Flowers Hoddesdon GDPR Privacy Policy
Introduction
This Privacy Policy sets out how Flowers Hoddesdon ('we', 'us', 'our') collects, uses, stores, and protects personal information of customers placing orders from Hoddesdon and the surrounding districts. Flowers Hoddesdon is firmly committed to ensuring your privacy and handling your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable UK data protection laws. By using our services, you agree to the terms outlined in this policy.
Scope of this Privacy Policy
This Privacy Policy applies to all customers who place orders with Flowers Hoddesdon, whether via telephone, our website, or in-person, covering deliveries to Hoddesdon and neighbouring districts. It explains how we handle your personal data within these contexts and your rights regarding your personal information.
What Personal Data We Collect
In order to fulfill your flower order and provide our services, we may collect and process the following categories of personal data:
- Identification Information: Name and title
- Contact Details: Delivery address, billing address, telephone number(s)
- Order Information: Details of products ordered, recipient details (where you order flowers for others), specific delivery instructions
- Payment Information: Transaction details (processed by payment partners; we do not store card details)
- Correspondence: Records of queries, feedback, or complaints
- Technical Data (when using our website): IP address, time and date of access, device and browser information, cookies preferences
Lawful Basis for Processing Your Data
Flowers Hoddesdon collects and processes your personal data only when permitted by law. Our legal grounds include:
- Contractual Necessity: Processing your information to enter into and fulfill our contract to deliver flowers and related goods or services to you or the delivery recipient
- Legitimate Interests: Using minimal information to optimize service delivery, respond to customer queries, prevent fraud, and maintain business operations, provided this does not infringe on your rights
- Legal Obligation: Where required to retain or disclose data to comply with applicable laws and regulations (e.g., accounting, tax records, or regulatory requests)
- Consent: With your explicit consent, for specific purposes such as email marketing (you may withdraw your consent at any time)
How We Use Your Data
We use your personal data only for the purposes it was collected. This includes:
- Processing and delivering your flower orders
- Confirming orders and contacting you about your order status
- Managing payments and preventing fraudulent transactions
- Responding to queries, complaints, or service requests
- Improving our products and customer experience
- Complying with legal and regulatory obligations
Retention of Your Data
We retain your personal data only as long as necessary for the stated purposes. The length of time depends on factors such as the nature of the order, our ongoing relationship, legal requirements, and our legitimate business interests. In general:
- Order and delivery data is retained for up to six years to comply with legal and accounting obligations
- Marketing data is retained until you withdraw consent or object to processing
- Records of queries and correspondence may be held for up to two years for customer service purposes
After this period, your data will be securely deleted or anonymized.
Processors and Third Parties
To deliver our services efficiently and securely, we sometimes engage third-party processors. These include:
- Payment Processors: Third parties who securely handle payment transactions on our behalf (we do not store payment card details)
- Delivery Partners: Trusted couriers and delivery services who may receive delivery addresses and contact information to fulfill your order
- IT Service Providers: Companies who host our website, maintain IT systems, and provide software tools necessary for our business operations
- Professional Advisors: Accountants, auditors, or legal advisors where required by law or business need
We require all third-party service providers to respect the security of your personal data and to treat it in accordance with the law. Processors act only on our instructions and are subject to contractual confidentiality obligations.
Security of Your Data
We implement appropriate organizational and technical measures to safeguard your personal data. This includes secure storage, restricted access, regular staff training, and use of encryption technologies where appropriate to minimize the risk of unauthorized access, alteration, or loss.
Your Rights under GDPR
Under the GDPR, you have rights over your personal data. These include:
- Right to Access: Obtain a copy of your personal data held by us
- Right to Rectification: Request corrections to any inaccurate or incomplete data
- Right to Erasure: Request deletion of your data where there is no lawful basis for its retention
- Right to Restriction: Ask us to limit processing of your data under certain circumstances
- Right to Data Portability: Obtain a copy of your data in a structured, commonly used format for transfer elsewhere
- Right to Object: Object to processing where we rely on legitimate interests; object to direct marketing at any time
- Right to Withdraw Consent: Where processing is based on your consent, you may withdraw it at any time
If you wish to exercise any of these rights, or have questions about how we process your data, please contact us using the details on our website or provided at the time of your order.
Updates to this Privacy Policy
We may periodically review and update this Privacy Policy to reflect changes to our practices, operational requirements, or legal obligations. When changes are made, we will publish the updated policy and note the date of the revision. We encourage you to review this statement regularly to stay informed about how we protect your data.
Contact and Complaints
If you have concerns about our data practices, or believe your data rights have been infringed, you have the right to lodge a complaint with the Information Commissioner's Office, the UK data protection regulator. Please contact us first so we can address your concerns directly.
This policy was last updated on [Insert policy date].