This Privacy Policy describes how Flower Delivery Totteridge (“we,” “us,” or “our”) processes your personal data in connection with the sale, payment, and delivery of flower orders placed by customers (“you,” “your”) from Totteridge and surrounding districts. We are committed to protecting your privacy and ensuring the lawful and transparent processing of your personal information in accordance with the UK General Data Protection Regulation (GDPR) and other relevant data protection laws. By placing an order with Flower Delivery Totteridge, you agree to the practices as described in this policy.
This policy applies to all individuals who interact with Flower Delivery Totteridge as customers or recipients of orders within Totteridge and neighbouring districts. It outlines our responsibilities and your rights regarding personal data collected during the ordering and delivery of flowers.
Depending on how you interact with us, we may collect the following categories of personal data:
Under the GDPR, Flower Delivery Totteridge must have a lawful basis for processing your personal data. Our legal bases include:
We use your personal information for the following purposes:
We only retain your personal data for as long as necessary to fulfil the purposes described in this policy. This typically means:
After these timeframes, your data is securely deleted or anonymised so that you can no longer be identified.
We sometimes use third-party service providers ("processors") to help us deliver our services. Examples of these processors include:
All our processors are contractually required to safeguard your data in compliance with GDPR and to use it only for the purpose of providing their services to Flower Delivery Totteridge. We do not sell your personal data or share it with third parties outside our service delivery process, except as required by law.
Where any of our processors are based outside the UK or European Economic Area, we ensure that adequate protections are in place, such as data processing agreements and reliance on appropriate safeguards as set out under GDPR (for example, Standard Contractual Clauses).
Under GDPR, you have the following rights concerning your personal data:
If you wish to exercise any of these rights, please contact us via our website or in writing. We may need to verify your identity before fulfilling your request.
We implement appropriate technical and organisational measures designed to safeguard your personal data against unauthorised access, loss, or misuse. These measures include secure storage, encryption of payment details, staff training, and regular review of our data handling practices.
We may update this Privacy Policy occasionally to reflect changes in our practices or legal obligations. Any such updates will be posted on our website, and significant changes will be communicated to you appropriately.
If you have any questions, concerns, or would like further information about how we process your personal data, please contact us through the details provided on our website. We are committed to resolving any issues or queries regarding your privacy rights promptly and transparently.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
