BE MY FLOWER Privacy Policy
Table of Contents
The controller of the personal data processed through the online store available at bemyflower.wroclaw.pl is Vladyslav Kuzmenko, conducting business as ART CONCEPT VLADYSLAV KUZMENKO, with its registered office at Sikorskiego 5H, 53-659 Wrocław, Poland.
The business is registered under:
– Tax Identification Number (NIP): 8943258532
– Business Registration Number (REGON): 541483614
You can contact the Data Controller using the following details:
– Phone: +48 731 687 033
– Email: bemyflower.wro@gmail.com
The Data Controller is also the controller of personal data within the meaning of the General Data Protection Regulation (GDPR).
The Data Controller processes personal data voluntarily provided by Users when using the Store and placing orders.
Webflow processes certain personal data as a data processor and, in some cases, as an independent data controller (for example, in relation to platform security). More information is available in Webflow's Privacy Policy.
The personal data we may collect includes, in particular:
– Full name
– Billing and/or delivery address
– Email address
– Phone number
– Invoicing details (company name, Tax Identification Number (NIP), and business address), where an invoice is requested
– Payment information (processed directly by the payment provider; the Data Controller does not always store payment card details)
– Order information, including purchased products and transaction history
– Technical information, such as IP address, device information, and server logs
– Information provided through correspondence, including emails and telephone communications
Sources of Personal Data
We collect personal data from the following sources:
– Directly from the User (for example, through the order form, customer account, or contact forms)
– Automatically through server logs, cookies, and analytics technologies
– From trusted service providers and partners, such as payment processors and courier companies
We process your personal data for the following purposes and on the following legal bases:
1. Order Processing and Contract PerformanceWe process personal data necessary to enter into and perform a sales contract, in accordance with Article 6(1)(b) of the GDPR. This includes contact details, delivery information, transaction data, and billing information.
2. Payment ProcessingPersonal data is processed to facilitate and complete payments, pursuant to Article 6(1)(b) of the GDPR.
3. Compliance with Legal ObligationsWe process and retain accounting, tax, and financial records where required by law, in accordance with Article 6(1)(c) of the GDPR.
4. Direct Marketing and Behavioural AdvertisingWhere you have provided your consent, we process your personal data for purposes such as sending newsletters, remarketing, and displaying personalised advertisements, pursuant to Article 6(1)(a) of the GDPR.Your consent is voluntary and may be given or withdrawn independently at any time.
5. Legitimate Interests of the Data ControllerWe may process personal data where necessary for our legitimate interests under Article 6(1)(f) of the GDPR, including:Establishing, exercising, or defending legal claimsMaintaining the security of the website and our servicesDetecting, preventing, and investigating fraud or other unlawful activitySuch processing is carried out only where our legitimate interests do not override your rights and freedoms.
6. Customer Support and Complaint HandlingWe process personal data to respond to enquiries and handle complaints, where applicable, pursuant to Article 6(1)(b), 6(1)(c), or 6(1)(f) of the GDPR, depending on the circumstances.
7. Consent ManagementYour cookie preferences and marketing consents are managed using the CookieConsent platform.
We retain your personal data only for as long as necessary to fulfil the purposes for which it was collected and to comply with applicable legal obligations.
The retention periods are generally as follows:
– Order and accounting records (including invoices and receipts) are retained for the period required under applicable tax and accounting laws, typically 5 years from the end of the financial year to which the records relate.
– Personal data required to fulfil your order (such as your contact details and delivery address) is retained for the duration of order fulfilment and for the period during which legal claims may be asserted or defended, typically 2-3 years, depending on the nature of the claim.
– Marketing data, including newsletter subscriptions and marketing consents, is retained until you withdraw your consent.
– Customer account information is retained for as long as your account remains active and for 12 months after its closure for evidential purposes, unless a longer retention period is required by law.
– Server logs and technical data are generally retained for up to 12 months.
– Data processed for fraud prevention and security purposes is retained for as long as necessary to assess risks, prevent abuse, or until the applicable limitation period for legal claims has expired.
In every case, we retain personal data only for the minimum period necessary, taking into account applicable legal requirements and our legitimate business needs.
Your personal data may be shared only with trusted third parties that assist us in providing our services, including:
– Webflow
– Payment service providers (such as Stripe, BLIK, and PayPal)
– Courier and logistics companies
– Accounting and bookkeeping service providers
– IT service providers (including hosting and backup services)
– Analytics and advertising providers (such as Google Analytics and Meta/Facebook)
Where required under the GDPR, the Data Controller enters into appropriate Data Processing Agreements (DPAs) with these service providers to ensure that your personal data is processed securely and in compliance with applicable data protection laws.
We use third-party platforms and service providers (such as Webflow) that may process personal data outside the European Economic Area (EEA).
Whenever personal data is transferred outside the EEA, the Data Controller ensures that appropriate safeguards are in place in accordance with the GDPR. These safeguards may include Standard Contractual Clauses (SCCs) approved by the European Commission or other legally recognised transfer mechanisms.
Information about the safeguards applied to international data transfers is available upon request.
Where we use profiling tools or behavioural advertising technologies (such as remarketing or custom audience lists), personal data is processed only with your consent and through the use of cookies or similar technologies.
You may withdraw your consent at any time.
Under the GDPR, you have the following rights regarding your personal data:
– The right to access your personal data and obtain a copy of it
– The right to rectify inaccurate or incomplete personal data
– The right to erasure ("the right to be forgotten"), where applicable under the law
– The right to restrict the processing of your personal data
– The right to data portability
– The right to object to processing based on our legitimate interests
– The right to withdraw your consent at any time where processing is based on consent. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.
– The right to lodge a complaint with the competent supervisory authority.
How to Exercise Your Rights
Requests relating to your personal data should be sent by email to bemyflower.wro@gmail.com or by post to the registered address of the Data Controller.
We will respond without undue delay and no later than one month after receiving your request. Where necessary due to the complexity or number of requests, this period may be extended by up to two additional months.
Where necessary, we may request additional information or documentation to verify your identity before processing your request.
Our services are not intended for children under the age of 16, in accordance with applicable Polish and European Union legislation.
We do not knowingly collect personal data from children under this age. If we become aware that personal data has been provided by a child without the consent of a parent or legal guardian, we will delete such data upon request.
We implement appropriate technical and organisational measures to protect your personal data, including:
– Encrypted data transmission
– Access controls based on user permissions
– Regular data backups
– Data Processing Agreements with our service providers
While we take every reasonable precaution to protect your personal data, no method of electronic transmission or storage can be guaranteed to be completely secure. We continuously work to minimise any potential risks.
We may disclose personal data to public authorities where required by applicable law, including in response to lawful requests from courts, regulatory authorities, or law enforcement agencies.
Any disclosure of personal data will be made only where legally required and only to the extent necessary under applicable legislation.
We may update this Privacy Policy from time to time.
If we make any significant changes, we will notify users through our website and update the "Last Updated" date shown at the top of this Policy.
If you have any questions regarding the processing of your personal data, please contact us: bemyflower.wro@gmail.com
Postal address:
ul. Sikorskiego 5H
53-659 Wrocław
Poland
For customer service enquiries:
Email: bemyflower.wro@gmail.com
Phone: +48 731 687 033
You also have the right to lodge a complaint with the competent data protection supervisory authority if you believe that the processing of your personal data violates applicable data protection laws.
You may submit a complaint in the EU Member State of your habitual residence, place of work, or the place where the alleged infringement occurred.
In Poland, the competent supervisory authority under the GDPR is the President of the Personal Data Protection Office (PUODO).

