Flowers Biggin Hill GDPR Privacy Policy
  Introduction
This Privacy Policy explains how Flowers Biggin Hill collects, processes, and retains personal information from customers placing orders in Biggin Hill and surrounding districts. We are committed to safeguarding your privacy and ensuring all personal data is processed in accordance with the General Data Protection Regulation (GDPR) and applicable UK data protection laws.
Scope of this Policy
This policy applies to all individuals who place flower orders with Flowers Biggin Hill, whether via our website, by phone, or in person, and who reside or place orders for delivery in Biggin Hill and its surrounding areas.
What Personal Data We Collect
We may collect, store, and use the following categories of personal data:
- Contact Details: Name, delivery address, billing address, and telephone number.
 
- Order Information: Details of products ordered, order notes, and messages for recipients.
 
- Payment Information: Payment method, and limited payment data (processed securely through our payment provider; we do not retain card numbers).
 
- Account Information (if applicable): Username, password, and order history if you register for an account.
 
- Communication Data: Communications via email, phone, or our website forms.
 
- Website Usage Data: IP address, browser type, operating system, and browsing behaviour (through cookies and analytics tools).
 
Lawful Basis for Data Processing
We collect and use your personal data under one or more lawful bases as required under Article 6 of the GDPR:
- Contract: To perform our obligations under the contract when you place an order with us and to ensure successful delivery.
 
- Legal Obligation: To comply with applicable financial, business, and tax record-keeping requirements.
 
- Legitimate Interest: For internal business purposes such as improving our services, managing customer relationships, and protecting our business from fraud.
 
- Consent: Where required, such as for emailing marketing materials or newsletters, we request your explicit consent. You may withdraw consent at any time.
 
How We Use Your Personal Data
Flowers Biggin Hill uses the collected data for the following purposes:
- Fulfilling and managing your orders, including delivery and order tracking.
 
- Processing payments and accounting for completed transactions.
 
- Providing customer support and responding to your enquiries.
 
- Sending service-related communications (such as order confirmations and delivery notifications).
 
- Improving our services and website, including troubleshooting and analytics.
 
- Complying with legal obligations and resolving any disputes.
 
- With your explicit consent, sending you promotional offers, newsletters, or updates about our services.
 
Disclosure and Data Processors
We may share your data with trusted third parties to help us provide our services. These include:
- Payment Service Providers: To securely process payments (we do not store your full payment details).
 
- IT and Hosting Providers: For website hosting, storage, and security.
 
- Certain Delivery Partners: For the purpose of delivering your ordered products to the intended address.
 
- Professional advisors: For accounting, legal, or business consultancy where required.
 
All our data processors are carefully selected and must guarantee compliance with GDPR by entering into appropriate data processing agreements, ensuring your data is handled securely and confidentially.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
Retention of Your Personal Data
Your personal data is retained only for as long as necessary for the purposes stated in this policy, or as required by law. Typically, we retain:
- Order records and contact information for up to 6 years, as required for tax and business accounting purposes.
 
- Payment transaction data for as long as necessary to facilitate refunds or dispute resolutions (up to 2 years).
 
- Marketing and communication preferences until you withdraw consent or unsubscribe.
 
- Website analytics data is stored in aggregate or anonymised form where possible.
 
Once no longer needed, your data will be securely deleted or anonymised.
Data Security
We employ suitable technical and organisational measures to protect your personal data, including secure payment processing, restricted access to customer data, data encryption, and regular security reviews of our systems.
Your Rights Under GDPR
As a data subject, you have the following rights regarding your personal data:
- Access: The right to request access to your personal data and receive a copy of the information we hold about you.
 
- Rectification: The right to request correction of inaccurate or incomplete data.
 
- Erasure: The right to request deletion of your personal data in certain circumstances.
 
- Restriction: The right to request restriction of processing your data where appropriate.
 
- Portability: The right to receive your data in a structured, commonly used, and machine-readable format for transfer to another data controller where applicable.
 
- Objection: The right to object to certain types of data processing, such as direct marketing based on legitimate interests.
 
- Withdrawal of Consent: If we rely on your consent for processing, you have the right to withdraw it at any time without affecting the lawfulness of processing carried out before withdrawal.
 
- Complaint: The right to lodge a complaint with a supervisory authority if you believe your rights have been infringed.
 
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in the law or to our business practices. The updated policy will always be made available before new activities begin.
Contact Us
If you have any questions or wish to exercise your data protection rights, please contact us using the communication options provided on our website or visit our store in Biggin Hill.