Privacy Policy

This Privacy Policy explains how Bloom Boutique processes personal data in connection with its website, consultations, quotations, bookings, and floral services for weddings and events. It also describes the main categories of data, the purposes of processing, cookie use, sharing practices, retention, and the rights available to users under applicable law.

Effective Date
As stated in this policy
Scope
All users of our services
Questions?

Contact Information

Email contact
Telephone contact
+39 312 030 4612
Postal address
Corso Secondigliano 171, 80144 Naples
Privacy contact
01

Data We Collect

We may process identification and contact details, event and order information, consultation notes, delivery and setup details, payment-related records, and technical data such as device and usage information. Where needed for a floral project, we may also process preferences about style, timing, venue access, and other details provided by the user.

The categories collected depend on the inquiry, booking, or service request.
02

How We Collect Data

We collect data when users submit an inquiry, arrange a consultation, request a quote, confirm a booking, communicate about an event, or use the website. We may also receive information from payment, delivery, or technical service providers acting on our instructions, and we may generate internal records from those interactions.

Information is received directly from users and may also arise from service administration.
03

Cookie Types

The website may use essential cookies to support basic functions, preference cookies to remember selected settings, and analytics cookies to understand site performance and usage patterns. Cookies may be session-based or persistent depending on their purpose.

We use only standard cookie categories needed for operation and measurement.
04

Cookie Controls

Users may block or delete cookies through their browser settings. If certain cookies are disabled, some site functions may not work as intended. Where the website provides a cookie notice or preference tool, users may use it to manage non-essential cookies.

Cookie choices can be adjusted through browser settings and, where available, site controls.
GDPR

EU data protection framework

GDPR Overview

Where GDPR applies, Bloom Boutique acts as a controller for personal data processed through the website and related service communications. Processing is carried out on a lawful basis appropriate to the purpose, such as performance of a contract, steps taken at the user's request before entering into a contract, compliance with legal obligations, or legitimate interests where permitted.

For users in the European Economic Area, the General Data Protection Regulation may apply to our processing of personal data.
This section is intended for individuals whose data is processed under GDPR.

Protected individual rights

GDPR Rights

Where GDPR applies, individuals may have rights of access, rectification, erasure, restriction, objection, and data portability, as well as the right to withdraw consent where processing is based on consent. A complaint may also be lodged with the competent supervisory authority, without prejudice to other legal remedies.

GDPR rights are available subject to the conditions and limits set by law.
Purpose of use

Purposes of Processing

We use personal data to respond to inquiries, arrange consultations, prepare quotes, confirm bookings, manage deposits and event details, coordinate delivery and setup, communicate about service changes, maintain records, improve website performance, and comply with legal obligations. We may also use data to handle disputes, prevent misuse, and support internal administration.

Note
Processing is limited to operational needs and lawful business administration.
Third-party sharing

Service Providers

We may share personal data with trusted service providers that assist with website hosting, communication tools, payment processing, delivery coordination, technical support, and similar operational functions. These parties may process data only as instructed and for the purposes necessary to provide their services.

Note
Recipients are limited to service providers that support the operation of the business.

Depending on applicable law, users may have rights relating to access, correction, deletion, restriction, objection, and portability of personal data. Where processing is based on consent, that consent may be withdrawn for future processing without affecting prior lawful processing.

Available rights depend on the legal basis and the nature of the processing.

To exercise a privacy right, users should provide enough information to identify the relevant data and the nature of the request. We may ask for additional details to verify identity or clarify the scope of the request before responding.

Requests are reviewed before action is taken to protect data and prevent misuse.

We retain personal data for as long as necessary to manage inquiries, provide services, maintain business records, resolve disputes, and meet legal, accounting, or tax obligations. When data is no longer needed, it is deleted, anonymized, or otherwise handled in a secure manner consistent with applicable requirements.

Data is kept only for the period needed for the relevant purpose or legal duty.

We may update this Privacy Policy to reflect changes in our practices, legal requirements, or service structure. The revised version takes effect when published unless a different effective date is stated. Users should review the policy periodically to remain informed about current processing practices.

Changes are reflected in the policy text and, where appropriate, communicated by notice on the website.