Privacy Policy
This policy explains what personal data Dolce Vita Flowers collects on this website and in its boutiques, why, with whom it is shared and what rights you have. It applies from the launch of the new website; version of 2026-10-06.
WHO IS RESPONSIBLE
The data controller is Apriory Apartmants Kft. (Apriory Apartmants Korlátolt Felelősségű Társaság), registered seat 1073 Budapest, Erzsébet körút 18. földszint U1., Hungary, tax number 25147478-2-42, company registration number 01-09-202577. Contact for all questions about personal data: ilove@dolcevitaflowers.app, +36 30 169 0303. Boutiques: 1052 Budapest, Petőfi Sándor u. 3 and 1073 Budapest, Erzsébet körút 18.
WHAT WE COLLECT AND WHY
Orders. Your name, phone number, e-mail address, delivery address, the recipient's name and phone number, the contents of the order, the delivery slot and the payment status. We need this to conclude and fulfil the contract (Art. 6(1)(b) GDPR). Card details are entered on Stripe's page and never reach us. Bouquet photo. Before an order is sent out or collected, the florist photographs the finished bouquet, and we show you the photo on the order page — in your account or via the personal link in our e-mail. Florists take the photo so that the text of the card is not in the frame. The photo is kept in private storage in the EU and opens only via a time-limited link.
Invoices and accounting records. Name, address and order details on invoices. We keep them because Hungarian accounting law requires it (Art. 6(1)(c) GDPR; Act C of 2000, Section 169) — for 8 years.
Account. E-mail address, password (stored only as a hash), order history, bonus balance and favourites. The order history also shows orders placed with this e-mail address without signing in. When you confirm the account’s e-mail address (for an account moved from the shop’s previous website, when you first reset your password), we link to the account the paid orders placed with that e-mail address without signing in and move their bonuses to it; orders placed later with that e-mail address without signing in are linked when they are delivered or picked up. Basis: the contract with you (Art. 6(1)(b)). The account exists until you ask us to delete it: write to the shop from the e-mail address the account uses.
Requests from forms. Event requests, custom bouquet requests and newsletter sign-up: the details you enter. Basis: steps at your request before a contract (Art. 6(1)(b)) or your consent (Art. 6(1)(a)) for the newsletter, which you confirm by e-mail and can withdraw in every message. Requests are kept for 2 years.
“Drop a hint”. If you send a hint about a bouquet to another person, we store your name and e-mail, the recipient's name and e-mail and the chosen product, and we send the recipient one e-mail on your behalf. The recipient sees who sent the hint and can refuse further hints. We limit sending by IP address and browser to prevent abuse. Basis: our legitimate interest in providing the feature you requested (Art. 6(1)(f)). Kept for 12 months.
Chat. The chat is a separate service running on Cloudflare; the location of its database is not limited to the EU. Its script is loaded from the chat server on every page of the site. When you use the chat, the chat server briefly keeps your IP address to limit abuse (usually 10 minutes; at the latest it is removed by the daily clean-up once it is older than 24 hours). In the chat you can talk to our AI assistant, Dolce the bear, or write to our team. The conversation with Dolce is kept only in your browser; to answer, the text of up to the last 16 messages is sent to Anthropic (USA). Messages to the team are stored on the chat server and forwarded to our florists' group in Telegram; while we are closed, Dolce may answer instead and then receives up to the last 12 messages of the conversation, including the florists' replies. Giving personal data is optional: the chat may ask for your name (after your first message; you can skip it), a phone number or e-mail so that a florist can get back to you (if nobody has replied within three minutes or we are closed) and, after a florist closes the conversation, an e-mail for tips and seasonal offers. In Telegram the florists see the conversation, the name you gave, the chat language and the first characters of the chat identifier; your contact appears there partly hidden and in full only in the chat's administration. The website does not pass your account details to the chat. Basis: legitimate interest in customer support (Art. 6(1)(f)); for tips and offers — your consent (Art. 6(1)(a)), recorded with its time and text version, which you can withdraw at any time. Conversations with the team are deleted automatically 30 days after the last message; a contact you left is kept until we have handled your request; an e-mail left for tips is kept until you ask us to delete it or delete the chat with the bin icon; if you withdraw consent, it stays marked as withdrawn so that we do not write to you again; the chat's weekly backups keep data for up to 8 more weeks; messages in the florists' Telegram group stay there until they are deleted. To delete a conversation with the team, use the bin icon “Delete my chat history” in the chat header: your messages, our replies, your contact, a tips subscription left in this chat, the topic in Telegram and the entries in the backups are deleted; copies a florist has saved elsewhere cannot be reached this way. Deleting your account on the website does not delete the chat: use the bin icon, or write to us and we will delete it. The conversation with Dolce is cleared with the ↻ “New conversation” button or by clearing the site data in your browser.
