Privacy Policy for Flower Delivery Brunswick Park Orders
GDPR-Compliant Privacy Policy
This Privacy Policy outlines how Flower Delivery Brunswick Park collects, uses, protects, and retains your personal information. The policy applies to all customers who place flower delivery orders with us from Brunswick Park and surrounding districts. Your privacy and the secure handling of your data are very important to us. We handle your personal information according to the principles set out in the General Data Protection Regulation (GDPR).
What Data We Collect
When you place an order with Flower Delivery Brunswick Park, we may collect, process, and store the following data:
- Identification and Contact Data: Including your full name, billing and delivery addresses, phone number, and (if provided) any other means of contact.
- Order Information: Details regarding the flowers or products you purchase, delivery instructions, gift card messages, and order history.
- Payment Information: Partial payment data provided to us by payment processors (never full card details), billing information, and transaction identifiers.
- Communication Records: Records of correspondence with our customer service, including inquiries, complaints, or feedback.
- Website Usage Data: Data generated by your use of our website, such as browser information, device type, duration of visit, and navigation paths, collected through cookies and analytics tools.
Lawful Basis for Processing Personal Data
GDPR requires a valid legal basis for processing your personal information. Flower Delivery Brunswick Park relies on the following lawful bases:
- Contractual Necessity: We process your data to fulfill your order, deliver products, and provide customer support as required to complete our contract with you.
- Legal Obligations: We process personal information as necessary to comply with laws and regulations, such as tax or accounting requirements.
- Legitimate Interests: We process certain information for our legitimate business purposes, such as improving our services, preventing fraud, and maintaining website security. We weigh our reasons for processing against your rights and freedoms.
- Consent: In situations where you provide explicit consent, such as receiving marketing communications, we process data accordingly. You have the right to withdraw consent at any time.
How We Use Your Data
Your information is used strictly for the purposes for which it was collected. This includes processing and delivering your flower orders, communicating updates or issues regarding your purchase, offering relevant customer service, maintaining our business operations, and—where consent is given—sending you marketing or promotional material regarding our products and services.
Retention Periods
We retain your personal data only as long as necessary to fulfill the purposes outlined in this policy and in line with regulatory and legal requirements:
- Order data is typically retained for up to seven years to comply with financial, legal, and auditing requirements.
- Communication records and customer service correspondence are retained for up to two years after your last interaction, unless required for ongoing dispute resolution or compliance.
- Website analytics data is anonymized where possible and retained according to our analytics provider's retention policy, typically up to 26 months.
Once data is no longer necessary, we securely delete or anonymize it.
Data Processors and Third Party Sharing
To provide our services, we may share your data with trusted third parties (“processors”) who process data on our behalf, under written contracts that meet GDPR standards. These include:
- Payment processors for facilitating online payments.
- Delivery partners to ensure timely and accurate delivery of your orders.
- IT service providers supporting our customer management and website systems.
- Analytics providers to help us understand website usage and improve user experiences (using aggregate, pseudonymised, or anonymised data whenever possible).
All third-party processors are required to comply with GDPR and handle your data securely. Your data is never sold or shared for unrelated marketing purposes.
International Data Transfers
Where we transfer data outside the European Economic Area (EEA), we ensure such transfers are protected by appropriate safeguards, such as Standard Contractual Clauses or approved certifications, to guarantee your data rights remain protected.
Your Rights as a Data Subject
Under GDPR, you have several rights regarding your personal data:
- The right to access: You may request a copy of your personal data held by us.
- The right to rectification: You can request correction of inaccurate or incomplete data.
- The right to erasure: Also known as the 'right to be forgotten'; you may request deletion of your data when it is no longer necessary for the purposes it was collected.
- The right to restriction: You can request restriction of processing in specific circumstances.
- The right to data portability: You may request to receive your data in a commonly used machine-readable format, or request its transfer to another provider where technically feasible.
- The right to object: You can object to processing based on our legitimate interests or to direct marketing at any time.
- The right to withdraw consent: Where processing is based on consent, you may withdraw this consent at any time.
To exercise your rights, please contact us using the details provided on our website. We will respond to all requests in accordance with our legal obligations. For identity verification, we may request further information from you.
Security of Your Data
We implement appropriate technical and organizational security measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. These measures include secure servers, encrypted transmission, regular data audits, and staff data protection training.
Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. The most current version will always be available on our website, with the date of the latest update clearly marked. We encourage you to review this policy periodically.
Contact Us
If you have any questions, concerns, or wish to exercise your data protection rights, please use the contact details provided on our website. If you are not satisfied with our response, you may contact the relevant data protection authority in your jurisdiction for further assistance.