This Privacy Policy explains how Flower Delivery Elephant and Castle collects, processes, stores, and protects your personal information in accordance with the General Data Protection Regulation (GDPR). This policy applies to all customers placing orders with Flower Delivery Elephant and Castle from Elephant and Castle and the surrounding districts. We take your privacy seriously and are committed to safeguarding your personal data.
In the course of providing our flower delivery services, we may collect and process the following types of personal data:
Flower Delivery Elephant and Castle processes your personal data only where we have a lawful basis to do so, as defined under GDPR. Our lawful bases include:
Your personal data is used for the following purposes:
We retain your personal data only for as long as is necessary to fulfill the purposes for which it was collected, to comply with legal obligations, resolve disputes, and enforce our agreements. Typically, order information and correspondence are retained for up to seven years for accounting and auditing purposes. Marketing preferences are retained only as long as you are subscribed or until you withdraw your consent. At the end of the retention period, personal data is securely deleted or anonymized.
To provide our services, we may share your personal data with carefully selected third-party processors who act on our behalf. These processors include:
All processors are contractually obliged to safeguard your data and act only in accordance with our instructions and the applicable data protection regulations. We do not sell or rent your personal data to third parties.
As a data subject under the GDPR, you have the following rights regarding your personal data:
To exercise your rights, please contact us using the contact details provided through our established communication channels.
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, destruction, or alteration. Such measures include secure servers, encryption, regular security assessments, controlled access, and staff training. However, no internet-based service is completely secure and we encourage you to take appropriate measures to protect your personal data.
Your personal data may be processed outside the European Economic Area (EEA) if our processors are located or store data internationally. In such cases, we ensure that all necessary safeguards are in place to protect your information, including standard contractual clauses or equivalent protective measures in compliance with GDPR.
We reserve the right to update this privacy policy from time to time to reflect changes in our business or legal requirements. We encourage you to review this policy periodically to stay informed about how we protect your personal information.
If you have questions about this Privacy Policy or wish to make a complaint regarding the processing of your personal data, please contact us via the channels available on our website. You also have the right to lodge a complaint with the Information Commissioner's Office (ICO) if you believe your data protection rights have not been upheld.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