Technical data. IP address, browser type, time of request and the pages requested, in server logs — for security and troubleshooting (Art. 6(1)(f)). Logs are kept for 30 days. Location. With your permission, the “Find the nearest boutique” button asks your browser for your location and compares it with the boutique addresses right on your device. The coordinates are not sent to us or to anyone else and are not stored. You can withdraw the permission in your browser settings.
Analytics. Only with your consent in the cookie banner we use PostHog (servers in the EU) to see how the site is used: pages, steps of the order, errors. With the events PostHog stores an approximate location derived from your IP address (country, region, city, postal code, time zone, approximate coordinates at city level); the IP address itself is not stored. Identifiers are pseudonymous; sessions are not recorded. Basis: consent (Art. 6(1)(a)); withdraw it at any time via “Cookie settings”. See the Cookie Policy.
Staff and couriers. Our staff see order details, including the recipient's address and phone number, in the shop's systems and in Telegram notifications, only as far as needed to prepare and deliver the order. In the boutiques, staff can open your website account to deduct bonuses you spend at the till; the deduction appears in your bonus history. Florists upload the photo of the finished bouquet in the shop's systems or via the staff Telegram bot; in the latter case the photo passes through Telegram.
WHERE THE DATA GOES
We do not sell personal data and do not share it with advertising networks. We use the following service providers (processors) under data processing agreements: Posiflora (our shop management system: customers, orders, bonuses), Stripe Payments Europe (payments; also an independent controller for fraud prevention), Resend (sending e-mails; based in the USA), Bluehost / Newfold Digital (hosting of the website and database in Frankfurt, EU), Cloudflare (DNS, content delivery, images, storage of finished-bouquet photos in the EU and encrypted backups; the chat service with its database and backups), Google Firebase (a second encrypted backup, EU region), Google Maps Platform (address suggestions and distance calculation — the delivery address only, without your name), PostHog (analytics, EU, only with consent), Anthropic (AI answers in the chat, USA). Payments made with Apple Pay and Google Pay are also processed by Stripe; Apple and Google take part in them as wallet providers and handle data under their own privacy policies. Telegram, through which chat messages and notifications reach our staff, is not our processor and we have no data processing agreement with it: it is an independent service based outside the EU, with its own privacy policy.
Transfers outside the EU. Stripe, Resend, Anthropic and Cloudflare may process data in the USA. These transfers are covered by the EU Standard Contractual Clauses included in their data processing agreements.
Authorities. We disclose data when the law requires it, for example to the tax authority or a court.
HOW LONG WE KEEP DATA
Orders and invoices — 8 years (accounting law). Contact details and address in an unpaid order without an account — 30 days. Account — until deleted. Form requests — 2 years. Hints — 12 months. Photos of finished bouquets — 180 days. Chat — conversations with the team 30 days after the last message; contacts left in the chat, chat backups and copies in Telegram — as described under “Chat”. Server logs — 30 days. Exchange log with payment and other service providers — 5 years: it is kept to resolve disputes. Analytics — up to 7 years from collection: this is the storage period of our analytics provider PostHog, and it cannot be shortened. After you delete your account or ask for erasure, your personal fields are made unreadable within 30 days by destroying the encryption key that protects them; if you have a paid order or subscription delivery that has not been delivered yet, within 30 days after it is delivered, and until then the data is used only to fulfil that order; records we must keep by law stay readable until their retention period ends. Your customer record and bonus card in our shop management system (Posiflora), and the copy of them the website receives from Posiflora, are not deleted when you delete your account or ask for erasure on the website. To have them deleted as well, say so in your request to ilove@dolcevitaflowers.app; records we must keep by law stay until their retention period ends. Encrypted backups are kept for up to 90 days and are then overwritten; we keep a minimal record (identifier, date, reason) that your data was erased, so that it is not restored by mistake.
SECURITY
On the website and in its database, data is encrypted in transit and at rest; personal fields are encrypted with a key specific to each person. Access for staff requires two-factor authentication and is logged. These systems run in the European Union. The chat is a separate service: where and how it keeps data is described under “Chat”.
YOUR RIGHTS
You may ask for access to your data and a copy of it, correction, erasure, restriction of processing, portability of the data you gave us, and you may object to processing based on legitimate interest. Consent can be withdrawn at any time without affecting earlier processing. Write to ilove@dolcevitaflowers.app; we answer within one month. You can also complain to the Hungarian supervisory authority: Nemzeti Adatvédelmi és Információszabadság Hatóság (NAIH), 1055 Budapest, Falk Miksa utca 9–11, naih.hu, or go to court.
CHILDREN
The website is intended for adults. We do not knowingly collect data from persons under 16; if you believe a child has given us data, write to us and we will delete it.
CHANGES
We update this policy when our processing changes and publish the new version with its date on this page.