Privacy Notice

Last updated: August 31, 2026

Digital Florists Ltd ("Digital Florists", "we", "us", "our") is committed to being transparent about how we use personal data.

This Privacy Notice explains how we collect and use personal data when you:

If you do not agree with this Notice, please do not use the Website or (where applicable) the Service.

1. Who We Are and Our Role (Controller vs Processor)

1.1 When we act as a Controller

We act as a "Controller" (meaning we decide how and why personal data is processed) for:

1.2 When we act as a Processor

We act as a "Processor" (meaning we process personal data on a customer's behalf and under their instructions) for "Customer Data" submitted to or processed within the Service, including via Public Features (e.g., orders, recipient details, delivery addresses, messages, portal content, tracking page content and public form submissions configured by our customer).

In those circumstances, the relevant business using our Service is the Controller. If you are an end customer/recipient interacting with a florist using our Service, you should also read the florist's own privacy notice and contact them first for rights requests (see Section 8).

1.3 Contact details

Digital Florists Ltd
Address: 7 Booker Ave, Liverpool L18 4QY, United Kingdom
Email: hello [at] digitalflorists.com
Telephone: 0151 272 0049

Company number: 15423324

Privacy contact:
Email: privacy [at] digitalflorists.com

2. Personal Data We Collect

2.1 Website data (Website visitors and prospects)

We may collect:

2.2 Service account and relationship data (B2B customers and authorised users)

We may collect:

2.3 Customer Data processed in the Service (Processor role)

Our customers may submit Customer Data into the Service, which may include:

Important: Our customers control what they upload and configure. Customers should avoid uploading special category data (e.g., health information) unless they have a valid lawful basis and appropriate safeguards.

2.4 Data from third parties

We may receive personal data from:

3. How We Use Personal Data (Purposes and Lawful Bases)

3.1 Website data (Controller)

We use Website data to:

3.2 Service account/relationship data (Controller)

We use this data to:

3.3 Customer Data in the Service (Processor)

We process Customer Data only:

As the Controller, the customer is responsible for:

3.4 Aggregated and anonymised data

We may generate aggregated and/or anonymised data from usage of the Website and Service (e.g., feature adoption rates, performance metrics, benchmarking). We use this to:

We do not attempt to re-identify individuals from anonymised datasets.

4. Sharing and Disclosure

We may share personal data with:

Sub-processors (Processor role): Where we process Customer Data, we may use sub-processors to help deliver the Service. We remain responsible for their compliance as required by applicable law and our Data Processing Addendum.

We do not sell personal data.

5. International Transfers

We may transfer personal data outside the UK and/or EEA (for example, where a supplier hosts data internationally).

Where we do, we put appropriate safeguards in place, such as:

For transfers to the US, we may rely on the UK-US Data Bridge (UK Extension to the EU-US Data Privacy Framework) where the recipient participates.

6. Security

We implement appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration or misuse. Measures may include encryption in transit, access controls, least-privilege permissions, logging and monitoring, and regular security review.

No system is completely secure. You are responsible for maintaining the confidentiality of your login credentials and ensuring your users do the same.

7. Retention

7.1 Website data

We retain Website personal data for as long as necessary for the purposes described above, including:

7.2 Service data (Controller data)

We retain account, billing and support records for the duration of the customer relationship and for up to seven (7) years as required for tax and financial record-keeping, after which they are securely deleted.

7.3 Customer Data (Processor data)

We retain Customer Data for the duration of the customer subscription.

Upon termination/expiry of the subscription:

Backups: Customer Data may remain in secure backups for up to twelve (12) months as part of our standard backup and disaster recovery cycles, after which it is permanently overwritten or erased.

8. Your Rights and How to Exercise Them

8.1 If you are a Website visitor, prospect, or an authorised user (Controller data)

Depending on your jurisdiction, you may have rights including: access, rectification, erasure, restriction, objection, portability, withdrawal of consent, and not to be subject to solely automated decision-making (where relevant).

To exercise rights in relation to Controller data, contact us using Section 1.3.

8.2 If you are an end customer/recipient using a portal, tracking link or public form (Customer Data)

In most cases, the florist/business you are dealing with is the Controller. Please contact them first to exercise your rights.

If you contact us directly, we may redirect you to the relevant Controller or assist them as required by law.

8.3 Automated decision-making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect you.

8.4 Complaints

If you have a concern, please contact us first at privacy [at] digitalflorists.com so we can investigate and respond.

You also have the right to complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We encourage you to contact us first.

9. Public Features (Portals, Tracking Links, Public Forms) - Important Information

10. Cookies and Similar Technologies

We use cookies and similar technologies on the Website and within the Service. For details, please see our Cookie Policy and our cookie preference tools (where available).

11. Changes to This Notice

We may update this Notice from time to time. We will post the updated version and change the "Last updated" date. Material changes will be notified via the Website or Service.

12. Contact

For privacy queries, requests or complaints, contact:

Email: privacy [at] digitalflorists.com
Post: Digital Florists Ltd, 7 Booker Ave, Liverpool L18 4QY, United Kingdom