Privacy Policy

Who we are

The website florariaazalee.ro and the online shop azalee.ro (together, the "Site") are operated by: Floraria azalee.ro SRL Registered office: Calea Cristești 117, Camera 3, Holboca, județul Iași, Romania Shop and workshop: Strada Ion Creangă 7, 700320 Iași, Romania Trade Register number: J22/3139/2019 Sole registration code (CUI): 41731440 Email: contact@florariaazalee.ro Phone: +40 757 908 508 Website: https://florariaazalee.ro Our opening hours are published in the contact panel of the Site.

About this policy

This policy explains what personal data we collect when you use florariaazalee.ro, why we use it, with whom we share it, how long we keep it and what rights you have. The controller of the data is the company named above. We have not appointed a data protection officer. Every question about personal data is handled at contact@florariaazalee.ro. The rights described here come from Regulation (EU) 2016/679 (GDPR) and from Romanian data protection law. Your rights and how to exercise them are set out in more detail on our GDPR page.

The data we collect

Data you give us: - identity and contact details: first name, last name, email address, phone number - billing details: country, county, city, address and, if you order as a company, the CUI and the Trade Register number - delivery details: the recipient's first name, last name and phone number, the delivery address, the delivery date and time slot, delivery notes, and whether you want to remain anonymous to the recipient - account details: your password, held by Google Firebase Authentication and never stored by us in readable form; your saved addresses; your language and theme preference - content you write: the greeting card message, order notes, and the free text you type into the AI assistant - recordings: the video greeting you record, if you use that option Data created by your use of the Site: - order data: products, quantities, prices, payment method, payment status, order status history, tracking code, invoice - loyalty data: your point balance and the points reserved for an order - reminder dates: the day and the month of a date you asked to be reminded about; we deliberately do not store the year - technical data: IP address, browser and device information, request time, the pages you request, cookie identifiers Data from third parties: - when you sign in with Google or Facebook, we receive the name and the email address associated with that account - when you pay by card, our payment provider tells us whether the payment succeeded, and gives us a reference for it. We never receive your card number.

Why we use your data, and on what legal basis

To perform the contract with you (art. 6(1)(b) GDPR): - taking, preparing, delivering and invoicing your order - sending order status notifications by email or SMS, when you choose those channels - creating and running your account, your saved addresses and your loyalty points - storing and delivering the video greeting you attached to an order - answering your questions and handling complaints To comply with legal obligations (art. 6(1)(c) GDPR): - issuing, storing and transmitting invoices, including through the national RO e-Factura system - accounting and tax records - consumer protection obligations For our legitimate interests (art. 6(1)(f) GDPR): - keeping the Site secure and preventing abuse, automated attacks and fraud - keeping records of orders and communications in order to establish or defend legal claims - aggregated internal statistics about how the shop is used, in order to improve it - reporting each completed sale to Google, so that we can measure how many orders our advertising produces. This report leaves our server and happens whether or not you accepted the cookie banner With your consent (art. 6(1)(a) GDPR): - analytics cookies and the measurement they enable - date reminder emails, when you ask for them You can withdraw consent at any time. Withdrawing it does not affect what was done before.

What you must give us, and what is optional

Some data is necessary in order for us to sell you flowers. Giving it is not a legal obligation, but it is a requirement of the contract: without it we cannot accept the order. What we need in order to complete a sale: the billing name and contact details we have to put on the invoice, and a delivery address with a name and a phone number for the person who receives the flowers. If you do not give us these, we cannot take the order. Everything else is optional, and refusing it costs you only that one feature: - an account: you can order as a guest instead - saved addresses: you can type the address each time - a date reminder: without the date, we simply do not remind you - a video greeting: the order is delivered without it - the greeting card message and the order notes: leave them empty if you prefer Refusing anything on this second list has no other consequence. It does not change the price, the delivery or your rights.

Cookies and analytics

The Site uses cookies that are strictly necessary for it to work, and, only if you accept them, analytics cookies. We use Google Analytics 4 to understand, in aggregate, how the shop is used, and Google Ads to measure our advertising. In your browser both run with Google Consent Mode: until you accept, analytics and advertising storage are denied and no measurement cookies are set. There is one measurement that does not depend on your answer. When an order is paid, our server reports the sale to Google, so that we can see how many orders our advertising produced. That report leaves our server, not your browser, and it happens whether you accepted or refused the banner. We do it on the basis of our legitimate interest in knowing what our advertising brings us, and you can object to it at contact@florariaazalee.ro. Our Cookie Policy explains which cookies the Site uses and how you choose. You can reopen the question at any time from the "Cookie settings" button in the footer.

Card payments

Card payments are processed by Viva.com, on their own secure payment page. Your card details are entered on that page and are never transmitted to us or stored by us. We receive only the outcome of the payment and a reference number we use to reconcile the order. Viva.com acts as an independent controller for the payment data it processes, under its own privacy policy and under the rules of the card schemes.

