Privacy Policy for Customers Ordering with Flowers Nine Elms
  Introduction
This Privacy Policy describes how Flowers Nine Elms ("we", "our", or "us") processes and safeguards your personal data when you place orders with us from Nine Elms and the surrounding districts. We are committed to protecting your privacy and handling your personal information in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable laws of the United Kingdom.
Scope of This Policy
This policy applies to all customers placing orders with Flowers Nine Elms, whether in-person, by phone, or through our online platforms, from Nine Elms or any of the neighbouring areas. By ordering with us, you acknowledge that you have read and understood this Privacy Policy.
Personal Data We Collect
We collect and process a variety of personal data, depending on the nature of your interaction with us. This may include:
  - Identity Information: such as your full name and title
- Contact Information: such as your delivery address, billing address, phone number, and other contact details
- Order Information: details about your floral orders, product preferences, recipient names and addresses, and special instructions
- Payment Information: payment method, transaction details (note: we do not store your full credit or debit card numbers)
- Communication Data: correspondence with us by email, telephone, or other means
- Technical Data: information collected automatically when you use our website, such as IP address, device type, browser type, and usage statistics
Lawful Basis for Processing
We process your personal data only when there is a lawful basis to do so under the GDPR. These bases include:
  - Contractual Necessity: To fulfil obligations arising from any orders you place with us, such as delivering floral arrangements and processing payments.
- Legal Obligation: To comply with legal requirements, such as maintaining financial records or responding to lawful requests from authorities.
- Legitimate Interests: To improve our services, manage customer relationships, and prevent fraud, provided such processing does not override your privacy rights.
- Consent: In some cases, we rely on your consent, such as when you subscribe to receive marketing communications. You can withdraw your consent at any time.
How We Use Your Data
We use your personal data for the following purposes:
  - To process and deliver your orders
- To communicate with you about your orders and provide customer support
- To manage payments, fees, and charges
- To personalize your experience with us
- To improve our website, products, and services based on usage analytics
- To comply with our legal obligations and to protect the rights, property, or safety of our customers and employees
- For marketing purposes, where you have consented to receive such communications
Retention of Your Personal Data
We retain your personal information for as long as is necessary to fulfill the purposes outlined in this policy, including for satisfying any legal, accounting, or reporting requirements. The retention period may vary based on the nature of the data and our legal obligations. Typically:
  - Order and transaction data are retained for at least six years for tax and accounting purposes
- Customer correspondence is kept for as long as necessary to resolve queries or complaints
- Marketing consent records are retained until you withdraw your consent
- Technical data collected for analytics is anonymized or deleted after a maximum of 24 months
Processors and Data Sharing
Flowers Nine Elms engages trusted third-party service providers ("processors") to help us deliver our services efficiently and securely. Processors may include:
  - Payment processing providers
- Courier and logistics companies to deliver your orders
- IT service providers, including website hosting and maintenance providers
- Professional advisers, such as accountants
- Analytics service providers
These processors are contractually obligated to protect your data and may only use it to deliver the services we have requested. We do not sell or rent your personal information to third parties. If required by law, we may disclose your data to authorities.
International Data Transfers
Your personal data is primarily processed within the United Kingdom and the European Economic Area (EEA). If we need to transfer data outside the EEA, we will ensure appropriate safeguards are in place to guarantee your data is protected with a similar level of security as under the GDPR.
Your Rights Under GDPR
As a data subject under the GDPR, you have the following rights regarding your personal information:
  - Right of Access: You can request access to the personal data we hold about you
- Right to Rectification: You can ask us to correct inaccuracies or complete incomplete data
- Right to Erasure: In certain circumstances, you can request that we delete your personal data
- Right to Restrict Processing: You may request that we restrict the processing of your personal data
- Right to Data Portability: You can request to receive your data in a structured, commonly used format and have it transmitted to another controller
- Right to Object: You have the right to object to processing based on our legitimate interests or for direct marketing purposes
- Right to Withdraw Consent: If we rely on consent to process your data, you may withdraw your consent at any time
To exercise any of your rights, or if you have any concerns about how your data is handled, you may contact us using the methods provided on our website or through your usual contact channels with our business.
Data Security
We implement appropriate technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, alteration, or disclosure. These measures include secure servers, encrypted communications, access controls, regular staff training, and policies to manage our information security.
Policy Updates
We may update this Privacy Policy periodically to reflect changes in our data processing practices or legal requirements. Any changes will be posted on our website and will take effect immediately upon posting. We encourage you to review this policy regularly to stay informed.
Contact Information
If you have any questions about this Privacy Policy or wish to exercise your rights under GDPR, please contact Flowers Nine Elms using the contact methods published on our website or through your preferred communication channel with our team.