Flower Delivery Fortis Green Privacy Policy
  Introduction
Your privacy is important to us at Flower Delivery Fortis Green. This Privacy Policy explains in detail how we collect, use, store, and protect your personal information when you order flowers from us. It applies to all customers placing orders for delivery to Fortis Green and the surrounding districts. We process personal data in accordance with the UK General Data Protection Regulation (UK GDPR) and other relevant privacy legislation.
The Data We Collect
When you place an order or interact with us, we may collect the following types of personal data:
- Identity Data: Your full name and, where applicable, that of the recipient.
- Contact Data: Billing and delivery addresses, telephone numbers, and any alternative contact details you provide for delivery purposes.
- Order Information: Details of your flower order, any accompanying personalised messages, preferred delivery date and time, and transaction records related to your purchase.
- Payment Data: Partial payment card information (handled securely via approved payment processors), payment status, and transaction references. We do not store or access full card details ourselves.
- Technical Data: IP address, browser type, device identifiers, and log information collected automatically when using our website for order placement or browsing.
- Communications: Any correspondence between you and Flower Delivery Fortis Green, including queries, complaints, or special requests.
Our Lawful Basis for Processing Your Data
Under UK GDPR, we are required to have a lawful basis for each type of processing we undertake:
- Contractual Necessity: Processing your personal data is necessary to fulfil our contract with you (e.g., taking, managing, and delivering your order).
- Legal Obligation: We may need to process your information to comply with legal requirements, such as tax and accounting.
- Legitimate Interests: For certain processing, such as improving our services, preventing fraud, and marketing direct to existing customers, we rely on legitimate interests, provided these do not override your data protection rights.
- Consent: We will obtain your explicit consent before contacting you with marketing communications unrelated to your previous orders. You may withdraw consent at any time.
How We Use Your Information
We use your personal data for the following purposes:
- To process and fulfil your flower delivery orders, including handling payments and arranging delivery logistics.
- To contact you regarding your order, such as confirming details, updating you on delivery status, or resolving queries.
- To manage your customer account, if you choose to create one.
- To comply with legal and regulatory requirements.
- To improve our products, services, and customer experience based on feedback and usage patterns.
- To prevent and detect fraud and other abuses of our services.
- With your consent, to send you marketing communications about Flower Delivery Fortis Green products, service updates, and promotions.
Sharing and Use of Processors
In order to provide our services efficiently, we sometimes share your information with selected third parties (processors), always under strict obligations to protect your data. These include:
- Payment Processors: For secure processing of credit/debit card or digital wallet transactions.
- Delivery Partners: Couriers or drivers entrusted with your order delivery, given relevant delivery and contact information.
- IT Service Providers: Companies providing website hosting, customer relationship management (CRM), security, and email automation.
- Professional Advisors: Accountants, legal advisors, or auditors as required for compliance or dispute resolution.
All processors are contractually obliged to process your information only as instructed, in compliance with UK GDPR and for no other purpose.
Personal Data Retention
We retain your personal information only as long as necessary to fulfill the purposes described in this Privacy Policy, including for satisfying legal, accounting, or reporting obligations. Retention periods are as follows:
- Order and Account Information: Typically retained for up to seven years after order completion for financial and legal reasons.
- Marketing Preferences: Data related to your marketing consent is retained while your consent remains active and for up to 12 months after withdrawal.
- Technical Data: Retained for analytical and security purposes for up to 24 months.
At the end of applicable retention periods, your data is securely deleted or anonymised.
Your Data Protection Rights
You have the following rights under UK GDPR in connection with your personal data:
- Right to Access: You can request a copy of your personal data that we hold.
- Right to Rectification: If you believe your data is inaccurate or incomplete, you may request that it is corrected or updated.
- Right to Erasure: You can ask us to delete your personal data, subject to certain conditions such as our legal obligations.
- Right to Restrict Processing: You can ask us to restrict how we process your personal information in certain circumstances.
- Right to Data Portability: Where applicable, you can request a copy of your data in a structured format for transfer to another service provider.
- Right to Object: You can object to certain processing, especially relating to direct marketing at any time.
- Right to Withdraw Consent: Where consent is the basis for processing, you may withdraw consent at any time without affecting previous lawful processing.
To exercise your rights, please contact us using the details available on our website or in your order confirmation communications. We may require verification of your identity before fulfilling requests.
Data Security
Your security matters to us. We implement a range of technical and organisational measures to safeguard your personal data against unauthorised access, loss, alteration, or disclosure. These include encrypted transmission, secure storage, access controls, regular security reviews, and staff training. In the unlikely event of a data breach affecting your rights and freedoms, we will notify you and relevant authorities, as required by law.
International Transfers
We aim to store and process your data within the UK and European Economic Area (EEA) wherever possible. If data is transferred outside these jurisdictions, we ensure that appropriate safeguards are in place to protect your personal information, in compliance with UK GDPR.
Children’s Personal Data
Our services are intended for those aged 18 and over. We do not knowingly collect or process any personal data from individuals under 18 years of age.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or relevant legislation. Any updates will be posted clearly on our website, and where appropriate, notified to you directly. We encourage you to review this Privacy Policy periodically.
Contact and Complaints
If you have questions about this Privacy Policy or wish to exercise your data protection rights, please refer to our website contact section or your order confirmation for the appropriate contact form. If you are dissatisfied with our response, you may lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection regulator.