Who is Responsible for Processing Your Personal Data
IOW Flowers Ltd trading as Isle of Wight Flowers (www.isleofwightflowers.co.uk) is the Data Controller. This is the legal entity responsible for how your personal data is collected, stored and processed.
We respect your privacy rights and recognise the importance of protecting the information collected about you.
Explaining The Legal Bases We Rely On
The law on data protection sets out a number of different reasons for which a company may collect and process your personal data, including:
- Consent – In specific situations, we can collect and process your data with your consent. For example, when you tick a box to receive email newsletters. When collecting your personal data, we’ll always make clear to you which data is necessary in connection with a particular service.
- Contractual obligations – In certain circumstances, we need your personal data to comply with our contractual obligations. For example, if you order an item from us for home delivery, we’ll collect your address details to deliver your purchase, and pass them to our courier.
- Legal compliance – If the law requires us to, we may need to collect and process your data. For example, we can pass on details of people involved in fraud or other criminal activity affecting the Partnership to law enforcement.
- Legitimate interest – In specific situations, we require your data to pursue our legitimate interests in a way which might reasonably be expected as part of running our business and which does not materially impact your rights, freedom or interests. For example, we will use your purchase history to send you or make available personalised offers. We also combine the shopping history of many customers to identify trends and ensure we can keep up with demand, or develop new products/services. We will also use your address details to send you direct marketing information by post, telling you about products and services that we think might interest you.
Managing Your Personal Data
When you share your personal information with us, you have a right to expect that information to be treated with total confidentiality. Therefore, it is our responsibility to manage your personal data that you provide to us with care and in accordance with all data protection legislation and industry best practice.
It is your responsibility to ensure that your personal data provided to us is accurate and up to date. You can update your personal contact details, including email address and phone number, by visiting My Account online or, if you need to update any other personal details, by calling our Isle of Wight Flowers Team on 01983 756333.
We collect information about you for two reasons:
- to process your order
- to provide you with the best possible service
The personal information which we hold will be held securely in accordance with our internal security policy and English law. We are fully compliant with PCI DSS.
Using Your Personal Data For Marketing Purposes
We would like to keep you informed about our latest product offers and promotions using the email address you provide to us. Based on your marketing preferences, we use your email and home address to send you details of our latest products and promotions. We also use marketing Profiling techniques to determine what product offers may be of interest to you whether that be by email, direct mail (by post) or social media.
Any email marketing we may send will always include an unsubscribe option. If you wish to add or remove yourself from our mailing list at a later date you can do so by unsubscribing from the email received or by contacting us directly.
We do not and will not sell our mailing list to third parties.
We hold your personal data for the purposes of direct marketing to you for a period of two years from the date of your last purchase. If you have updated your marketing preferences to “opt in” to receive regular content from us you will continue to receive marketing information until you tell us otherwise.
Obtaining Your Consent
We will obtain your consent to send you details of our latest products and promotions to you via Email Marketing and other Direct Marketing methods in a number of ways. To do this, we will ask you to opt-in to receive marketing emails when you first register an account with us, make a purchase, sign up for our newsletter, enter a competition or prize draw or agree for us to use your email address for marketing purposes when we send you electronic receipts in store. You can opt out of email marketing at any time.
Marketing By Post (Direct Mail)
We will use your name and address to send you personalised marketing mails in the post. We have a legitimate business interest to send you information about our products and offers in the post as we know that many of our customers like to browse through catalogues or offers prior to placing an order with us. However, should you wish to exercise your right to stop personalised postal marketing activity, you can do this at any time.
We will use your email address to send you online targeted marketing information about our product offers and promotions via social media platforms. To do this, we will share your email address in a secure manner with social media organisations, such as Facebook, who will match our advertising requirements to your social media profile. We have a legitimate business interest to send you product information via social media which we believe is of relevance to you; this is known as Interest-Based Advertising. However, should you wish to exercise your right to stop targeted social media marketing, you can do this at any time.
Changing Your Marketing Preferences
You can change your marketing preferences for Email Marketing at any time by:
- Clicking unsubscribe in the body of the email sent to you;
- Going online to My Account; or
- Calling Isle of Wight Flowers on 01983 756333.
You can exercise your right to object to Direct Mail (Marketing By Post) or Social Media at any time by:
- Calling Isle of Wight Flowers on 01983 756333.
Please allow 48 hours for your changes to be processed for social media. You may still receive direct marketing materials that are already processed before we received your request for up to 2 months.
Using Your Personal Data to Improve Your Online Shopping Experience: Tracking Patterns of Behaviour
We use technology to track the patterns of behaviour of visitors to our site. This can include using a “cookie” which would be stored on your browser. You can usually modify your browser to prevent this happening (for example, using Internet Explorer select ‘internet options’ from the ‘tools’ menu, then click ‘security’, followed by ‘custom level’ and select ‘disable cookies’).
The information collected in this way can be used to identify you unless you modify your browser settings. Cookies are also used to ensure private and secure purchase sessions are operated within the site.
We have a legitimate business interest to use the aggregated and anonymised data obtained via Cookies and other data sources to help us provide you with relevant product marketing and improve your online shopping experience.
Every time you connect to our website we store a log of your visit which shows the unique number your machine uses when it is connected to the internet (IP address). This tells us what you looked at; whether the page request was successful or not and which browser you use to view the pages. The use of this data is strictly for statistical purposes only. This helps us to understand which areas of the site are of particular interest and also which pages are not being requested. It also tells how many people are visiting the website in total.
