Blackheath Flowers Privacy Policy

Introduction

This Privacy Policy sets out how Blackheath Flowers collects, uses, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). The policy applies to all customers placing orders with Blackheath Flowers within Blackheath and the surrounding districts. We are committed to protecting your privacy and being transparent about how your information is managed.

What Data We Collect

When you place an order with Blackheath Flowers, we collect the following categories of personal data:

  • Contact Information: Name, address for delivery, contact telephone number, and, where applicable, email address.
  • Order Details: Information about the products ordered, delivery instructions, occasion (e.g., birthday, anniversary), and any message included with the flowers.
  • Payment Information: We process payment details, such as card information or other payment methods, securely via our payment processor.
  • Communication Records: Correspondence you may have with us, such as queries, complaints, or feedback.
  • Technical Data: Your IP address and data about your device or browser, collected via cookies when you interact with our website, for security and analytics purposes.

Lawful Basis for Processing

Under GDPR, we must have a valid lawful basis to process your personal data. Blackheath Flowers uses your information for the following purposes and under the following lawful bases:

  • Contract: To process and deliver your orders, communicate with you about your order, and provide customer service in relation to your purchase. This is necessary for the performance of our contract with you.
  • Legal Obligation: We may use your information to comply with legal requirements, such as tax and accounting obligations.
  • Legitimate Interests: To improve our services, ensure the security of our website and customers, and keep records of transactions. We ensure these interests do not override your rights and freedoms.
  • Consent: Where you have expressly opted to receive marketing communications from us, we will process your contact information for these purposes based on your consent. You may withdraw this consent at any time.

How We Use Your Information

Blackheath Flowers uses your data to process your orders, deliver flowers, send transactional confirmations, handle queries or feedback, and, where you have consented, send you information about our products, promotions, or services. We do not use your personal data for automated decision-making or profiling.

How Long We Retain Your Data

We retain your personal data for as long as is necessary to fulfill the purposes for which it was collected, including to satisfy legal, accounting, or reporting requirements. Typically, customer order records are kept for up to seven years to comply with tax and legal obligations. Where data is held based solely on your consent (for example, for marketing purposes), we retain it until you withdraw your consent or request its deletion.

Our Data Processors

To provide our services, we may share your data with trusted third-party service providers (data processors). These include:

  • Payment Processors: To securely process your payments, we use third-party payment gateways.
  • Delivery Partners: For efficient order delivery, select information such as your recipient's name, delivery address, and contact number may be shared with our courier or delivery staff.
  • IT and Hosting Providers: Our website, order system, and communication channels may be hosted or maintained by external IT providers to ensure the smooth functioning of our services.
  • Professional Advisors: Accountants, legal advisors, or auditors where necessary for our compliance and business operations.

All partners and providers are required to act only on our instructions and to implement adequate security measures to protect your data. Data processors are prohibited from using your information for their own purposes.

Security of Your Data

We take the security of your personal information seriously. Appropriate technical and organisational measures are implemented to protect your data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access. Your payment details are processed securely using encrypted technology and are never stored by us in plain text.

Your Rights

Under the GDPR, you have rights regarding your personal data that Blackheath Flowers holds and processes. These rights include:

  • Right to Access: You can request a copy of the personal data we hold about you.
  • Right to Rectification: You may ask us to correct or update inaccurate or incomplete data.
  • Right to Erasure ("Right to be Forgotten"): In certain circumstances, you may request deletion of your data.
  • Right to Restrict Processing: You can request we restrict how we process your personal data in certain cases.
  • Right to Data Portability: You have the right to obtain your data in a commonly used format and to transfer it to another provider.
  • Right to Object: You may object to us processing your personal information for particular purposes, such as direct marketing.
  • Right to Withdraw Consent: Where processing is based on your consent, you can withdraw this at any time.
  • Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you are unhappy with how we have handled your data.

International Transfers

Your personal data is primarily processed within the United Kingdom; if there is any need to transfer your information outside the UK or the European Economic Area, we ensure appropriate safeguards are in place as required under GDPR.

Policy Updates

We may occasionally update this Privacy Policy to reflect changes in the law or our practices. We encourage you to review this policy periodically. Significant changes will be communicated where appropriate.

Contact Us

If you have any questions about this Privacy Policy or would like to exercise your data protection rights, please contact us via our usual customer service channels. We will be glad to assist you with any queries regarding your personal data at Blackheath Flowers.