• Lietuvių
  • English
  • Беларуская

Processing of personal data

Updated 1 August 2026

ROSES24.LT Privacy Policy

How ONE Management OÜ collects, uses, stores, and protects the personal data of ROSES24.LT visitors and customers.

1. General provisions

This Privacy Policy (the Policy) explains how ONE Management OÜ processes the personal data of visitors and customers using the ROSES24.LT website, online shop, customer service channels, and related services.

The Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act, the Lithuanian Law on Legal Protection of Personal Data, and other applicable legislation.

ROSES24.LT accepts orders for flowers and other products for collection from partner pickup points in Lithuania. Orders are prepared in Estonia and transported to Lithuania.

2. Personal data controller

The controller of personal data is:

CompanyONE Management OÜ
Registry code14770859
VAT numberEE102363069
Registered addressTartu mnt 24, 10115 Tallinn, Estonia

3. Categories of data processed

Depending on the service used, we may process:

  • first and last name, telephone number, email address, billing address, and information required for order collection;
  • the details of the customer and recipient, as well as card text or order notes;
  • account information: username, encrypted password, settings, and loyalty programme details;
  • order and purchase history: products, amounts, dates, collection methods, discounts, and bonuses;
  • payment information: method, status, amount, currency, and transaction identifier. We do not store full payment card details;
  • customer service enquiries, correspondence, reviews, complaints, and their outcomes;
  • recordings of telephone calls after the caller has been informed in advance;
  • technical data: IP address, cookie identifiers, browser and device information, visited pages, and actions on the website;
  • other information voluntarily provided in connection with an order or enquiry.
If the customer provides another person’s data, such as the flower recipient’s details, the customer confirms that the data are accurate and may be provided for order fulfilment. Recipient data are used only for order collection and directly related communication unless another legal basis applies.

4. Purposes and legal bases for processing

We process personal data for the following purposes:

  • accepting, receiving payment for, preparing, transporting, and handing over orders and sending status notifications – to enter into and perform a contract (Article 6(1)(b) GDPR);
  • customer service, returns, and complaint handling – to perform a contract and on the basis of our legitimate interest in providing high-quality service (Article 6(1)(b) and (f));
  • processing payments and refunds and meeting accounting and tax obligations – to perform a contract and comply with a legal obligation (Article 6(1)(b) and (c));
  • organising transport and logistics – to perform a contract;
  • operating and securing the websites, preventing fraud, and improving services – on the basis of legitimate interests (Article 6(1)(f));
  • administering the loyalty programme – to perform its terms and maintain customer relationships;
  • personalised offers and direct marketing – on the basis of consent or, where permitted by law, legitimate interests. You may always opt out of marketing;
  • recording calls for quality control, staff training, and dispute resolution – on the basis of legitimate interests (Article 6(1)(f));
  • establishing, exercising, or defending legal claims – on the basis of legitimate interests.

We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Limited segmentation for marketing and offer personalisation does not produce such effects.

5. Recording telephone calls

Calls with customer service may be recorded for service quality control, staff training, and clarification of circumstances relating to an order, complaint, or dispute.

Before recording begins, the caller hears a notice explaining that the call is being recorded and for what purposes. Separate consent is not requested. The legal basis is ONE Management OÜ’s legitimate interest in ensuring service quality and protecting legal claims (Article 6(1)(f) GDPR).

Recordings are accessible only to authorised employees and service providers who require access to perform their duties. Recordings are retained for no longer than one year and may be deleted earlier once the purpose has been achieved. A recording related to a specific complaint, dispute, or proceeding may be kept longer until the relevant process is finally concluded.

6. Cookies and technical data

The website uses cookies and similar technologies:

  • essential cookies enable login, the shopping cart, language selection, security, and core functions;
  • analytics and preference cookies help us understand website use and improve it;
  • marketing cookies may be used to measure and personalise advertising.

