• Eesti
  • Русский
  • English

Privacy Policy

ROSES.EE

Privacy Policy

Processing and protection of the personal data of ROSES.EE online store customers

Data controller
ONE MANAGEMENT OÜ
Registration number: 14770859
Address: Tartu mnt 24, Tallinn, Harju County, Estonia
Telephone: +372 54 50 12 19
Email: [email protected]

1. General provisions

ONE MANAGEMENT OÜ processes the personal data of ROSES.EE online store customers only to the extent necessary to accept and fulfil orders, process payments and refunds, arrange delivery, provide customer support, comply with accounting and tax obligations, ensure security and maintain the technical operation of the online store.

ONE MANAGEMENT OÜ may disclose personal data to authorised service providers only to the extent necessary for the performance of a specific function.

Such providers may include payment and financial institutions, transport and courier partners, IT and POS providers, technical infrastructure providers and accounting service providers.

2. Payment and financial service providers

For the processing of payments and refunds, ROSES.EE may use payment and financial service providers, including Montonio Finance UAB, Revolut Payments UAB, PayPal and other payment service providers.

Such providers receive only the data required to process a payment transaction, identify a payment, issue a refund and comply with applicable financial regulatory requirements. This data may include the payer’s name, payment amount, transaction details, payment reference, payment details and other information required to process the payment or refund.

Payment and financial service providers do not receive access to complete operational information about an order and its delivery, including the recipient’s address, the recipient’s telephone number, the contents of the order, order comments, route information or internal delivery data, unless such disclosure is required for a specific payment transaction.

3. POS and IT service providers

To support sales, accounting and the operation of the ROSES.EE online store, ROSES.EE may use POS and IT systems, including Poster POS and other technical services.

When such services are used, data required for the technical operation of the system, sales accounting, order placement, transaction processing and internal control may be processed.

POS and IT service providers do not receive access to customers’ personal data beyond what is necessary for the operation of the relevant service.

4. Transfers outside the European Union and the European Economic Area

If individual service providers process personal data outside the European Union or the European Economic Area, such transfers take place only where there is an appropriate legal basis under the GDPR and suitable safeguards are in place.

Such safeguards may include a data processing agreement, the European Commission’s Standard Contractual Clauses, an adequacy decision or other applicable personal data protection mechanisms.

5. Personal data processed

ROSES.EE may process the following personal data:

  • the customer’s first and last name;
  • the recipient’s name and contact details, if provided when placing an order;
  • telephone number;
  • email address;
  • delivery address;
  • data required to fulfil the order;
  • the value of goods and purchase history;
  • customer support data;
  • bank account number or other payment details required to issue a refund;
  • IP address;
  • cookies;
  • device and browser data;
  • data required to ensure security and prevent misuse.

6. Purposes of processing personal data

Personal data is processed for the following purposes:

  • accepting, processing and fulfilling orders;
  • arranging delivery;
  • communicating with the customer and/or the order recipient;
  • processing payments and refunds;
  • providing customer support;
  • complying with accounting and tax obligations;
  • resolving disputes and complaints;
  • ensuring the security of customers, employees, goods and property;
  • ensuring the technical operation of the online store;
  • analysing website performance and visitor statistics;
  • improving service quality and the product range;
  • sending marketing communications where the customer has given consent.

7. Legal bases for processing

Personal data is processed on the following legal bases:

  • performance of a contract with the customer — Article 6(1)(b) GDPR;
  • compliance with legal obligations — Article 6(1)(c) GDPR;
  • the company’s legitimate interests — Article 6(1)(f) GDPR;
  • the customer’s consent to marketing or the use of non-essential cookies — Article 6(1)(a) GDPR.

8. Recipients of personal data

Personal data may be disclosed to the following categories of recipients:

  • ROSES.EE customer support — to the extent necessary to process the order and communicate with the customer;
  • transport and courier partners — to the extent necessary to deliver the order, including the name, telephone number, email address and delivery address;
  • payment and financial institutions, including Montonio Finance UAB, Revolut Payments UAB, PayPal and other payment service providers — to the extent necessary to process payments and refunds;
  • POS and IT service providers, including Poster POS and other technical services — to the extent necessary to support sales, accounting, the online store and related systems;
  • accounting service providers — only to the extent necessary to comply with accounting and tax obligations.

Accounting service providers do not receive access to operational delivery data, such as the recipient’s address, the recipient’s telephone number, the contents of the order, order comments or route information, unless such access is required to fulfil a specific accounting or legal obligation.

9. Data security

ROSES.EE applies technical and organisational measures to protect personal data against unauthorised access, alteration, disclosure, loss or destruction.

Access to personal data is granted only to authorised persons and only to the extent necessary for them to perform their duties or provide the relevant service.

Service providers that process personal data on behalf of ROSES.EE are required to comply with the GDPR and ensure an appropriate level of data protection.

10. Data retention periods

Personal data is retained only for as long as necessary to achieve the purposes of processing or for the period required by law.

Retention periods:

  • customer account data — until the account is deleted;
  • order data for orders placed without an account — up to 3 years, unless longer retention is required to resolve a dispute or protect the company’s rights;
  • accounting and tax data — 7 years;
  • data relating to complaints and disputes — until the dispute has been resolved or the applicable limitation period has expired;
  • marketing data — until consent is withdrawn;
  • technical data and cookies — in accordance with the cookie settings and the retention periods of the relevant tools.

11. Automated decision-making and profiling

ROSES.EE does not use automated decision-making that produces legal or other similarly significant effects for the customer.

