Skip to content
FLOWERX
Expo
FLOWERX 2027Expo
Overview ↗Tickets ↗All exhibitors ↗Categories ↗Products ↗Floor plan ↗
Masterclass
FLOWERX 2027Masterclass
Overview ↗Programme ↗Access and pricing ↗FAQ ↗
Preston Bailey
FLOWERX 2027Preston Bailey
Overview ↗Masterclass ↗Stage appearance ↗Dinner with Preston Bailey ↗
Programme
FLOWERX 2027Programme
Overview ↗22 January ↗23 January ↗24 January ↗
Speakers
FLOWERX 2027Speakers
Overview ↗Greg van G ↗Preston Bailey ↗
Exhibit
FLOWERX 2027Exhibit
Overview ↗Stand options ↗Stand floor plan ↗Apply / book ↗Exhibitor information ↗
Partners
FLOWERX 2027Partners
Overview ↗Opportunities ↗Become a partner ↗
Visit
FLOWERX 2027Visit
Overview ↗Venue ↗Travel ↗Hotels ↗Parking ↗FAQ ↗
ROTickets ↗

FLOWERX 2027 · LEGAL

Privacy Policy

How we use and protect data across the website, checkout, bank transfer, NEXUS, email, QR tickets and the event.

Version
PRIV · 25.09.2026
Controller
Flowers Market Holland S.R.L.
Clear document15structured sectionsView tickets ↗

AT A GLANCE

Your data is not our product.

We collect what is needed for orders, bank-transfer reconciliation, invoices, access and support. We do not automatically share attendee lists with sponsors or exhibitors.

Terms & ConditionsPrivacyRefund & cancellationCookies

In this document

  1. 01Who controls data
  2. 02Data categories
  3. 03Purposes and bases
  4. 04What is required
  5. 05Payment and invoice
  6. 06Providers and recipients
  7. 07International transfers
  8. 08Retention periods
  9. 09Access and control
  10. 10Automation
  11. 11Images at the event
  12. 12Cookies and analytics
  13. 13How we protect data
  14. 14Minors
  15. 15Updates
01

Controller and contact

The primary controller for the website, ticket sales and event operations is S.C. Flowers Market Holland S.R.L., CUI RO31556279, J23/3468/2013, Șoseaua București–Urziceni nr. 55A, comuna Afumați, județul Ilfov, România. For questions and data-rights requests, contact office@flowersmarket.ro · +40 756 068 600 with the subject “FLOWERX data protection”. Requests are handled through the contact above and directed to the appropriate responsible person.

NETOPIA Financial Services S.A. is planned as a separate controller for future online-card processing but receives no data in the current bank-transfer flow. Exhibitors and sponsors become independent controllers only when you interact directly with them or explicitly choose to share data.

02

Data we collect

Website and security

IP address, technical identifiers, browser/device, timestamps, pages and technical events, security logs and consent preferences.

Order and attendee

Name, email, phone, product, quantity, named attendees, language, access entitlements, order and status.

Billing

Individual/company type, legal name, address, country, city, postcode, VAT ID, invoice data and NEXUS identifiers. We do not request a Romanian personal numeric code in checkout.

Bank transfer

FLOWERX reference, amount, currency, due date, receipt status, NEXUS document identifier, payer and transaction explanation. No card data is collected in this flow.

Access and support

Hashed QR token, scans, day/zone, re-entry, requests, correspondence, complaints and audit.

Professional forms

Company, contact, role, category, website, stand/partnership preferences, message and lead source.

03

Why we use data and our legal basis

PurposeTypical dataLegal basis
Catalogue, reservation until the proforma due date, order, ticket, My FLOWERX and supportIdentity, contact, product, attendees, accessContract and pre-contract steps · Art. 6(1)(b) GDPR
Transfer, invoice, accounting, tax and reconciliationBilling, receipt, orderContract and legal obligation · Art. 6(1)(b)–(c)
Security, fraud prevention, audit, rate limiting and legal defenceIP, logs, identifiers, historyLegitimate interest · Art. 6(1)(f)
Check-in, re-entry, safety and zone operationsTicket, QR hash, scansContract and legitimate interest
Stand, sponsorship, press and contact inquiriesProfessional details and messagePre-contract steps and legitimate interest
FLOWERX marketingEmail and preferenceSeparate consent · Art. 6(1)(a); withdraw at any time
Non-essential analytics/cookiesIdentifiers and interactionsConsent under the cookie policy
Atmosphere photo/video and venue securityImage, voice, incidentLegitimate interest; consent for individualised uses where required
04

Required data, attendees and sensitive information

Required fields are necessary for the contract, invoice, ticket delivery or response to an inquiry. Without them we cannot process the order or provide the service. Marketing is always optional and unchecked by default.

Where a buyer enters another attendee's data, the buyer confirms that they may provide it and have given this policy to that person. The attendee may directly request access, correction or object.

