This Privacy Policy applies to all customers who place orders with Flowers Highams Park, whether online, over the phone, or in person, across Highams Park and its neighbouring districts. We are committed to protecting your personal data in compliance with the General Data Protection Regulation (GDPR) and ensuring transparency regarding how we collect, use, store, and share your information.
To provide our services and complete your order, we collect the following categories of data:
We do not intentionally collect or process sensitive personal information (special category data) as defined by GDPR, unless you provide this information in communications or order instructions. In such cases, we treat it with enhanced care.
Flowers Highams Park relies on the following lawful bases to process your personal data as permitted by GDPR:
Your information is processed strictly for the following reasons:
We store personal data only for as long as necessary to fulfil the purposes for which it was collected, including legal, accounting, or reporting requirements. Generally, order and customer data is retained for up to seven years to satisfy tax and business record obligations. Communication data related to queries or complaints may be retained for up to three years after resolution. At the end of the relevant retention period, data is securely deleted or anonymised.
We may engage select third-party service providers ("processors") to assist in fulfilling your order and supporting business operations. Examples include:
Where third-party processors are used, they are contractually obliged to handle your data only as instructed, comply with the GDPR, and implement appropriate data security measures.
We do not sell, rent, or trade your personal data. Transfers outside the UK/EEA, if required for technical solutions, are only permitted where adequate protection measures are in place.
As a customer, you have the following rights concerning your personal data:
To exercise any of these rights, you may contact us using the details provided on our website or ordering platform. For security, we may need to verify your identity before processing your request. We aim to respond within one month, as required by law.
We implement appropriate organisational and technical measures to safeguard your personal data against accidental loss, confusion, unauthorised access, alteration, or disclosure. These include restricted access controls, secure storage, and ongoing staff training.
We may update this Policy from time to time to reflect changes in the law or our business practices. The latest version is always available before you place an order, and material changes will be clearly indicated. Your continued use of our services signifies your acceptance of any updates.
If you have questions, concerns, or wish to exercise your rights regarding your personal data, please contact us via the contact details on our website or in-store. If you remain dissatisfied, you may lodge a complaint with the UK Information Commissioner's Office (ICO), which oversees data protection compliance.
Last Updated: June 2024
Please fill out the form below to send us an email and we will get back to you as soon as possible.
