Brent Flowers Customer Privacy Policy
Introduction
This Privacy Policy outlines how Brent Flowers collects, uses, stores, and protects your personal information when you place orders with us. Our aim is to operate in full compliance with the General Data Protection Regulation (GDPR). The policy applies to all customers placing orders with Brent Flowers from Brent and the surrounding districts.
What Data We Collect
When you interact with Brent Flowers, whether by making a purchase, an inquiry, or signing up for updates, we may collect the following types of data:
- Personal Identification Details: Name, delivery address, billing address, and contact details (such as phone number where required for delivery coordination).
- Order Information: Details of the products you order, recipient name, card messages, gift preferences, and any specific instructions related to your order.
- Transactional Data: Payment information and records of transactions processed through our payment service providers (Brent Flowers does not directly store card numbers or bank account details).
- Communications: Correspondence with us, including emails, feedback, queries, or complaints.
- Technical Data: Information collected automatically via our website such as IP addresses, browser type and version, device type, time zone settings, and website usage data.
Lawful Basis for Processing
Brent Flowers processes your personal data on the following legal bases:
- Contractual Necessity: We use your information to process your orders, deliver your flowers, and manage payments as these activities are necessary for fulfilling our contract with you.
- Legal Obligations: We are required to process and retain certain data for tax and accounting purposes, as well as to comply with local laws.
- Legitimate Interests: To provide, improve, and personalize our services, respond to your inquiries, prevent fraudulent activities, and enhance your customer experience.
- Consent: If you opt in to receive marketing communications or newsletters, we will use your data only for this purpose and you may withdraw your consent at any time.
How We Use Your Data
Your data is used for the following purposes:
- Processing and managing your orders, including contacting you or the recipient as required for delivery.
- Maintaining accurate records for accounting and legal obligations.
- Providing customer support and responding to inquiries.
- Improving our website and services based on usage data.
- Sending relevant marketing or promotional communications if you have opted in.
Data Retention Policy
We will retain your personal data only for as long as necessary for the purposes set out in this policy. The retention periods are determined by factors such as the nature of the data, the purpose for which it was collected, and legal or regulatory requirements:
- Order and Transaction Data: Typically retained for up to 7 years to comply with tax laws and accounting regulations.
- Correspondence and Support Data: Retained for up to 2 years from the date of last correspondence.
- Marketing Data: If you unsubscribe from marketing communications, your contact details will be removed from our mailing list within 30 days, but records may be retained for up to 1 year to evidence compliance with your request.
After these periods, personal data will be securely deleted or anonymized so it cannot be attributed to any individual.
Data Processors and Third Parties
To fulfil your orders and operate our business, we use trusted third-party service providers (data processors) who may process limited personal information on our behalf. These include:
- Payment processing companies
- Couriers and delivery service providers
- IT support and website hosting companies
- Professional advisors (such as accountants)
We ensure that all processors act in accordance with GDPR requirements, process data only upon our instructions, and implement appropriate security measures. Data is not sold, rented, or otherwise shared for unrelated third-party marketing purposes.
Your Rights under GDPR
Under the GDPR, you have important rights with respect to your personal data:
- Access: You have the right to request access to your personal data and to receive a copy of what information we hold about you.
- Rectification: You may request correction of any inaccurate or incomplete information.
- Erasure: In certain circumstances, you have the right to request the deletion of your data, unless we are required by law to retain it.
- Restriction: You can ask us to restrict how we use your data in specific situations.
- Objection: You may object to our processing of your data where processing is based on our legitimate interests or for direct marketing purposes.
- Portability: You have the right to request your data be provided to you in a structured, machine-readable format.
- Withdraw Consent: Where consent is the basis for processing, you can withdraw your consent at any time without affecting the lawfulness of processing prior to withdrawal.
Requests regarding these rights will be responded to within one month, in accordance with GDPR.
Data Security
Brent Flowers uses appropriate technical and organizational security measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. Access to your data is strictly limited to staff and contractors who require it for business purposes and who are bound by confidentiality obligations.
Policy Updates
This Privacy Policy may be updated periodically to reflect changes in our practices, operational requirements, or legal regulations. Any significant changes will be communicated before they take effect.
Applicability
This Privacy Policy applies to all Brent Flowers customers placing orders from Brent and surrounding districts. By placing an order or engaging with Brent Flowers, you acknowledge you have read and understood this policy.