Privacy Policy for Bayswater Flowers Customers

Introduction

This Privacy Policy explains how Bayswater Flowers collects, uses, and protects your personal information when you place flower orders with us. Our policy is crafted in compliance with the UK General Data Protection Regulation (GDPR) and applies to all customers ordering from Bayswater and surrounding districts. We are committed to handling your personal data with care, transparency, and respect for your privacy rights.

What Data We Collect

When you place an order with Bayswater Flowers, we may collect and process the following categories of personal data:

  • Identity Information: Your full name and, where applicable, the recipient's name.
  • Contact Information: Addresses for delivery and billing, phone number, and occasionally other contact details necessary for order fulfillment.
  • Order Details: Information about products ordered, messages for recipients, delivery notes, and special instructions.
  • Payment Information: Payment method, transaction references, and amounts (note: card details are processed securely and not stored by us).
  • Correspondence: Communications related to your order, such as email or written communication, queries, and feedback.
  • Technical and Usage Data: Basic device, browser, and site usage data when you interact with our website, such as IP address, browser type, and time of visit. This may include cookies and analytics data for website administration purposes.

Lawful Basis for Processing

Our processing of your personal information is based on one or more of the following lawful grounds:

  • Contractual Necessity: We require certain information to process, confirm, and deliver your flower orders as part of our contractual arrangements with you.
  • Legal Obligations: Some data are retained and processed to comply with legal and financial duties (e.g., for accounting or tax records).
  • Legitimate Interests: We may process limited data to improve and develop our services, ensure the security of our systems, and respond to your inquiries, where this does not override your rights.
  • Consent: Where necessary, we request your consent – for example, for specific marketing or promotional communications. Consent can be withdrawn at any time.

Data Retention

Your personal data is retained only as long as needed for the purposes for which it was collected, including for the fulfillment of your order, legal obligations, dispute resolution, and enforcement of agreements. Retention periods may vary:

  • Order Details and Contact Information: Typically retained for up to 7 years from the last transaction to satisfy legal, accounting, or reporting requirements.
  • Marketing and Communications Data: Kept until you withdraw your consent, unsubscribe, or request deletion.
  • Technical Data: Analytics and cookies data are retained per our internal policies, typically not exceeding 26 months unless needed to investigate issues or fulfill legal requirements.

After these periods, personal data is securely erased or anonymised.

Data Processors and Sharing

To provide our services efficiently and securely, we may share information with selected third-party service providers acting as data processors, under appropriate contractual safeguards as required by the GDPR. These include:

  • Payment Processors: Secure facilities process your payments; card data is never stored by us directly.
  • Delivery Partners: Couriers and delivery services receive delivery-related data to ensure flowers reach the intended recipient.
  • IT and Web Hosting Providers: Providers that host our website, support our email, and store data securely.
  • Professional Advisors: Accountants, insurers, or legal advisers, where necessary for compliance or to protect our business and your interests.

We do not sell or rent your personal information to any third parties. Data processors are vetted to maintain data security and confidentiality, and they may only process data on our instructions. In limited circumstances, we may share data if required by law or for legal proceedings.

User Rights under the GDPR

As a customer of Bayswater Flowers, you have a range of rights concerning your personal data:

  • Right of Access: You can request a copy of the personal information we hold about you.
  • Right to Rectification: You can ask us to correct or update any inaccurate or incomplete data.
  • Right to Erasure: Under certain circumstances, you may ask for your personal data to be deleted (also known as the ‘right to be forgotten’).
  • Right to Restrict Processing: You can ask us to restrict how your data is processed in some cases.
  • Right to Data Portability: Where we process data by automated means based on consent or contract, you can request your data in a machine-readable format.
  • Right to Object: You may object to processing based on legitimate interests or direct marketing.
  • Right to Withdraw Consent: Where processing is based on your consent, you may withdraw that consent at any time.

To exercise your rights, please contact us through the communication channels provided on our website. We may require confirmation of your identity prior to handling your request, and we aim to respond promptly, typically within one month.

Security of Your Data

We take appropriate technical and organisational measures to safeguard your personal information against unauthorised or unlawful access, alteration, disclosure, or destruction. These include secure hosting, encrypted connections, access controls, and staff training in data protection best practices. Nevertheless, no online system can be guaranteed 100% secure, so we encourage you to take your own precautions, such as safeguarding your payment details and using secure networks when placing orders.

Changes to This Policy

We review and may update our Privacy Policy from time to time in response to changes in law, technology, or our business practices. Any significant changes will be clearly indicated, and continued use of our services after such changes constitutes your acceptance of the revised Policy.

Contact and Complaints

For questions, requests relating to your personal data, or if you have concerns regarding this Policy, please refer to the contact details on our website. If you are dissatisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office or your local data protection authority.

This Policy is effective from the date of your interaction with Bayswater Flowers and applies to all orders placed by customers in Bayswater and surrounding districts.