This Policy explains how Zeester bloemen en planten bv processes personal data when you use flowerbridgenz.com, why the data is used, and what rights you have.
01 Controller
The controller is Zeester bloemen en planten bv, Hertenlaan 6, 2675 AH Honselersdijk, Netherlands; KvK 27265757; VAT NL813140699B01 (the “Company”).
02 Data we process
- name, surname, company, role and professional field;
- telephone number, email address and other contact details;
- the enquiry, registration, correspondence and files voluntarily submitted;
- event registration and attendance information;
- technical data such as IP address, device and browser type, language, date and time, and security logs;
- website-use and cookie data to the extent permitted by your choices and applicable law.
Please do not submit special-category data, health information, political or religious views, or identity documents unless the Company specifically requests them for a lawful purpose.
03 Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Responding to enquiries and applications | Steps at your request before entering a contract; legitimate interest in business communication |
| Event registration and delivery | Performance of a contract and steps requested by the participant |
| News and marketing | Consent; where permitted, legitimate interest concerning existing business contacts |
| Security, abuse prevention and legal claims | Legitimate interests; compliance with legal obligations |
| Mandatory accounting and legal records | Compliance with legal obligations |
| Optional analytics and cookies | Consent where required |
04 Recipients
Data may be accessed by authorised staff and service providers supporting hosting, forms, email, analytics, registration, video communications and professional advice, as well as a grower or partner to whom an enquiry is addressed. Each recipient receives only what is necessary and must protect the data.
If an external service is used for registration or communication, its role and processing terms are determined by the relevant notice and its agreement with the Company.
05 Transfers outside the EEA
If a provider or recipient is outside the European Economic Area, the Company relies on a GDPR transfer mechanism and appropriate safeguards, such as an adequacy decision, standard contractual clauses or a specific lawful derogation. Information about the applicable safeguard is available on request.
06 Retention
Data is kept no longer than necessary: enquiries are generally retained for up to two years after the conversation ends; registration data for the event and a reasonable follow-up period; marketing data until consent is withdrawn or the relationship is no longer active; and technical logs for the security period for which they are needed. Contractual and accounting records are retained for the period required by law. A dispute may require longer retention until claims are resolved.
07 Cookies
Necessary cookies support website operation and security. Optional analytics or marketing cookies are used only where the required consent has been obtained. You may change your choice in the cookie interface and remove cookies through your browser.
08 Your rights
Where provided by the GDPR, you may request access, rectification, erasure, restriction and portability; object to processing based on legitimate interests; and withdraw consent at any time without affecting earlier lawful processing. You may lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or the supervisory authority where you live.
09 Automated decisions
The Company does not use solely automated decision-making that produces legal or similarly significant effects unless this is separately disclosed.
10 Security
The Company applies proportionate technical and organisational safeguards, including access control, protected transmission, backups, system updates and supplier checks. No transmission or storage method can eliminate every risk.
11 Children
The website and professional events are not intended for independent use by children. Where processing a child’s data requires consent from a legal representative, the data will be accepted only after valid consent is obtained.
12 Requests and updates
To exercise a right, describe the request and provide information reasonably necessary to verify identity through the website contact form or by post to the Company. This Policy may be updated; the current version is published on this page.