Flower Delivery Leatherhead Privacy Policy
  Privacy Policy for Flower Delivery Leatherhead Customers
This Privacy Policy explains how Flower Delivery Leatherhead ('we', 'us', 'our') collects, processes, and protects your personal information when you place a flower delivery order with us. This policy applies to all customers who order our services from Leatherhead and surrounding districts. We prioritise your privacy and are committed to complying fully with the UK Data Protection Act 2018 and the EU General Data Protection Regulation (GDPR).
1. What Data We Collect
To fulfil your flower delivery order and provide a smooth customer experience, we may collect and process the following types of personal data:
  - Identity Data: Your full name, and in some cases, the recipient’s name.
- Contact Data: Address for delivery, billing address, and phone number of recipient (if provided by you) and your own contact details as the ordering customer.
- Order Details: Products ordered, special instructions, order tracking information, and any correspondence relating to your order.
- Payment Data: Payment card information and transaction history (please note that payment card data is processed securely via our payment processor and not stored by us).
- Technical Data: IP address, browser type, device information, and access times, which may be collected when you use our website.
We do not actively collect or process sensitive personal data unless explicitly required for the performance of your contract with us and you have provided consent.
2. Lawful Basis for Data Processing
Under GDPR, we are required to have a lawful basis for processing your personal data. The main legal bases we rely on are:
  - Contractual Necessity: Most data is collected and processed so we can fulfil your flower delivery order, take payment, and provide customer support as needed. Without this information, we could not deliver your order.
- Legitimate Interests: We may process your data for our legitimate interests, such as improving our services, fraud prevention, or handling any customer queries, provided your rights and freedoms do not override these interests.
- Legal Obligation: To comply with applicable laws and regulatory requirements (for example, keeping transaction records for tax purposes).
- Consent: Where required (such as for direct marketing by email or SMS), we will always seek your explicit consent, which you can withdraw at any time.
3. How We Use Your Information
We use your information for the following purposes:
  - To process and fulfil your orders, including payment collection and delivery to the specified recipient.
- To communicate with you about your orders or to inform you of any changes or issues.
- To improve our website, services, and customer experience.
- To comply with our legal obligations (such as record keeping for HMRC or other authorities).
- If you have opted in, to send you updates or marketing communications about our services.
4. Data Retention
We only retain your personal information for as long as is necessary to fulfil the purposes for which it was collected, including to meet legal, accounting, or reporting requirements. Usually, order data is retained for up to six years to comply with required accounting practices. Where consent has been given for marketing, we retain your contact information until you opt out or withdraw consent.
5. Sharing Your Data and Data Processors
We do not sell or rent your personal data to third parties. However, your personal data may be shared with trusted third-party service providers (data processors) who perform services on our behalf, such as:
  - Payment processing companies (to securely manage your payment transactions). Your full card details are never stored on our systems.
- Delivery partners or couriers (to deliver your flower order to the recipient).
- IT support and hosting providers (to operate our website and store data securely).
- Email service providers (to communicate order confirmations or updates).
These processors are only permitted to use your personal information as necessary to provide their services on our behalf and are required to maintain its confidentiality.
If required by law, we may disclose your data to authorities or regulators.
6. Data Security
We implement appropriate organisational and technical measures to safeguard your personal data against unauthorised access, alteration, disclosure, or destruction. Access to your data is limited to authorised personnel and trusted service providers only. Where possible, all information is encrypted in transit and at rest.
7. International Transfers
Your data is primarily stored and processed within the United Kingdom. If any of our third-party processors transfer your personal information outside the UK or European Economic Area (EEA), we ensure that adequate safeguards are in place, such as standard contractual clauses or other approved mechanisms, in line with data protection law requirements.
8. Your Rights Under GDPR
You have various rights under the GDPR with respect to your personal data, including:
  - Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You can ask us to correct inaccurate or incomplete data.
- Right to Erasure: You can ask us to delete your data in certain circumstances (the 'right to be forgotten').
- Right to Restrict Processing: You can ask us to restrict the processing of your data in specific situations.
- Right to Data Portability: You can request that we provide your data in a structured, commonly used, machine-readable format and transfer it to another controller.
- Right to Object: You can object to the processing of your data for direct marketing or where we process on grounds of legitimate interest.
- Right to Withdraw Consent: Where processing is based on consent, you may withdraw this at any time.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe we are not complying with data protection laws.
If you wish to exercise any of these rights, please contact us using the methods provided on our website.
9. Updates to This Privacy Policy
We may update this policy occasionally to reflect changes in our practices or legal requirements. Significant changes will be communicated on our website. Please review this policy periodically to stay informed about how we protect your privacy.
10. Contact Us
If you have any questions or concerns regarding this Privacy Policy or our handling of your personal data, please get in touch with us using the contact details available on our website. We are committed to addressing your inquiries promptly and thoroughly.
This policy is effective as of 13 June 2024.