ROSES24.LT Privacy Policy
How ONE Management OÜ collects, uses, stores, and protects the personal data of ROSES24.LT visitors and customers.
1. General provisions
This Privacy Policy (the Policy) explains how ONE Management OÜ processes the personal data of visitors and customers using the ROSES24.LT website, online shop, customer service channels, and related services.
The Policy has been prepared in accordance with Regulation (EU) 2016/679 (GDPR), the Estonian Personal Data Protection Act, the Lithuanian Law on Legal Protection of Personal Data, and other applicable legislation.
2. Personal data controller
The controller of personal data is:
3. Categories of data processed
Depending on the service used, we may process:
- first and last name, telephone number, email address, billing address, and information required for order collection;
- the details of the customer and recipient, as well as card text or order notes;
- account information: username, encrypted password, settings, and loyalty programme details;
- order and purchase history: products, amounts, dates, collection methods, discounts, and bonuses;
- payment information: method, status, amount, currency, and transaction identifier. We do not store full payment card details;
- customer service enquiries, correspondence, reviews, complaints, and their outcomes;
- recordings of telephone calls after the caller has been informed in advance;
- technical data: IP address, cookie identifiers, browser and device information, visited pages, and actions on the website;
- other information voluntarily provided in connection with an order or enquiry.
4. Purposes and legal bases for processing
We process personal data for the following purposes:
- accepting, receiving payment for, preparing, transporting, and handing over orders and sending status notifications – to enter into and perform a contract (Article 6(1)(b) GDPR);
- customer service, returns, and complaint handling – to perform a contract and on the basis of our legitimate interest in providing high-quality service (Article 6(1)(b) and (f));
- processing payments and refunds and meeting accounting and tax obligations – to perform a contract and comply with a legal obligation (Article 6(1)(b) and (c));
- organising transport and logistics – to perform a contract;
- operating and securing the websites, preventing fraud, and improving services – on the basis of legitimate interests (Article 6(1)(f));
- administering the loyalty programme – to perform its terms and maintain customer relationships;
- personalised offers and direct marketing – on the basis of consent or, where permitted by law, legitimate interests. You may always opt out of marketing;
- recording calls for quality control, staff training, and dispute resolution – on the basis of legitimate interests (Article 6(1)(f));
- establishing, exercising, or defending legal claims – on the basis of legitimate interests.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects. Limited segmentation for marketing and offer personalisation does not produce such effects.
5. Recording telephone calls
Calls with customer service may be recorded for service quality control, staff training, and clarification of circumstances relating to an order, complaint, or dispute.
Recordings are accessible only to authorised employees and service providers who require access to perform their duties. Recordings are retained for no longer than one year and may be deleted earlier once the purpose has been achieved. A recording related to a specific complaint, dispute, or proceeding may be kept longer until the relevant process is finally concluded.
6. Cookies and technical data
The website uses cookies and similar technologies:
- essential cookies enable login, the shopping cart, language selection, security, and core functions;
- analytics and preference cookies help us understand website use and improve it;
- marketing cookies may be used to measure and personalise advertising.
We request consent for non-essential cookies. You can change your choices in the website’s cookie settings. Server logs may store an IP address, visit time, requested page, browser, operating system, and referring address for security and technical troubleshooting.
7. Recipients of personal data
Where necessary, personal data may be received by:
- transport and logistics partners and partner pickup points;
- payment service providers, including Montonio Finance UAB, Revolut Bank UAB, PayPal (Europe) S.à r.l. et Cie, S.C.A., and other payment partners used by us;
- banks and financing providers;
- IT, hosting, data storage, CRM, email, SMS, analytics, and cybersecurity providers;
- accountants, auditors, legal advisers, and debt collection providers;
- public and law-enforcement authorities where disclosure is required by law.
Processors may use personal data only according to our instructions and agreements. Certain partners, such as banks and payment service providers, may act as independent controllers under their own privacy policies.
8. Transfers outside the EEA
We prefer to process personal data within the European Union and the European Economic Area. If a provider processes data outside the EEA, the transfer is made using safeguards provided by the GDPR, such as European Commission adequacy decisions, standard contractual clauses, and additional safeguards where necessary.
9. Retention periods
Personal data are retained only for as long as necessary for the processing purpose or required by law. As a general rule:
- account data – while the account is active and afterwards to the extent necessary to comply with the law or defend claims;
- order and customer service data – for up to 3 years after the last transaction or enquiry unless a dispute or law requires a longer period;
- accounting and tax documents – for 7 years or another mandatory period;
- call recordings – for up to 1 year unless needed longer for a specific complaint, dispute, or proceeding;
- marketing consent – until withdrawn; minimal opt-out data may be retained to prevent further marketing;
- technical logs – generally for up to 1 year.
At the end of the retention period, data are deleted or irreversibly anonymised.
10. Data security
We apply appropriate technical and organisational measures, including connection encryption, access-rights management, backups, software updates, confidentiality obligations, and agreements with processors. Access is granted only to persons who require it for their work.
If a personal data breach occurs, we assess the risk and notify the supervisory authority and affected persons where required by the GDPR.
11. Data subject rights
You have the right to:
- receive information and access your personal data;
- correct inaccurate data;
- request erasure where there is no legal basis for continued retention;
- restrict processing;
- receive data in a structured, commonly used, machine-readable format where applicable;
- object to processing based on legitimate interests;
- opt out of direct marketing at any time;
- withdraw consent without affecting the lawfulness of processing before withdrawal;
- lodge a complaint with a competent supervisory authority.
12. Direct marketing
Marketing messages are sent with consent or, where permitted by law, to existing customers about similar products and services. Every marketing email includes an opt-out option.
13. Contacts
For questions about this Policy or personal data processing:
ONE Management OÜ
Tartu mnt 24, 10115 Tallinn, Estonia
Registry code: 14770859
Email: [email protected]
14. Supervisory authorities
Because the controller is established in Estonia, the lead supervisory authority is:
In Lithuania, you may also contact:
15. Changes to this Policy
We may update this Policy when legislation, services, or processing practices change. The current version is published on the relevant website. Material changes will be announced on the website or by another appropriate method.
Last updated: 1 August 2026.
