• Latviešu
  • English
  • Русский

Processing of personal data

Updated 28 July 2026

ROSES24.LV Privacy Policy

How ONE Management OÜ collects, uses, stores and protects the personal data of ROSES24.LV visitors and customers.

1. General provisions

This Privacy Policy (the Policy) explains how ONE Management OÜ processes the personal data of visitors and customers using the ROSES24.LV website, online store, customer service channels and related services.

The Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act, the Latvian Personal Data Processing Law and other applicable legislation.

ROSES24.LV accepts orders for flowers and other goods for collection from a partner pickup point in Riga. Orders are prepared in Estonia and transported to Riga.

2. Personal data controller

The controller of personal data is:

CompanyONE Management OÜ
Registration number14770859
VAT numberEE102363069
Registered addressTartu mnt 24, 10115 Tallinn, Estonia

3. Categories of personal data

Depending on the service used, we may process:

  • first and last name, telephone number, e-mail address, billing address and information needed to hand over an order;
  • the Customer’s and Recipient’s details and the text of a greeting card or order note;
  • account data: username, encrypted password, settings and loyalty programme information;
  • order and purchase history: goods, amounts, dates, collection methods, discounts and bonuses;
  • payment information: payment method, status, amount, currency and transaction identifier. We do not store full payment card details;
  • customer support enquiries, correspondence, reviews, claims and their outcomes;
  • recordings of telephone conversations after prior notice to the caller;
  • technical data: IP address, cookie identifiers, browser and device data, pages visited and actions taken on the website;
  • other data voluntarily provided in connection with an order or enquiry.
If a Customer provides another person’s data, such as the Recipient’s details, the Customer confirms that the data is accurate and may be supplied for fulfilment of the order. The Recipient’s data is used only to hand over the order and for directly related communication unless another legal basis applies.

4. Purposes and legal bases for processing

We process personal data for:

  • accepting, receiving payment for, preparing, transporting and handing over orders and providing status updates — to enter into and perform a contract (Article 6(1)(b) GDPR);
  • customer service, returns and handling claims — to perform a contract and on the basis of our legitimate interest in providing quality service (Article 6(1)(b) and (f));
  • processing payments and refunds and complying with accounting and tax obligations — to perform a contract and comply with a legal obligation (Article 6(1)(b) and (c));
  • organising transport and logistics — to perform a contract;
  • operating and securing our websites, preventing fraud and improving services — on the basis of legitimate interest (Article 6(1)(f));
  • administering the loyalty programme — to perform its terms and maintain customer relationships;
  • personalised offers and direct marketing — on the basis of consent or, where permitted by law, legitimate interest. Marketing can always be refused;
  • recording calls for quality control, staff training and dispute resolution — on the basis of legitimate interest (Article 6(1)(f));
  • establishing, exercising or defending legal claims — on the basis of legitimate interest.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Limited segmentation for marketing and offer personalisation does not produce such effects.

5. Recording telephone conversations

Conversations with customer support may be recorded to monitor service quality, train employees and establish the circumstances of an order, claim or dispute.

Before recording begins, the caller hears a notice explaining that the call will be recorded and for what purpose. Separate consent is not requested. The legal basis is ONE Management OÜ’s legitimate interest in ensuring service quality and protecting legal claims (Article 6(1)(f) GDPR).

Recordings are available only to authorised employees and service providers who need access to perform their duties. Recordings are retained for no longer than one year and may be deleted earlier if the purpose has been achieved. A recording may be retained longer where needed for a specific complaint, dispute or proceeding, until the matter has been finally resolved.

6. Cookies and technical data

The website uses cookies and similar technologies:

  • essential cookies provide login, shopping cart, language selection, security and core functions;
  • analytics and preference cookies help us understand use of the website and improve it;
  • marketing cookies may be used to measure and personalise advertising.

