Flowers Homerton Privacy Policy
  Introduction
This Privacy Policy explains how Flowers Homerton collects, uses, stores, and protects your personal data when you place an order with us as a customer in Homerton and surrounding districts. We are committed to safeguarding your privacy and handling your information transparently and securely in accordance with the General Data Protection Regulation (GDPR) and relevant UK data protection laws.
Scope of This Policy
This policy applies to all customers ordering from Flowers Homerton, whether you are ordering in person, online, or via telephone, when residing in or sending flowers to the Homerton area or adjacent districts. It covers how we process your data throughout the order lifecycle, from initial enquiry to order completion and follow-up.
What Data We Collect
To process and fulfil your orders, Flowers Homerton collects the following categories of personal data:
  - Contact Information: Name, delivery address, billing address, phone number, and (if provided) email address.
- Order Details: Product selection, delivery instructions, recipient’s address (if the flowers are sent to someone else), any personal message to be included with the order.
- Payment Information: We process payments by capturing details required to complete transactions. Payment card data is handled securely through our payment processor and not stored on our own systems.
- Communication Records: Correspondence and communications that you may exchange with us regarding your order or our services.
- Website Usage Data: When you visit our website, technical data such as IP address, browser details, session duration, and usage patterns may be collected to enhance user experience and security.
Lawful Basis for Processing
We process your personal data according to the following lawful bases under GDPR:
  - Contractual Necessity: Most of the data we collect is necessary to perform our contract with you, such as processing and delivering your flower orders.
- Legal Obligations: We may store or disclose certain information to meet our legal or regulatory obligations (for example, accounting and taxation).
- Legitimate Interests: We may use your data to improve our services, handle enquiries, or for limited marketing communications with existing customers, provided this does not override your rights and interests.
- Consent: In situations where we rely on your consent (for instance, for optional marketing messages), you may withdraw your consent at any time.
How We Use Your Data
Your personal information is used solely for purposes related to your customer relationship with us, including:
  - Processing and fulfilling your floral orders
- Arranging deliveries and notifying you or recipients
- Responding to your queries and providing customer support
- Managing records for accounting, taxation, and legal requirements
- Sending service-related communications such as order confirmations or delivery updates
- Improving our products, services, and customer interactions
Retention of Your Data
We retain personal data for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. The specific retention periods are:
  - Order Records: Retained for up to 7 years to comply with accounting regulations and tax laws.
- Marketing Records: If you opt in to receive marketing, we will retain your details until you unsubscribe or withdraw consent.
- Website Usage Data: Retained for up to 2 years to assist with analytics and security reviews.
After these periods, your information will be securely deleted or anonymised.
Sharing Your Data and Use of Processors
Flowers Homerton limits the sharing of your personal data. In certain circumstances, we may share relevant data with trusted third-party processors to support our services, including:
  - Payment service providers to process financial transactions securely
- Courier and delivery partners for providing order delivery
- IT and software providers assisting with order management, website hosting, and data security
- Professional advisers or legal authorities if required to comply with legal obligations
All processors handle your information on our instructions, consistent with GDPR requirements, and are prohibited from using your data for other purposes.
Your Rights as a Data Subject
As a customer, GDPR grants you certain rights regarding your personal information, including:
  - Right of Access: You can request a copy of the personal data we hold about you.
- Right to Rectification: You may ask us to correct inaccurate or incomplete information.
- Right to Erasure: You can request deletion of your personal data where there is no valid reason for us to keep it.
- Right to Restrict Processing: You can request us to limit the way we use your data.
- Right to Data Portability: You may request that we provide your data to you, or a third party, in a structured, commonly used digital format.
- Right to Object: You may object to the processing of your data on grounds relating to your particular situation, including for direct marketing.
- Right to Withdraw Consent: If we are processing your data based on your consent, you can withdraw it at any time.
To exercise these rights, or for any questions regarding your data, please contact us using the details provided on our website or in your order confirmation communications. We will seek to respond promptly and within the timescales set by law.
Data Security
Flowers Homerton implements a range of technical and organisational measures to protect your personal data from loss, misuse, or unauthorised access. These include access controls, encrypted transmissions, secure storage, regular staff training, and strict vetting of our processors.
Policy Updates
This policy may be reviewed and updated periodically to reflect changes in our practices or legal obligations. The latest version will always be available to our customers, and significant updates will be communicated where practicable.
Contact and Complaints
If you have questions or concerns about how Flowers Homerton processes your personal data, or wish to exercise any of your legal rights, please contact us through the methods outlined on our website or your order documents. You also have the right to lodge a complaint with the UK Information Commissioner’s Office (ICO) if you believe your data protection rights have been infringed.