Dulwich Flowers Privacy Policy for Customers

Our Commitment to Your Privacy

This Privacy Policy explains how Dulwich Flowers collects, processes, and protects your personal data when you place an order with us in Dulwich and the surrounding districts. Our practices are designed to comply with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018. Please review this Policy to understand what we do with your information and how we safeguard your privacy.

Scope of this Policy

This policy applies to all customers who place orders directly with Dulwich Flowers, whether online, by phone, or in person, specifically in Dulwich and neighbouring districts. If you interact with us in other ways or outside these areas, additional privacy notices may also apply.

What Personal Data We Collect

When you purchase from Dulwich Flowers or interact with us, we may collect and process the following categories of personal data:

  • Identification Data: Name, title, delivery recipient’s name
  • Contact Details: Delivery address, billing address, postcode, phone (if provided), and any contact information required to fulfil your order
  • Order Information: Details of the products ordered, delivery instructions, and messages for gift cards
  • Payment Information: Payment method details, though payment card data is processed directly by secure third-party payment processors and not retained by Dulwich Flowers
  • Communication Data: Records of correspondence regarding your order, including any queries, feedback, or complaints
  • Technical Data: If ordering online, technical information such as IP addresses, browser type, device information, and cookies necessary for the function of our website

Lawful Basis for Processing Your Data

We rely on several lawful grounds under the GDPR to process your personal data:

  • Contractual Necessity: We process your data in order to fulfil and deliver your order, respond to your service requests, and provide customer support.
  • Legal Obligation: We may process data where necessary to comply with applicable laws, such as accounting and tax regulations.
  • Legitimate Interests: We may use your information to improve our services, prevent fraud, and ensure the security of transactions, provided these interests are not overridden by your rights.
  • Consent: Where we send marketing communications, we do so only with your express consent. You can withdraw your consent at any time.

How We Use and Share Your Personal Data

Your data will only be used for the purposes outlined in this policy. We may share your information with trusted partners and service providers to assist with payment processing, order deliveries, and IT services. All third-party processors are contractually obligated to protect your data in accordance with GDPR requirements and only process your data in line with our instructions.

We will never sell your personal data or disclose it for any unauthorised purposes.

Data Retention

Dulwich Flowers retains your personal data only as long as necessary for the purpose it was collected:

  • Order Records: Kept for up to 7 years to comply with tax and accounting regulations.
  • Contact and Communication History: Retained for up to 3 years after your last interaction to handle any queries, complaints, or for quality assurance purposes.
  • Marketing Data: Retained until you withdraw consent or unsubscribe. On withdrawal, data will be promptly deleted or anonymised.
  • Technical Data: Retained for as long as necessary for website security and performance, typically not exceeding 12 months.

After these periods, your information will be safely deleted or irreversibly anonymised.

Data Processors and International Transfers

We use carefully selected service providers (data processors) to manage payments, deliveries, website hosting, and IT infrastructure. Each processor is required by contract to implement strong data security measures and comply with all relevant GDPR obligations. We do not transfer your personal data outside the UK or the European Economic Area unless adequate safeguards such as Standard Contractual Clauses are in place.

Your Data Rights

Under the GDPR, you have the following rights regarding your personal data:

  • Right of Access: Request a copy of the personal data we hold about you.
  • Right to Rectification: Request corrections to incorrect or incomplete information.
  • Right to Erasure: Ask for your personal data to be deleted where no longer necessary.
  • Right to Restrict Processing: Ask us to limit the use of your data in certain circumstances.
  • Right to Data Portability: Request your data in a structured, commonly used and machine-readable format.
  • Right to Object: Object to processing where we rely on legitimate interests; object to direct marketing at any time.
  • Right to Withdraw Consent: If we process your data based on consent, you may withdraw that consent at any time, without affecting the lawfulness of processing carried out before withdrawal.

Should you wish to exercise any of these rights, please contact us using the details provided on our website or written correspondence to our business address. We will respond to legitimate requests within one month, as required by law.

Data Security

Dulwich Flowers applies appropriate organisational and technical measures to safeguard your personal data. These measures include staff training, secure IT systems, and regular security reviews. In the unlikely event of a data breach, we will notify affected individuals and regulatory authorities in accordance with legal requirements.

Changes to Our Privacy Policy

We reserve the right to update or change this Privacy Policy from time to time. Any changes will be communicated through our website. The updated version will take effect immediately upon posting.

Contact and Concerns

If you have any questions, concerns, or complaints regarding the handling of your personal data or wish to exercise your rights, please refer to our website for current contact information or write to us at our business address. If you are not satisfied with how your data is handled, you also have the right to lodge a complaint with the Information Commissioner's Office (ICO).

Thank you for placing your trust in Dulwich Flowers. We are committed to protecting your privacy and handling your data transparently and securely.