Invoicing

Invoices are issued through Oblio, an invoicing service provider acting as our processor. To issue an invoice we transmit the billing details of the order, the ordered items and the amounts. Where the law requires it, the invoice is also transmitted to the national RO e-Factura system operated by ANAF. Invoices and the data they contain are kept for the period required by accounting and tax law.

Emails and SMS

Transactional emails and SMS messages are sent through Brevo, acting as our processor. These messages are: the account verification email, the password reset email, the order confirmation, the order status notifications you asked for, the payment link, the video greeting delivery and, if you enabled them, the date reminders. We do not send marketing newsletters from the Site.

The AI assistant

The Site offers an assistant that recommends products based on what you tell it: the occasion, the recipient, preferred flowers or colours, a budget and a short free text. Your answers and that free text are sent to OpenAI, which generates the recommendation, together with the list of products currently available in our catalogue. Your name, your email address, your phone number, your addresses and your order history are never sent to the assistant. Requests are checked automatically before being sent. Please do not type personal data about yourself or about other people into the assistant. It is a tool for choosing flowers, not a channel for personal information. OpenAI processes the request in the United States. This transfer does not currently rest on the same contractual safeguard as our other suppliers: no data processing agreement is in place for it and no Chapter V instrument covers it. That is why the caution above matters, and in particular why you should not write health details or details about other people.

Video greetings

If you record a video greeting, the recording is stored in Google Cloud Storage, in the European Union, and is accessible through a private link and a QR code delivered with the order. Anyone who has that link can view the recording while it is live. Until the order is delivered the recording is yours: you can delete it and upload another as often as you like. Delivery opens a fixed window - the recording stays available for 48 hours and can be downloaded a limited number of times. The recording is deleted automatically at the end of that window and, if the order never reaches an end, no later than 30 days after it is created. Its record is removed entirely at most 60 days after deletion. You can also delete a recording yourself, from your account, at any moment. You are the one who decides what to record. If other people appear in the recording, make sure they agree to it.

Date reminders

If you ask us to remind you about a date, we store the day and the month of that date, linked to your account, together with the year in which a reminder was last sent, so that we do not send it twice. We deliberately do not store the year of the date itself, and we do not ask who the date is about. You can switch a reminder off or delete it at any time from your account, and you can turn the feature off entirely.

If someone sent you flowers

This section is for the person who receives a delivery, not for the person who ordered it. If flowers were sent to you, we hold your first name and last name, your phone number, the delivery address, the delivery date and time slot, and the message written on the card, if there is one. None of it came from you. The buyer gave it to us so that we could bring the flowers to your door, and that is the only thing we use it for. We never contact you for anything else. Updates about the order go to the buyer, not to you. We do not add you to any list, we do not send you marketing and we do not build a profile about you. Your data stays with the order it belongs to, for the same period as the rest of that order, and it is removed or anonymised together with it. You have the same rights as anyone else: to ask what we hold about you, to have it corrected, to object to it and, where nothing obliges us to keep it, to have it deleted. Write to contact@florariaazalee.ro with the delivery address and roughly when the delivery happened, so that we can find the order.

Reviews

The reviews published on the Site are the reviews left for our business on Google. We import them and publish a selection of them, with a first name and an initial in place of the author name, together with the rating, the text and the date. We shorten the name at the moment we import it, so the Site never shows the full name the author used on Google. We keep a review for 3 years from the date it was written, and then remove it. We do not collect reviews through a form on the Site.

Delivery map

To plan deliveries, our internal administration tool converts delivery addresses into map coordinates using Mapbox, acting as our processor. Only the address and the locality are sent for this purpose.

Security and prevention of abuse

We protect the Site and your data with technical and organisational measures: - all traffic is encrypted in transit (HTTPS) - the session cookie is encrypted and can be read only by our servers - passwords are held by Google Firebase Authentication and are never visible to us - access to the administration tools is limited to authorised persons and requires a verified account - data is stored in Google Cloud infrastructure in the European Union To stop automated abuse, our servers count requests per IP address. An IP address that exceeds the limits is blocked temporarily, for at most 7 days. This processing is based on our legitimate interest in keeping the service available. Our servers also keep technical logs of the requests they serve, for 30 days. An address is shortened before it is written to a log line, so what is kept points to a network rather than to a household or a person.

Anonymisation and aggregated data

Wherever we can do our work without knowing who you are, we work with anonymous or aggregated data. - Our internal statistics about the shop, such as turnover, the number of orders and the best-selling products, are aggregate figures. They contain no personal data and cannot be traced back to you. - Audience measurement, when you accept it, reports visits in aggregate. It is used to improve the shop, never to identify you. - The IP addresses used to stop automated abuse are never kept in our database. A block lasts at most 7 days, on the server that handled the request. What reaches our technical logs is a shortened address, kept for 30 days, which points to a network rather than to a household. - For a date reminder we keep only the day and the month, never the year, so the date cannot tell anyone an age or the year of an event. - An order placed without an account is linked to an anonymous identifier, not to a personal profile. Anonymous data is no longer personal data, so the rights described here do not apply to it: once data can no longer be linked to you, we can no longer find it for you either.

