Waterloo Flowers GDPR Privacy Policy
Introduction
At Waterloo Flowers, we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and process your personal information when you place orders with us. The policy applies to all customers ordering from Waterloo Flowers within Waterloo and the surrounding districts, ensuring compliance with the General Data Protection Regulation (GDPR) and relevant local laws.
What Data We Collect
To process your orders and provide quality service, Waterloo Flowers may collect and process various types of data, including:
- Identity Data: Name, title, and contact details such as delivery address.
- Contact Data: Telephone number (if provided), billing address, and delivery address.
- Order Data: Details of products ordered, delivery instructions, order history, and payment confirmation details (though payment card details are handled by secure processors and are not stored by us).
- Communication Data: Your communications with us, customer service queries, and feedback.
- Marketing Preferences: If you have opted to receive updates or promotions from us.
We do not knowingly collect data from individuals under the age of 16 without appropriate consent.
The Lawful Basis for Data Processing
Waterloo Flowers processes personal data based on legitimate, explicit, and lawful reasons in accordance with the GDPR:
- Contractual Necessity: Most data collection is required to process and deliver your order. Without this data, we would not be able to fulfill your purchase.
- Legal Obligation: Some information is retained to meet legal and regulatory requirements, such as record-keeping for tax purposes.
- Legitimate Interests: We may process data to improve our services, respond to queries, or manage complaints, provided such interests are not overridden by your rights.
- Consent: In situations such as sending marketing communications, we rely on your given consent, which you can withdraw at any time.
How We Use Your Data
Your information is used exclusively for legitimate business purposes, including:
- Processing and fulfilling your flower orders.
- Delivering floral gifts to specified recipients.
- Communicating concerning your order, such as confirmations or delivery updates.
- Responding to your queries, feedback, or complaints.
- Fulfilling legal and regulatory obligations.
- With your consent, providing marketing communications about promotions and offers.
Retention Periods
Waterloo Flowers is committed to keeping your personal data only for as long as necessary:
- Order and transaction data is usually retained for up to 7 years, fulfilling our legal and record-keeping obligations.
- Communication records and feedback are retained for up to 2 years for customer service and service improvement purposes.
- If you unsubscribe or withdraw consent from marketing, we will promptly remove your details from our marketing lists, though some data may be retained to ensure compliance with your preferences.
- After these periods, your information is securely deleted or anonymised.
Data Processors and Third Parties
To provide and improve our services, Waterloo Flowers may share your data with strictly selected third parties, always ensuring equivalent levels of data protection. These include:
- Payment Processors: We use secure, GDPR-compliant payment services to process transactions, who may access transaction data solely for payment processing purposes.
- Delivery Partners: If we use local couriers or providers for delivery, relevant contact and delivery information is shared for fulfilment purposes only.
- IT and System Support: Technology partners may access some data as necessary to maintain and improve our order management and website systems. Access is limited and monitored.
No personal data is ever sold to third parties. We require all processors to comply with strict data protection and confidentiality obligations and only allow them to use the data for specified purposes.
Your Rights Under GDPR
As a customer of Waterloo Flowers, you benefit from the following rights regarding your personal data:
- Right to Access: You may request a copy of the personal data we hold about you.
- Right to Rectification: If your information is incorrect or incomplete, you have the right to ask us to correct it.
- Right to Erasure: In some cases, you can ask us to erase your data (‘right to be forgotten’), especially where data is no longer necessary or you have withdrawn consent.
- Right to Restrict Processing: You may ask us to stop processing your data in certain circumstances.
- Right to Data Portability: Where technically feasible, you can request that your information be transferred to another organisation in a structured, commonly used format.
- Right to Object: You have the right to object to our processing of your data for marketing or legitimate interest purposes.
- Right to Withdraw Consent: If we rely on your consent (for example, for marketing communications), you may withdraw this at any time.
- Right to Complain: If you believe we have not complied with GDPR, you can lodge a complaint with your local supervisory authority.
How We Protect Your Data
We take all reasonable technical and organisational measures to protect your data from unauthorized access, disclosure, alteration, or destruction. This includes secure servers, encrypted communication, limited access to data, and regular staff training on data protection obligations.
Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices or for legal compliance. The most current version will always be available through our website. We recommend reviewing our Privacy Policy from time to time to stay informed about how we protect your data.
Contacting Us
If you have any questions, requests, or concerns about how we handle your personal data, or wish to exercise any of your rights, please contact us through the methods provided on our website or in your order communications. We will respond as promptly as possible and always in accordance with GDPR requirements.