Analysis of purchasing behaviour may be used in aggregated form for statistics and to improve the product range, service quality and operation of the online store.

12. Marketing

Marketing communications are sent only with the customer’s consent or on another lawful basis provided for by applicable law.

The customer may opt out of marketing communications at any time by using the unsubscribe link in an email or by sending a request to [email protected].

The customer has the right to object at any time to the processing of their personal data for direct marketing purposes.

13. Cookies

ROSES.EE may use cookies and similar technologies to ensure the operation of the website, analyse traffic, improve the user experience and conduct marketing activities.

Cookies may be:

  • strictly necessary;
  • analytical;
  • functional;
  • marketing cookies.

Non-essential cookies are used only with the user’s consent where such consent is required by applicable law.

Users can change their cookie settings in their browser or through the consent settings on the website, where this functionality is available.

14. Customer rights

The customer has the right to:

  • access their personal data;
  • request the correction of inaccurate data;
  • request the deletion of data;
  • request the restriction of processing;
  • object to the processing of data;
  • request data portability;
  • withdraw consent where processing is based on consent;
  • lodge a complaint with a supervisory authority.

Requests concerning the processing of personal data may be sent to: [email protected].

A response will be provided within one month of receipt of the request, unless a different period is provided for by applicable law.

15. Complaints

Complaints and requests concerning the processing of personal data may be submitted to ROSES.EE:

ONE MANAGEMENT OÜ
Email: [email protected]
Telephone: +372 54 50 12 19

The customer also has the right to contact the supervisory authority:

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Website: www.aki.ee
Additional section

Audio and video recording

16. Video surveillance

Video surveillance is in operation in the ROSES.EE retail premises at Tartu mnt 24, Tallinn.

Video surveillance is used to ensure the safety of customers, employees, goods and property, prevent theft and other offences, and resolve potential disputes relating to customer service, the handover of orders or other incidents.

The legal basis for processing is the company’s legitimate interest — Article 6(1)(f) GDPR.

Access to video recordings is restricted to authorised persons. Recordings are retained for a limited period and automatically deleted at the end of the established retention period, unless longer retention is required to investigate an incident, resolve a dispute or comply with a legal obligation.

17. Audio recording

In individual cases and only where necessary, ROSES.EE may record audio in customer service areas or during telephone conversations with customer service.

Audio recordings may be used to ensure security, prevent offences, monitor service quality and resolve disputes.

If a telephone conversation is recorded, the customer will be informed of the recording before the conversation begins.

Audio recording is not carried out in rest areas, toilets, changing rooms or other locations where a person has a heightened expectation of privacy.

GDPR

Legitimate Interest Assessment for Video Surveillance at ONE MANAGEMENT OÜ

18. Identification of the legitimate interest

The purposes of video surveillance are:

  • ensuring the security of property, goods, customers and employees;
  • preventing and investigating incidents, including theft, property damage and conflicts;
  • resolving customer disputes relating to orders, service, the handover of goods or delivery.

Legal basis: Article 6(1)(f) GDPR — the company’s legitimate interest.

Justification:

  • retail and online trade involve risks of losses, theft, errors and conflicts;
  • in the event of a customer dispute or incident, the company may require an objective record of events;
  • video surveillance helps protect the rights of the company, its employees, customers and third parties.

19. Necessity of processing

Video surveillance may be used in the following areas:

  • retail area — to record the actions of customers and employees and prevent theft and disputes;
  • corridors, storage areas and cold rooms — to protect stock and prevent unauthorised access;
  • order preparation area — to monitor order fulfilment quality and resolve potential disputes;
  • exit and goods handover area — to record the handover of goods to customers and couriers.

Alternative measures, such as physical security or logbooks, do not always make it possible to reconstruct the circumstances of an incident objectively.

20. Data minimisation

ROSES.EE uses video surveillance only in areas where it is necessary for the stated purposes.

Cameras do not cover rest areas, toilets, changing rooms or other areas where a person has a heightened expectation of privacy.

Access to recordings is restricted. Where necessary, recordings may be viewed only by authorised persons.

21. Impact on data subjects

ROSES.EE takes into account the right of customers, employees and other persons to respect for their private life.

Potential interference with privacy is limited by the following measures:

  • displaying video surveillance notices;
  • using video surveillance only in work, retail and storage areas;
  • a limited retention period for recordings;
  • restricted access to recordings;
  • using recordings only for the stated purposes.

22. Balancing of interests

The company’s interests:

  • protecting property and goods;
  • preventing losses;
  • ensuring the safety of staff and customers;
  • resolving conflicts and complaints;
  • protecting the company’s rights in the event of disputes.

The interests of data subjects:

  • the right to respect for private life;
  • the right to the protection of personal data;
  • the right to transparent information about the processing of data.
Conclusion: taking into account the limited surveillance areas, limited retention period, video surveillance notices and access controls, the processing of data through video surveillance is proportionate to the stated purposes. The company’s legitimate interest in ensuring security and protecting its rights outweighs the limited interference with the rights of data subjects.

23. Final conclusion

Video surveillance at ONE MANAGEMENT OÜ:

  • is used for specific and lawful purposes;
  • is limited to necessary areas;
  • is carried out in accordance with the principles of necessity, proportionality and data minimisation;
  • is carried out in compliance with the GDPR and with respect for the rights of data subjects.

Questions about the processing of personal data

Please send your request to the data controller, ONE MANAGEMENT OÜ.

[email protected]