The privacy and security of your personal data are paramount to Flower Delivery Epsom. This Privacy Policy explains how we collect, use, retain, and protect your information when you place a flower delivery order from Epsom or the surrounding districts. Our practices comply with the General Data Protection Regulation (GDPR). Please read this policy to understand your rights and how your data is managed.
This Privacy Policy applies to all Flower Delivery Epsom customers who place orders directly or through our website, phone service, or any other channels, specifically those located in Epsom and the surrounding districts. By placing an order, you acknowledge the processing of your personal data as described below.
When you use our service, we may collect, use, store, and transfer the following categories of personal data:
We process your personal data only when there is a lawful basis, including:
Your data is used for the following purposes:
We retain your personal data only as long as is necessary to fulfil the purposes it was collected for, including satisfying legal, accounting, and reporting requirements. Order and billing records are generally kept for a minimum of six years in accordance with UK tax and transaction regulations. Personal data for marketing purposes is retained until you withdraw consent, opt-out, or request erasure. After these periods, data will be securely deleted or anonymised.
To provide our services, we may share relevant data with trusted third-party suppliers or processors who act on our instructions, including:
We ensure all processors are bound by appropriate data protection and confidentiality agreements. Your data is not sold or shared for unrelated marketing purposes.
Your personal data is primarily processed within the UK and the European Economic Area (EEA). If any transfer outside the EEA is necessary, we ensure appropriate safeguards and legal mechanisms are in place, such as recognised adequacy agreements or contractual clauses.
Under the GDPR, you retain significant rights concerning your personal data:
Requests regarding your rights can be made in writing. We will respond in accordance with GDPR timescales and inform you if extended processing time is required.
We implement both technical and organisational measures to protect your personal data from unauthorised access, accidental loss, misuse, or disclosure. These include access controls, password protection, regular security reviews, staff training, and secure deletion processes. While we make every effort to protect your information, please note that transmission of data over the internet is never entirely secure.
We may update this Privacy Policy to reflect changes in law, regulations, or our operational practices. Any significant changes will be communicated to you where appropriate. The effective date of this policy will be updated accordingly.
If you have questions about this Privacy Policy or require further information regarding how we process your data, please contact us via the methods provided on our website or customer communications. If you are dissatisfied with how we process your data, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO).
Please fill out the form below to send us an email and we will get back to you as soon as possible.