We request consent for non-essential cookies. You can change your choices in the website’s cookie settings. Server logs may store an IP address, visit time, requested page, browser, operating system, and referring address for security and technical troubleshooting.

7. Recipients of personal data

Where necessary, personal data may be received by:

  • transport and logistics partners and partner pickup points;
  • payment service providers, including Montonio Finance UAB, Revolut Bank UAB, PayPal (Europe) S.à r.l. et Cie, S.C.A., and other payment partners used by us;
  • banks and financing providers;
  • IT, hosting, data storage, CRM, email, SMS, analytics, and cybersecurity providers;
  • accountants, auditors, legal advisers, and debt collection providers;
  • public and law-enforcement authorities where disclosure is required by law.

Processors may use personal data only according to our instructions and agreements. Certain partners, such as banks and payment service providers, may act as independent controllers under their own privacy policies.

8. Transfers outside the EEA

We prefer to process personal data within the European Union and the European Economic Area. If a provider processes data outside the EEA, the transfer is made using safeguards provided by the GDPR, such as European Commission adequacy decisions, standard contractual clauses, and additional safeguards where necessary.

9. Retention periods

Personal data are retained only for as long as necessary for the processing purpose or required by law. As a general rule:

  • account data – while the account is active and afterwards to the extent necessary to comply with the law or defend claims;
  • order and customer service data – for up to 3 years after the last transaction or enquiry unless a dispute or law requires a longer period;
  • accounting and tax documents – for 7 years or another mandatory period;
  • call recordings – for up to 1 year unless needed longer for a specific complaint, dispute, or proceeding;
  • marketing consent – until withdrawn; minimal opt-out data may be retained to prevent further marketing;
  • technical logs – generally for up to 1 year.

At the end of the retention period, data are deleted or irreversibly anonymised.

10. Data security

We apply appropriate technical and organisational measures, including connection encryption, access-rights management, backups, software updates, confidentiality obligations, and agreements with processors. Access is granted only to persons who require it for their work.

If a personal data breach occurs, we assess the risk and notify the supervisory authority and affected persons where required by the GDPR.

11. Data subject rights

You have the right to:

  • receive information and access your personal data;
  • correct inaccurate data;
  • request erasure where there is no legal basis for continued retention;
  • restrict processing;
  • receive data in a structured, commonly used, machine-readable format where applicable;
  • object to processing based on legitimate interests;
  • opt out of direct marketing at any time;
  • withdraw consent without affecting the lawfulness of processing before withdrawal;
  • lodge a complaint with a competent supervisory authority.
Send requests to [email protected]. To protect your data, we may ask you to verify your identity. We normally respond within one month; where permitted by the GDPR, this period may be extended by a further two months.

12. Direct marketing

Marketing messages are sent with consent or, where permitted by law, to existing customers about similar products and services. Every marketing email includes an opt-out option.

Opting out of marketing does not prevent us from sending order confirmations, transport and collection-readiness notifications, or other service messages.

13. Contacts

For questions about this Policy or personal data processing:

ONE Management OÜ
Tartu mnt 24, 10115 Tallinn, Estonia
Registry code: 14770859
Email: [email protected]

14. Supervisory authorities

Because the controller is established in Estonia, the lead supervisory authority is:

Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon)
Tatari 39, 10134 Tallinn, Estonia
Email: [email protected]
Telephone: +372 5620 2341
Website: www.aki.ee

In Lithuania, you may also contact:

State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija)
L. Sapiegos g. 17, LT-10312 Vilnius, Lithuania
Email: [email protected]
Telephone: +370 5 271 2804
Website: vdai.lrv.lt

15. Changes to this Policy

We may update this Policy when legislation, services, or processing practices change. The current version is published on the relevant website. Material changes will be announced on the website or by another appropriate method.

Last updated: 1 August 2026.

Questions about personal data?

Email us: [email protected]
ROSES24.LT · ONE Management OÜ