Privacy Policy for Canary Wharf Flowers Orders
Introduction
This Privacy Policy outlines how Canary Wharf Flowers collects, uses, retains, and safeguards your personal information in accordance with the General Data Protection Regulation (GDPR) and applicable data protection laws. This policy applies to all customers placing orders with Canary Wharf Flowers in Canary Wharf and surrounding districts.
Information We Collect
When you place an order with Canary Wharf Flowers or interact with our services, we may collect the following categories of personal data:
- Identity Data: First and last name.
- Contact Data: Billing and delivery addresses, phone number (if provided), and other relevant information necessary to fulfill your order.
- Order Data: Details of the floral products you purchase, order preferences, and delivery instructions.
- Payment Data: Transaction details (processed securely by payment processors; we do not store credit/debit card data).
- Communication Data: Records of communications with you regarding your orders or enquiries.
We do not intentionally collect special category (sensitive) data such as health, ethnicity, or political opinions.
Lawful Basis for Processing Your Data
In compliance with GDPR, we only process your data where there is a lawful basis:
- Contractual Necessity: Processing your personal data is required to fulfill our contract with you (for example, to deliver your order).
- Legitimate Interests: We may use your data in ways necessary for our legitimate business interests, provided these interests are not overridden by your rights and interests.
- Legal Obligations: We may process your data to comply with laws and regulations.
- Consent: If required, we will seek your explicit consent before processing when no other legal basis applies (for example, for direct marketing).
How We Use Your Personal Data
Your personal data is used for the following purposes:
- Processing and fulfilling your flower orders, including arranging delivery.
- Communicating with you about your order status, updates, or any issues.
- Improving our products and services based on customer feedback and preferences.
- Complying with legal obligations, such as tax records or responding to legal requests.
Third-Party Processors
To provide our services, we may share your personal data with trusted third-party processors, strictly for necessary business operations or legal requirements. These include:
- Payment Service Providers: For secure payment transaction processing. Payment providers process your card details directly; we do not retain or access your full payment information.
- Delivery Partners and Couriers: For order delivery within Canary Wharf and surrounding districts.
- IT and Hosting Services: For website hosting, secure data storage, and technical support.
All processors operate under a data processing agreement, are GDPR-compliant, and act only under our instructions.
Data Retention
We only retain your personal data for as long as is necessary for the purposes for which it was collected. In general, this means:
- Order and transaction records are stored for up to seven years to comply with legal and accounting requirements.
- Communication records and contact details are retained for up to two years after order fulfillment, unless you request erasure sooner, or unless retention is required by law.
Once your data is no longer required, it will be securely deleted or anonymised.
Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data held by Canary Wharf Flowers:
- Right of Access: You can request a copy of your personal data that we hold.
- Right to Rectification: You can request correction of inaccurate or incomplete data.
- Right to Erasure: You can request deletion of your data, subject to certain conditions.
- Right to Restrict Processing: You can request restriction of processing in certain circumstances.
- Right to Data Portability: You can request your data in a machine-readable format, or ask us to transfer it to another service provider where applicable.
- Right to Object: You have the right to object to certain types of data processing, including direct marketing.
- Right to Withdraw Consent: If processing is based on consent, you can withdraw that consent at any time without affecting the lawfulness of processing before withdrawal.
To exercise your rights, please contact us via our website or through the usual customer service channels. We may need to verify your identity before responding to your request, for your security.
Data Security
Your privacy is important to us. We implement appropriate technical and organisational measures to protect your personal information against unauthorised access, loss, destruction, or disclosure. These may include using secure encrypted connections, strict access controls, and regular data security reviews.
International Transfers
Your personal data is primarily stored and processed within the UK and the European Economic Area (EEA). In the event that any personal data is processed outside the EEA, such processing will occur only where adequate protections are in place, as required by GDPR.
Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or the law. Updates are effective once posted on our website. We recommend you review this policy periodically for any changes.
Contact Details
If you have any questions or concerns about this Privacy Policy or your personal data, please contact our customer support team through the methods provided on our website. We are committed to promptly addressing any queries or concerns you may have regarding your privacy and data protection.