Fortis Green Flowers Privacy Policy Overview
Introduction
This Privacy Policy describes how Fortis Green Flowers collects, uses, stores, and protects your personal data in accordance with the General Data Protection Regulation (GDPR). It applies to all customers placing orders with Fortis Green Flowers from Fortis Green and surrounding districts. Our goal is to ensure transparency and respect for your privacy by providing clear information about how your data is handled every step of the way.
What Data We Collect
When you place an order or interact with Fortis Green Flowers, we may collect the following categories of personal information:
- Contact details: Name, delivery address, billing address, phone number.
- Order information: Products ordered, order date, special instructions or messages for your order.
- Payment details: Payment card data (handled securely by our payment processor), transaction references, and payment status.
- Communication data: Any correspondence you have with us, including queries, complaints, or feedback.
- Technical information: Information about your device and usage when you access our website, such as IP address, browser type, and access times.
Lawful Basis for Processing
Under GDPR, we must have a lawful basis to process your personal data. Fortis Green Flowers relies on the following justifications:
- Contractual necessity: To process and fulfill your order, manage payment, and deliver products to you.
- Legitimate interests: To communicate with you about your order, improve our service, prevent fraud, and ensure the security of our website.
- Legal obligations: To comply with applicable UK and EU laws and regulations, such as record-keeping and tax requirements.
- Consent: In cases where we use your data for marketing purposes, we will seek your explicit consent, which you may withdraw at any time.
How We Use Your Data
Personal data is used strictly for the purpose for which it was collected. This includes:
- Processing and delivering your flower orders.
- Communicating order updates or queries to you.
- Providing customer service or responding to your requests.
- Processing payments securely through accredited processors.
- Complying with legitimate business, regulatory, and legal obligations.
- Improving our website, product offerings, and customer experience using aggregated, anonymised analytics.
Retention of Your Data
Fortis Green Flowers retains your personal data only as long as necessary to fulfill the purposes for which it was collected, and to comply with legal and accounting requirements. The retention periods are as follows:
- Order and contact information: Retained for up to 7 years to fulfil business, accounting, and legal requirements.
- Correspondence: Held for a maximum of 2 years after the issue is resolved, unless further retention is required for legal purposes.
- Payment information: We do not hold your card details; these are processed and retained by our payment processor according to their own retention schedules.
- Technical and analytical data: Retained for up to 24 months to support site security and performance tracking.
Third-Party Processors
We work with trusted external service providers (data processors) to process certain aspects of your data. These processors may include:
- Payment processing services: Securely process payments on our behalf.
- IT and website hosting providers: Maintain and secure our digital infrastructure.
- Courier and delivery partners: Fulfil and deliver your orders.
- Analytics providers: Help us understand website usage and improve our services (using anonymised data wherever possible).
All processors are bound by contractual obligations to protect your data in accordance with GDPR standards, and are not permitted to use your information for their own purposes.
How We Protect Your Data
We implement appropriate physical, technical, and organisational safeguards to ensure your personal data is safe. This includes website encryption, firewalls, secure data storage, access control, and staff data protection training. We regularly review these measures and update our procedures to respond to evolving security threats.
User Rights
Under the GDPR, you have several important rights regarding your personal data:
- The right to access – You can request a copy of your personal information held by us.
- The right to rectification – You can correct incorrect or incomplete data.
- The right to erasure – You can request deletion of your data where there is no lawful reason for us to keep it.
- The right to restrict processing – You can ask us to stop using your data in certain circumstances.
- The right to data portability – You can obtain and reuse your data for your own purposes across different services.
- The right to object – You can object to the processing of your data for direct marketing or where processing is based on our legitimate interests.
- The right to withdraw consent – Where you have provided consent, you may withdraw it at any time.
To exercise any of these rights, simply contact us using the details provided at the end of this policy. We will respond to your request within one month, subject to any complexity or legal requirements.
Data Transfers
Your data is stored and processed primarily within the UK and the European Economic Area (EEA). If it is ever necessary to transfer your personal information outside the EEA, we will ensure adequate protections are in place, in line with GDPR requirements.
Policy Updates
We may update this Privacy Policy occasionally to reflect changes in the law, our services, or privacy practices. We encourage you to review this page regularly. Any significant changes will be communicated clearly where appropriate.
Contact and Complaints
If you have any questions or concerns about this Privacy Policy or about how your personal data is handled, please contact us using the usual business communication channels provided on our website. If you remain dissatisfied, you have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) or your local supervisory authority.