ROSES24.LV Privacy Policy
How ONE Management OÜ collects, uses, stores and protects the personal data of ROSES24.LV visitors and customers.
1. General provisions
This Privacy Policy (the Policy) explains how ONE Management OÜ processes the personal data of visitors and customers using the ROSES24.LV website, online store, customer service channels and related services.
The Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act, the Latvian Personal Data Processing Law and other applicable legislation.
2. Personal data controller
The controller of personal data is:
3. Categories of personal data
Depending on the service used, we may process:
- first and last name, telephone number, e-mail address, billing address and information needed to hand over an order;
- the Customer’s and Recipient’s details and the text of a greeting card or order note;
- account data: username, encrypted password, settings and loyalty programme information;
- order and purchase history: goods, amounts, dates, collection methods, discounts and bonuses;
- payment information: payment method, status, amount, currency and transaction identifier. We do not store full payment card details;
- customer support enquiries, correspondence, reviews, claims and their outcomes;
- recordings of telephone conversations after prior notice to the caller;
- technical data: IP address, cookie identifiers, browser and device data, pages visited and actions taken on the website;
- other data voluntarily provided in connection with an order or enquiry.
4. Purposes and legal bases for processing
We process personal data for:
- accepting, receiving payment for, preparing, transporting and handing over orders and providing status updates — to enter into and perform a contract (Article 6(1)(b) GDPR);
- customer service, returns and handling claims — to perform a contract and on the basis of our legitimate interest in providing quality service (Article 6(1)(b) and (f));
- processing payments and refunds and complying with accounting and tax obligations — to perform a contract and comply with a legal obligation (Article 6(1)(b) and (c));
- organising transport and logistics — to perform a contract;
- operating and securing our websites, preventing fraud and improving services — on the basis of legitimate interest (Article 6(1)(f));
- administering the loyalty programme — to perform its terms and maintain customer relationships;
- personalised offers and direct marketing — on the basis of consent or, where permitted by law, legitimate interest. Marketing can always be refused;
- recording calls for quality control, staff training and dispute resolution — on the basis of legitimate interest (Article 6(1)(f));
- establishing, exercising or defending legal claims — on the basis of legitimate interest.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Limited segmentation for marketing and offer personalisation does not produce such effects.
5. Recording telephone conversations
Conversations with customer support may be recorded to monitor service quality, train employees and establish the circumstances of an order, claim or dispute.
Recordings are available only to authorised employees and service providers who need access to perform their duties. Recordings are retained for no longer than one year and may be deleted earlier if the purpose has been achieved. A recording may be retained longer where needed for a specific complaint, dispute or proceeding, until the matter has been finally resolved.
6. Cookies and technical data
The website uses cookies and similar technologies:
- essential cookies provide login, shopping cart, language selection, security and core functions;
- analytics and preference cookies help us understand use of the website and improve it;
- marketing cookies may be used to measure and personalise advertising.
We request consent for non-essential cookies. Choices can be changed in the website’s cookie settings. Server logs may store an IP address, visit time, requested page, browser, operating system and referring address for security and technical troubleshooting.
7. Recipients of personal data
To the extent necessary, personal data may be received by:
- transport and logistics partners and the partner pickup point;
- payment service providers, including Montonio Finance UAB, Revolut Bank UAB, PayPal (Europe) S.à r.l. et Cie, S.C.A., and other payment partners used by us;
- banks and financing providers;
- IT, hosting, data storage, CRM, e-mail, SMS, analytics and cybersecurity providers;
- accountants, auditors, lawyers and debt recovery service providers;
- public and law-enforcement authorities where disclosure is required by law.
Processors may use personal data only in accordance with our instructions and the agreements concluded with them. Certain partners, such as banks and payment providers, may act as independent controllers under their own privacy policies.
8. Transfers outside the EEA
We prefer to process personal data within the European Union and European Economic Area. If a provider processes data outside the EEA, the transfer is protected using safeguards provided by the GDPR, such as an adequacy decision of the European Commission, Standard Contractual Clauses and, where necessary, supplementary safeguards.
9. Retention periods
Personal data is retained only for as long as necessary for the processing purpose or required by law. As a general rule:
- account data — while the account is active and afterwards to the extent needed to comply with law or protect claims;
- order and customer-service information — up to 3 years after the last transaction or enquiry unless a dispute or law requires longer retention;
- accounting and tax documents — 7 years or another mandatory period;
- call recordings — up to 1 year unless needed longer for a specific complaint, dispute or proceeding;
- marketing consent — until withdrawn; minimum opt-out data may be retained to prevent further marketing;
- technical logs — generally up to 1 year.
After the relevant period expires, personal data is deleted or irreversibly anonymised.
10. Security
We apply appropriate technical and organisational measures, including encrypted connections, access-right management, backups, software updates, confidentiality obligations and agreements with processors. Access is granted only to persons who need it for their work.
If a personal data breach occurs, we assess the risk and notify the supervisory authority and affected individuals where required by the GDPR.
11. Rights of the data subject
You have the right to:
- receive information and access your personal data;
- rectify inaccurate data;
- request erasure where there is no legal basis for continued retention;
- restrict processing;
- receive data in a structured, commonly used and machine-readable format where applicable;
- object to processing based on legitimate interest;
- opt out of direct marketing at any time;
- withdraw consent without affecting the lawfulness of earlier processing;
- lodge a complaint with a competent supervisory authority.
12. Direct marketing
Marketing communications are sent with consent or to existing customers concerning similar goods and services where permitted by law. Every marketing e-mail provides an option to unsubscribe.
13. Contact details
For questions about this Policy or personal data processing:
ONE Management OÜ
Tartu mnt 24, 10115 Tallinn, Estonia
Registration number: 14770859
E-mail: [email protected]
14. Supervisory authorities
Because the controller is established in Estonia, the lead supervisory authority is:
Tatari 39, 10134 Tallinn, Estonia
E-mail: [email protected]
Telephone: +372 5620 2341
Website: www.aki.ee
In Latvia, you may also contact:
Elijas iela 17, Rīga, LV-1050, Latvija
E-mail: [email protected]
Telephone: +371 67223131
Website: www.dvi.gov.lv
15. Changes to this Policy
We may update this Policy when legislation, services or processing practices change. The current version is published on the relevant website. Material changes will be communicated on the website or by another appropriate method.
Last updated: 28 July 2026.
