Privacy Policy

This Privacy Policy explains how Blooming Artisan processes personal data when you visit the website, make an inquiry, request a consultation, or use our floral design services for weddings and events. It also describes the main choices and rights available to you under applicable data protection law.

Effective Date
As stated in this policy
Scope
All users of our services
Questions?

Data We Collect

We may process identification and contact details, event and order information, consultation notes, communication records, payment-related information, delivery and setup details, and technical data such as device, browser, and usage information. For wedding and event projects, we may also process information needed to prepare a quote, confirm dates, and coordinate venue access and on-site arrangements.

The categories collected depend on the service request and the way the website is used.

How We Collect Data

We collect data when you submit an inquiry, request a consultation, ask for a quote, confirm a booking, or communicate with us by phone or through the contact form. We also receive information from payment and delivery interactions, and we may generate internal records from correspondence, scheduling, and service coordination.

Most information is provided directly by the user, with some data created during normal website and service use.

Cookies We Use

The website may use essential cookies for core functions, preference cookies to remember basic settings, and analytics cookies to understand how the site is used. Cookies may be session-based or persistent, depending on their purpose and lifespan.

We use only standard cookie categories needed for site operation and basic measurement.

Cookie Controls

You may block or delete cookies through your browser settings. If your browser allows it, you can also refuse non-essential cookies or clear stored cookies after a visit. Some site functions may not work properly if cookies are disabled.

Cookie choices can be managed through browser settings and, where available, site controls.
GDPR

Regulation

GDPR Overview

Under the GDPR, we process personal data only where we have a lawful basis, such as performance of a contract, compliance with legal obligations, legitimate interests, or consent where required. We limit processing to what is relevant for inquiries, bookings, event coordination, payment handling, and website administration.

Where GDPR applies, it governs our processing of personal data of individuals in the European Economic Area in connection with this website and our services.
This section is intended for individuals whose data is protected by the GDPR.

GDPR-aware data handling

Your GDPR Rights

Where the GDPR applies, you may have the right to access, rectify, erase, restrict, or object to certain processing, and to request data portability in appropriate cases. If processing is based on consent, you may withdraw consent at any time without affecting prior processing. You may also lodge a complaint with the competent supervisory authority.

GDPR rights are assessed case by case and may depend on the legal basis for processing.
User Rights

Your Rights

Subject to applicable law, you may have rights to access your personal data, correct inaccurate information, request deletion, object to certain processing, and ask for restriction of processing. Where we rely on consent, you may withdraw it for future processing. Some requests may be limited where we must retain information for legal, contractual, or security reasons.

Available rights may vary depending on the legal basis and the nature of the request.
Requests

How to Make a Request

To exercise your rights, send a clear request using the contact details in this policy and describe the data or processing concerned. We may ask for information needed to verify your identity and to locate the relevant records. We will respond within the time limits required by applicable law.

Requests are handled after reasonable verification of identity and scope.
Data Retention

Data Retention

We keep personal data only for as long as needed for the purpose for which it was collected, including quotation handling, booking management, service delivery, recordkeeping, and legal compliance. When data is no longer needed, we delete it or anonymize it, unless a longer retention period is required by law or needed to resolve a dispute.

Retention depends on the purpose of the record and any legal or accounting requirement.
Policy Updates

Policy Updates

When we update this policy, we will post the revised version on the website and apply the new text from its stated effective date. If a change materially affects how we process personal data, we may provide an additional notice through the website or by direct communication where appropriate.

We may revise this policy to reflect legal, technical, or operational changes.

Contact Details

Email contact
Telephone contact
+33 6 12 60 14 99
Postal address
1 Avenue Eugène Avinée, 59120 Loos
Privacy contact

How We Use Data

We use personal data to respond to inquiries, arrange consultations, prepare quotes, confirm bookings, manage deposits and service dates, coordinate delivery and on-site setup, communicate about event details, process payments, maintain business records, improve website performance, and meet legal obligations.

Processing is limited to operational needs and lawful business administration.

Service Providers and Partners

We may share personal data with trusted service providers that support website hosting, communication handling, payment processing, scheduling, delivery coordination, and related administrative functions. These parties act on our instructions and are expected to use the data only for the services they provide to us.

Service providers receive only the information needed to perform their assigned tasks.

Legal Disclosures

We may disclose personal data where necessary to comply with legal obligations, respond to lawful requests, protect our rights, or support the establishment, exercise, or defense of legal claims. We may also share information when required to prevent fraud, misuse, or security incidents.

Disclosure to public authorities is limited to situations required or permitted by law.