Who we share your data with

We do not sell personal data and we do not share it for advertising by third parties. We share it only with the suppliers we need in order to run the shop, each acting under a contract and only for what we ask them to do: - Google Ireland Limited / Google Cloud (Firebase): hosting, database, file storage, authentication, and Google Analytics if you accepted analytics cookies. Our infrastructure runs in the European Union. - Google Ireland Limited (Google Ads): measuring our advertising. The completed sales we report from our server go here as well, as described in the cookies section above. - Cloudflare: delivery of the Site's images through a content delivery network. - Brevo: transactional emails and SMS. - Viva.com: card payments, as an independent controller. - Oblio: issuing and storing invoices. - OpenAI: generating the AI assistant's recommendations. - Mapbox: converting delivery addresses into map coordinates. We also disclose data: - to our accountants and auditors, and to our legal advisers where necessary - to public authorities, when the law obliges us to - to a buyer or successor, in the event of a reorganisation or transfer of the business, under the same protection

Transfers outside the European Union

Our infrastructure, our database and our files are located in the European Union. Some of the suppliers listed above are established in the United States or process data there: Google, Cloudflare and Mapbox for parts of their service, and OpenAI for the AI assistant. For Google, Cloudflare and Mapbox, these transfers take place under the safeguards provided by Chapter V of the GDPR: the European Commission's Standard Contractual Clauses, and, where the supplier is certified, the EU-US Data Privacy Framework. OpenAI is the exception, and we prefer to say so plainly. The text you type into the AI assistant reaches the United States without one of those instruments in place today. That is why the assistant asks you to write about flowers only, and not about health or about other people. Everything else on this page travels under the safeguards described above. You can ask us for details of the safeguards that apply to a specific supplier, at contact@florariaazalee.ro.

How long we keep your data

- Orders with an invoice: for the period Romanian accounting law requires accounting documents to be kept, counted from the date the invoice was issued. We do not delete an invoiced order earlier, because the law does not let us. - Orders without an invoice: 3 years from the delivery date, or from the order date if the order was never delivered. - Account data: while your account exists. If you delete it, or ask us to, we delete the account and its content, except what we must keep for legal reasons. An account that has been dormant for 3 years after its last order is deleted by us. - Saved addresses, preferences, loyalty balance and reminders: with the account. - Shopping cart: a cart kept without an account is deleted 90 days after it was last touched. - Video greetings: 48 hours from the delivery of the order, and at most 30 days from creation if that order is never delivered; their record is purged at most 60 days after deletion. - Reviews: 3 years from the date of the review. - Technical logs and security blocks: at most 7 days for blocked IP addresses; server logs are kept for 30 days, with the address shortened. - The cookie consent record: 1 year. - Correspondence with us: for as long as needed to handle the matter, and afterwards for the period in which a claim can still be made. When an account reaches the end of its period but one of its orders is still inside the accounting period above, we do not delete that order. We remove the identity from it and keep only the financial content.

Your rights

You have the right to: - be informed about how we use your data - obtain access to the data we hold about you - have inaccurate data corrected - have your data erased, where there is no legal reason for us to keep it - ask us to restrict processing in certain situations - receive the data you gave us in a portable format, and have it transmitted to another controller - object to processing based on our legitimate interests - withdraw consent at any time, where processing is based on consent Two of them you can exercise yourself, without writing to anyone. In the "My data" tab of your account you can download everything we hold about you as a file, and you can delete your account. The deletion is immediate and it takes your addresses, preferences, points, reminders and video greetings with it. For anything else, write to contact@florariaazalee.ro. We answer within one month, and we tell you if we need an extension. The procedure is described on our GDPR page. If you consider that we handle your data unlawfully, you can complain to the National Supervisory Authority for Personal Data Processing (ANSPDCP), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, 010336 Bucuresti, www.dataprotection.ro, anspdcp@dataprotection.ro. You also have the right to an effective judicial remedy.

Automated decisions

We do not take decisions with legal or similarly significant effects about you by automated means alone. The AI assistant recommends products and the abuse protection blocks abnormal traffic; neither decides anything about your rights, and both can be reviewed by a person if you contact us.

Children

The Site is not intended for children. We do not knowingly create accounts for persons under 16 and we do not knowingly collect their data. If you believe a child has given us personal data, write to contact@florariaazalee.ro and we will remove it.

Changes to this policy

We update this policy when the shop or the law changes. The version published here is the version in force, and its date is shown below. For significant changes we announce the update on the Site. Last updated: 1 September 2026

Contact

For any question about your personal data, or to exercise your rights: Email: contact@florariaazalee.ro Phone: +40 757 908 508 Address: Strada Ion Creangă 7, 700320 Iași, Romania