This Privacy Policy describes how Flower Delivery Gipsy Hill collects, uses, stores, and protects the personal data of all customers who place flower delivery orders from Gipsy Hill and the surrounding districts. We are committed to maintaining your privacy and safeguarding your personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR) and all relevant data protection legislation. This policy provides information regarding the categories of personal data we handle, the lawful basis for collection, our data retention periods, any third-party data processors we may use, and your legal rights.
This Privacy Policy applies to all personal data provided by customers for the purpose of placing and fulfilling flower delivery orders from Flower Delivery Gipsy Hill, whether orders are placed online, by telephone, or via other methods within Gipsy Hill and adjacent districts. By using our services, you acknowledge the practices set out in this Privacy Policy.
When you interact with Flower Delivery Gipsy Hill or place an order with us, we may collect the following categories of personal data:
We process your personal data in accordance with the lawful bases outlined under the GDPR. Our main grounds for processing include:
We use your personal data solely for the following purposes:
We retain your personal data only for as long as necessary to fulfill the purposes described above, and in accordance with our legal obligations and legitimate business interests. In general, we retain order and customer data for a period of six years from your last interaction with our services, to comply with legal and accounting requirements. Where data is processed based on consent (e.g., for marketing), your data will be retained until you withdraw consent or request erasure. After the applicable retention period, your data will be deleted or anonymized in a secure manner.
Flower Delivery Gipsy Hill may use trusted third-party processors for payment processing, delivery management, IT services, website hosting, and analytics. We ensure all processors are GDPR-compliant and only process data as instructed by us. Data shared with such processors is only what is strictly necessary to perform their services. We will never sell your personal data or share it for purposes other than those described in this policy. If we are required to disclose personal data by law, we will do so as needed to comply with legal proceedings or requirements.
We implement appropriate technical and organizational security measures to protect your personal data against loss, misuse, unauthorized access, disclosure, alteration, and destruction. These measures include encryption, secure servers, regular data protection reviews, and limited access to personal data to only those employees and partners with a legitimate business need.
Under the GDPR, you have the following rights regarding your personal data:
If you wish to exercise any of these rights, you may contact us through the communication methods detailed on our website. We may require identity verification before fulfilling your request and will respond in accordance with applicable law.
We may amend this Privacy Policy from time to time to reflect changes in legal obligations or our practices regarding personal data. Any modifications will appear in this document, with the date of last update indicated. We encourage customers to review this policy periodically to remain informed about how we handle and protect your data.
If you have concerns about the way your personal data is handled, or would like to exercise your data protection rights, you can reach out to us using the contact details provided on our website. Should you have further concerns, you also have the right to lodge a complaint with the relevant data protection authority in your country.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