Using Your Personal Data for Fraud Prevention
We carry out fraud checks on credit and debit card orders. In order to do this, we use data sourced from Credit Reference Agencies and other external agencies that are involved in fraud detection. If we identify fraud, we will pass data relating to the fraudulent activity such as name, address and email address to these agencies to help protect individuals and other businesses from the threat of fraud in the future.
We will hold your personal data for 6 years, plus the current financial year, after the date of your last transaction with us on your personal credit or debit card account.
Using Your Personal Data to Operate Flower Club VIP Membership
We will use the information, including personal data, which you provide to us when you register for your Flower Club VIP membership customer account to administer your loyalty membership. Without this data, we are unable to administer your Flower Club loyalty membership. For more details on how we use your personal data, click on the heading below.
We will hold your personal data for 6 years, plus the current financial year, after the date of your last transaction on your Flower Club loyalty membership.
We will use your personal data to operate your Flower Club loyalty membership in the following manner:
- Your personal data, such as name, postal address and email, will be used to process and distribute your rewards.
- Details of rewards that are available to you will be sent to the email address you provided.
- Data from your Flower Club membership customer account may be used for the purposes of analysis and so that we can provide rewards that are tailored to you.
It is important that the contact information on your Flower Club customer account is accurate and up to date at all times. If you need to amend any of your details, you can do this by calling us.
Using Your Personal Data to Operate Your Personal Account
We will use your personal data to administer and to operate your personal account. We will collect and use the contact details that you provide to us to communicate with you about your account and in relation to the products and services we provide to you.
We will hold your personal data for 6 years, plus the current financial year, after the date of your last transaction on your account.
Delivering Your Flowers & Gifts – We will use you and your recipients personal contact details such as name, postal address, phone number and email address that you provide to us in respect of delivering products or services for you. We will share this information with our delivery partners and our employees, who may contact you to arrange a convenient delivery time and provide you with updates as to when they will arrive.
Processing Refunds – We use your customer account and contact details to verify any returns and refunds that we process either by card or via your PayPal account. We process all card payments in line with our obligations under the PCI-DSS regulations and will encrypt the payment details before sending to our card payment and banking provider.
Electronic Receipts & Other Documents via Email – We will use the email address that you provide to us to communicate with you about your account and in relation to the products and services we provide to you. Unless you have specifically requested otherwise, we will send your account receipts and other account information and documentation to you electronically using your email address. We will hold your order data for 6 years, plus the current financial year, after the date of your last order.
Enquiries and Complaints – If you have any complaints with regards to the operation of your account, please contact us on 01983 756333 so we can deal with your complaint as quickly as possible. We will need to access your personal data and account history to verify your identity for security reasons and deal with the details of your complaint. Details of any complaints received will be logged and recorded so they can be dealt with accordingly.
General Service & Order Communications – We will use your personal data for all general service communications including sending your receipts, processing orders, notifying you of orders received, updating you on deliveries, despatched or products out of stock. We need to do this for the performance of the contract and terms and conditions that you have signed.
Sharing Your Personal Data with Third Party Processors & Partners
As part of delivering our products and services to you, we will share your personal data with carefully chosen Third Party Processors and Partners who carry out a number of services on our behalf. Should you wish to obtain a list of our latest Third Party Processors and Partners, you can request this at any time by contacting us.
Any third party that communicates with you on our behalf must only do so for the purpose of carrying out the services and not for the purpose of direct marketing their own products and services. If you have any concerns about any of our third party processors and partners, please contact us immediately.
Processing Your Personal Data Outside of the EU
Acting as a Data Processor for Our Marketplace Partners
Your Personal Data Rights
Right Of Access – You may wish to access a copy of the personal data we hold about you – known as a Subject Access Request. You can do so by calling, writing to or emailing us. We will respond to your Subject Access Request as soon as possible and, in any event, within the statutory 30 days. However, in the event that we need more information from you to verify your identity, which we must do to ensure we disclose your personal data to the right person, the 30 day response period will only commence from the time that we have validated your identity.
Right of Rectification – If you believe we have made an error as to the personal data we hold about you, please contact us on 01983 756333 and we will be able to process the correction for you. Alternatively, you can visit My Account to update your contact details online.
Right of Erasure – You have the right to request your personal data to be permanently deleted from our records and systems to avoid any further communication with you. Your request will always be considered in light of the legal bases that we hold, store and process your personal data and the purpose that we collected your data. Where the legal bases permits, we will carry out your instruction without undue delay.
Right to Restrict Processing – Should you believe that we are processing your personal data in a way that you did not understand or agree to and wish to restrict such processing, please contact us and we will be able to assist you.
Right to Object to Processing – You have the right to object to certain types of processing of your personal data. We will always make it clear at the outset of any new arrangement with you how we are going to process your personal data and how to unsubscribe or opt out.
Right to Portability – In the event that you wish to move your personal data that we hold on you to another organisation in the form of an excel or csv format, please contact us and we will be able to assist you.
Right to Complain to the Information Commissioner’s Office (ICO) – You have a right to lodge a complaint with the Information Commissioner’s Office (ICO) if you have a complaint with how you believe your personal data has been handled. For more information, please visit https://ico.org.uk/concerns
Data Controller Information
Should you wish to contact us about your personal data please write to us at:
Isle of Wight Flowers
Isle of Wight
Tel: 01983 756333
If you have any further queries, please do not hesitate to contact us.