LEGAL

Privacy Policy

We respect your personal data. Learn how we protect it under GDPR. (Greek version is legally binding — this English page is for reference only.)

Last updated: 25 April 2026

This Privacy Policy describes how the Bloom in Box online store collects, uses, stores and protects your personal data, in accordance with the General Data Protection Regulation (GDPR – EU Regulation 2016/679) and Greek law (Law 4624/2019).

1. Data Controller

The data controller for your personal data is:

Business name: [BUSINESS NAME]

VAT no.: [VAT NO.]

Address: [ADDRESS], Kastoria 521 00

Email: [EMAIL]

Phone: [PHONE]

2. Data We Collect

When you use our online store, we may collect the following categories of personal data:

  • Identification details: Full name
  • Contact details: Email address, phone
  • Shipping details: Postal address, city, postcode
  • Payment details: Card type, last 4 digits (full processing handled by the payment provider)
  • Order history: Products, amounts, purchase dates
  • Browsing data: IP address, browser type, pages visited, time spent (via cookies and analytics)

3. Processing Purpose

Your personal data is collected and processed for the following purposes:

  • Order fulfilment: Processing, shipping and delivery of your orders, as well as handling returns
  • Communication: Updates on the status of your order, responses to enquiries and customer service
  • Marketing activities: Sending newsletters and updates about new products or offers, only with your explicit consent
  • Legal obligations: Compliance with tax and accounting obligations under Greek law
  • Service improvement: Analysis of site usage to improve the browsing and shopping experience

5. Data Recipients

Your personal data may be disclosed to the following categories of recipients, only to the extent necessary for the processing purposes:

  • Courier companies: For shipping and delivery of your orders (name, address, phone)
  • Payment providers: For secure processing of electronic payments
  • Hosting services: For the operation and maintenance of the site
  • Accounting office: For compliance with tax obligations

We do not sell, rent or trade your personal data to third parties for advertising or commercial purposes. All third-party recipients are contractually bound to comply with the GDPR and apply appropriate security measures.

6. Data Retention Period

Your personal data is retained only for as long as necessary for the purposes for which it was collected:

  • Order & invoice data: Retained for 5 years after the completion of the transaction, in accordance with tax law
  • Customer account details: Retained for as long as the account remains active. You may request deletion at any time
  • Marketing/newsletter data: Retained until you withdraw your consent
  • Browsing data (cookies): According to the settings defined in our Cookie Policy

After the retention period ends, data is securely deleted or anonymised.

7. Your Rights (GDPR)

Under the General Data Protection Regulation, you have the following rights in relation to your personal data:

Your rights include:

  • Right of access: To know whether and which of your data we process, and to receive a copy
  • Right to rectification: To request correction of inaccurate data or completion of incomplete data
  • Right to erasure: To request deletion of your data, where no lawful reason for retention exists
  • Right to restriction: To request restriction of processing under certain conditions
  • Right to portability: To receive your data in a structured, commonly used format or to request its transfer to another controller
  • Right to object: To object to the processing of your data, particularly for direct marketing purposes
  • Right to withdraw consent: To withdraw your consent at any time, without affecting the lawfulness of processing prior to withdrawal

To exercise any of the above rights, you may contact us at [EMAIL]. We will respond to your request within 30 days of receipt.

8. Cookies

Our site uses cookies and similar technologies to improve the browsing experience, analyse traffic and ensure the correct operation of the online store.

The cookies we use include:

  • Essential cookies: Strictly necessary for the operation of the site (e.g. shopping cart, user login)
  • Analytics cookies: Help us understand how you use the site (e.g. Google Analytics)
  • Marketing cookies: Used to display relevant ads, only with your consent

You can manage your preferences via the cookie banner on your first visit or via your browser settings. For detailed information, please refer to our Cookie Policy.

9. Data Security

We take appropriate technical and organisational measures to protect your personal data from unauthorised access, modification, disclosure or destruction. In particular:

  • SSL/TLS encryption: All communication between your browser and our site is encrypted
  • Secure storage: Data is stored in encrypted systems with controlled access
  • Controlled access: Data is accessible only to authorised personnel, to the extent necessary for performing their duties
  • Secure payments: Electronic payments are processed via certified payment providers (PCI DSS)

Despite the security measures we apply, no data transmission over the internet can be guaranteed 100% secure. In the event of a data breach, we will notify you within the time limits set by the GDPR.

10. Minors

The Bloom in Box online store is intended for adults. We do not knowingly collect personal data from anyone under the age of 18 without parental or guardian consent.

If we become aware that we have collected data from a minor without appropriate consent, we will delete it immediately. If you are a parent or guardian and believe your child has provided us with personal data, please contact us.

11. Changes to the Privacy Policy

We reserve the right to modify this Privacy Policy at any time to reflect changes in our practices or in the law.

In case of material changes:

  • We will update the "Last updated" date at the top of the page
  • We will notify you by email or via a prominent notice on our site
  • Where required by law, we will request your renewed consent

We recommend that you check this page regularly for any updates.

12. Contact & Complaints

For any question, request or concern regarding the processing of your personal data, you can contact us:

Email: [EMAIL]

Phone: [PHONE]

By post: [BUSINESS NAME], [ADDRESS], Καστοριά 521 00

If you believe that the processing of your data violates the GDPR or Greek law, you have the right to lodge a complaint with the Hellenic Data Protection Authority (HDPA):

Hellenic Data Protection Authority (HDPA)

Address: Kifisias Avenue 1-3, 115 23 Athens

Phone: +30 210 6475600

Email: contact@dpa.gr

Website: www.dpa.gr

However, we encourage you to contact us first so that we can try to resolve any issue directly.

Have questions?

If you want to learn more about your rights or how we protect your data, talk to us.

CONTACT