our services, we may share necessary personal data with trusted third-party service providers (data processors), who process data on our behalf and strictly under our instructions. These processors include:

  • Payment Processing Providers: To handle secure online payments
  • Delivery Services: For arranging delivery of orders
  • IT and Systems Providers: For hosting our website and managing order systems

All processors are carefully selected to ensure they provide adequate protection of your data and comply with GDPR requirements. We do not sell or share your personal information with third parties for their own marketing purposes.

5. Security of Your Data

We take appropriate technical and organisational measures to protect your personal data against unauthorised or unlawful processing, accidental loss, destruction, or damage. Access to personal data is restricted to employees and service providers on a need-to-know basis and who are bound by confidentiality agreements.

6. Your Rights Under GDPR

Under GDPR, you have specific rights concerning the processing of your personal data. These include:

  • Right of Access: You can request a copy of the personal data we hold about you
  • Right to Rectification: You can request corrections to any incomplete or inaccurate data
  • Right to Erasure: You can request deletion of your data, except where we are required to retain it by law
  • Right to Restrict Processing: You may request us to limit certain types of processing
  • Right to Data Portability: You can request us to provide your data in a commonly used format to transfer to another provider
  • Right to Object: You can object to processing based on legitimate interests or for direct marketing purposes

To exercise your rights, please contact us by your chosen method (for example, by post or via our website form). We will respond to all requests as required by law and may request proof of identity to protect your privacy and security.

7. Policy Applicability and Changes

This privacy policy applies to all customers placing orders with Flowers Hackney Marshes for deliveries and collections within Hackney Marshes and the surrounding districts. We may update this policy from time to time to reflect changes to our practices or for legal reasons. Updates will be published on our website, and where appropriate, we will notify you directly.

8. Questions or Concerns

If you have any questions about this privacy policy, our data handling practices, or wish to make a complaint, please reach out to us using the contact methods published on our website. You also have the right to lodge a complaint with the UK Information Commissioner’s Office if you believe your rights have been violated.

Thank you for trusting Flowers Hackney Marshes with your personal data. We are committed to honoring that trust through responsible and transparent data practices.