We request consent for non-essential cookies. Choices can be changed in the website’s cookie settings. Server logs may store an IP address, visit time, requested page, browser, operating system and referring address for security and technical troubleshooting.

7. Recipients of personal data

To the extent necessary, personal data may be received by:

  • transport and logistics partners and the partner pickup point;
  • payment service providers, including Montonio Finance UAB, Revolut Bank UAB, PayPal (Europe) S.à r.l. et Cie, S.C.A., and other payment partners used by us;
  • banks and financing providers;
  • IT, hosting, data storage, CRM, e-mail, SMS, analytics and cybersecurity providers;
  • accountants, auditors, lawyers and debt recovery service providers;
  • public and law-enforcement authorities where disclosure is required by law.

Processors may use personal data only in accordance with our instructions and the agreements concluded with them. Certain partners, such as banks and payment providers, may act as independent controllers under their own privacy policies.

8. Transfers outside the EEA

We prefer to process personal data within the European Union and European Economic Area. If a provider processes data outside the EEA, the transfer is protected using safeguards provided by the GDPR, such as an adequacy decision of the European Commission, Standard Contractual Clauses and, where necessary, supplementary safeguards.

9. Retention periods

Personal data is retained only for as long as necessary for the processing purpose or required by law. As a general rule:

  • account data — while the account is active and afterwards to the extent needed to comply with law or protect claims;
  • order and customer-service information — up to 3 years after the last transaction or enquiry unless a dispute or law requires longer retention;
  • accounting and tax documents — 7 years or another mandatory period;
  • call recordings — up to 1 year unless needed longer for a specific complaint, dispute or proceeding;
  • marketing consent — until withdrawn; minimum opt-out data may be retained to prevent further marketing;
  • technical logs — generally up to 1 year.

After the relevant period expires, personal data is deleted or irreversibly anonymised.

10. Security

We apply appropriate technical and organisational measures, including encrypted connections, access-right management, backups, software updates, confidentiality obligations and agreements with processors. Access is granted only to persons who need it for their work.

If a personal data breach occurs, we assess the risk and notify the supervisory authority and affected individuals where required by the GDPR.

11. Rights of the data subject

You have the right to:

  • receive information and access your personal data;
  • rectify inaccurate data;
  • request erasure where there is no legal basis for continued retention;
  • restrict processing;
  • receive data in a structured, commonly used and machine-readable format where applicable;
  • object to processing based on legitimate interest;
  • opt out of direct marketing at any time;
  • withdraw consent without affecting the lawfulness of earlier processing;
  • lodge a complaint with a competent supervisory authority.
Requests should be sent to [email protected]. To protect personal data, we may request proof of identity. We normally respond within one month; in cases provided by the GDPR, this period may be extended by a further two months.

12. Direct marketing

Marketing communications are sent with consent or to existing customers concerning similar goods and services where permitted by law. Every marketing e-mail provides an option to unsubscribe.

Opting out of marketing does not prevent us from sending order confirmations, transport and collection notifications or other service messages.

13. Contact details

For questions about this Policy or personal data processing:

ONE Management OÜ
Tartu mnt 24, 10115 Tallinn, Estonia
Registration number: 14770859
E-mail: [email protected]

14. Supervisory authorities

Because the controller is established in Estonia, the lead supervisory authority is:

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
E-mail: [email protected]
Telephone: +372 5620 2341
Website: www.aki.ee

In Latvia, you may also contact:

Data State Inspectorate of Latvia (Datu valsts inspekcija)
Elijas iela 17, Rīga, LV-1050, Latvija
E-mail: [email protected]
Telephone: +371 67223131
Website: www.dvi.gov.lv

15. Changes to this Policy

We may update this Policy when legislation, services or processing practices change. The current version is published on the relevant website. Material changes will be communicated on the website or by another appropriate method.

Last updated: 28 July 2026.

Questions about your personal data?

Write to us at [email protected]
ROSES24.LV · ONE Management OÜ