At Fulham Flowers, your privacy is important to us. This Privacy Policy describes how we collect, use, store, and share your personal data in compliance with the General Data Protection Regulation (GDPR). The policy specifically applies to all customers and individuals placing orders in Fulham and surrounding districts. We explain our data practices transparently, including what information we collect, our lawful bases for processing, who has access to your data, and your individual rights.
When you place an order or interact with Fulham Flowers, we may collect the following personal data:
According to GDPR, we must have a legal basis for processing your personal data. At Fulham Flowers, we rely on the following lawful bases:
The personal data we collect is used for the following purposes:
We retain your personal data only for as long as necessary for the purposes outlined above, including to fulfill orders, resolve disputes, enforce agreements, and meet legal obligations. For most order-related data, we will retain your information for up to seven years to comply with recordkeeping and legal requirements. For marketing communications, your data will be retained until you withdraw consent or request deletion. Technical or analytical data may be anonymized and retained for a longer period for security and statistical purposes.
We may share your personal data with trusted third-party service providers who assist us in delivering our services. These data processors are required to comply with GDPR, maintain the confidentiality of your data, and only process information required to perform their contractual obligations. Examples include:
We do not sell or share your personal information with third parties for their own marketing purposes.
Wherever possible, we store and process your data within the United Kingdom and the European Economic Area (EEA). If any service provider processes your data in a country outside the EEA, we ensure appropriate safeguards are in place to protect your rights, as required by GDPR.
We take the security of your personal data seriously and implement technical and organizational measures to protect it from unauthorized access, loss, alteration, or misuse. These measures include secure server technologies, regular security reviews, staff training, and restricted data access on a need-to-know basis.
Under the GDPR, you have various rights over your personal data. These include:
If you would like to exercise any of your GDPR rights, please contact us using the contact methods provided on our website. We will respond to your requests in accordance with applicable law and within one month. In some cases, we may ask for further proof of identity to protect your privacy.
We may update this Privacy Policy from time to time to reflect changes in legal requirements or our data practices. Any significant changes will be communicated to you visibly on our website. We recommend reviewing this policy periodically to stay informed on how we protect your information.
If you have any questions or concerns about this Privacy Policy or how we process your data, please get in touch using the details on our website. Our team is committed to protecting your privacy and will address your concerns as promptly as possible.
Please fill out the form below to send us an email and we will get back to you as soon as possible.