Checkout does not collect special-category data. If you voluntarily provide accessibility, allergy, medical or religious details to request an accommodation, we use them narrowly, restrict access and, where appropriate, rely on explicit consent under Article 9(2)(a) GDPR. Do not send unnecessary details.

05

Bank transfer, NEXUS and the financial process

For bank-transfer orders, the FLOWERX reference, amount, currency, payer and bank-document explanation imported into NEXUS are used to reconcile the receipt. Automatic confirmation occurs only for a validated, previously unused, full and exact payment. Partial, excess, late, foreign-currency or ambiguous payments are reviewed by authorised finance staff.

After receipt confirmation, billing data is used in NEXUS ERP for partner identification/creation, invoice issue, readback and PDF archive. Timeouts do not trigger blind resubmission: we first check whether the document already exists. The invoice is accessible only to authorised personnel and the buyer through secured channels.

NETOPIA remains planned for future online payment but receives no data in the current bank-transfer flow.

06

Who may receive data

  • the payer's and Organizer's banks — execution and evidence of the bank transfer;
  • NEXUS ERP — bank-receipt reconciliation, invoicing, accounting and archiving;
  • transactional email provider — proformas, reminders, confirmations, magic links, tickets, invoices and operational notices;
  • Google Ireland Limited — GA4, Google Ads, Tag Manager and Maps, only after the applicable choice;
  • Vimeo and Cloudflare — external video delivery, only after External media consent;
  • hosting, maintenance and security providers — infrastructure under restricted access and contractual duties;
  • ROMEXPO and event operators — only where required for access, safety, badges, requested support or services;
  • accountants, lawyers, auditors, insurers and authorities — for legal duties, legitimate interests or legal defence.

NETOPIA is not an active recipient while card payment is disabled. We do not sell databases or give attendee lists to sponsors/exhibitors. Sharing with a stand occurs only when an attendee voluntarily scans a badge, completes that recipient's form or gives separate informed consent.

07

Processing outside the European Economic Area

Google, Vimeo, Cloudflare and other technical providers may involve processing outside the EEA. Every transfer is documented in the provider register and relies on an adequacy decision, applicable EU–US Data Privacy Framework participation or Standard Contractual Clauses, plus supplementary measures where required.

You may request information about the safeguard used for a provider. Passwords, keys, document copies and financial content are not placed in analytics. For Google services, see Google Business Data Responsibility ↗.

08

How long we retain data

CategoryPeriod / criterion
Invoices, ledgers and financial supporting documentsThe applicable statutory period, generally up to 10 years from financial year end, subject to legal exceptions
Order, contractual consents and financial auditAs needed for performance, limitation periods and legal defence; then minimised/anonymised
Tickets, attendees and QR scansUp to 12 months after the event, then erased or anonymised unless an incident, dispute or legal duty applies
Stand/partnership and professional inquiriesUp to 24 months after last contact or for the negotiation/contract duration
Potentially sensitive accessibility/dietary requestsNormally 30 days after the event unless required for an incident
GA414 months for user-level and event-level data; aggregated reports may follow different periods under Google configuration
Cookie-choice evidenceFor the period needed to demonstrate the choice and handle a dispute, using a pseudonymous identifier
MarketingUntil consent is withdrawn or after a documented inactivity period; proof may remain for legal defence
Security logsNormally 6–12 months, longer only for incident investigation

Periods may be suspended for disputes, chargebacks, fraud, tax audit or authority requests. On expiry, data is erased, anonymised or archived with restricted access.

09

Your rights

Subject to GDPR conditions, you may request access, correction, erasure, restriction, portability, object to legitimate-interest processing and withdraw consent. Withdrawal does not affect earlier lawful processing. Erasure cannot override fiscal retention or legal defence requirements.

Send requests to office@flowersmarket.ro · +40 756 068 600. We may request proportionate identity verification and normally respond within one month, subject to the GDPR extension for complex requests. You may complain to the Romanian supervisory authority (ANSPDCP) ↗ or your competent local authority.

10

Automated decisions and profiling

We do not use profiling that produces legal or similarly significant effects. Automated controls may limit abuse, expire a reservation at the proforma due date, select the available pricing phase, match an exact receipt through the FLOWERX reference and route exceptions to manual review. An ambiguous, partial, excess or late payment is not automatically confirmed.

11

Photography, filming and CCTV

FLOWERX may capture atmosphere images for documentation, press and promotion based on legitimate interest, with venue notices. Interviews, testimonials and individualised portraits rely on consent or another documented basis. You may raise a particular objection with staff and it will be genuinely assessed.

ROMEXPO or a security provider may operate CCTV as a separate or joint controller for safety and access; venue notices will identify the relevant system and period.

12

Cookies, analytics and preferences

Strictly necessary cookies support sessions, CSRF, security and checkout. Google Analytics, Google Ads and external media are separate preference categories and default to off. FLOWERX uses Google Consent Mode v2 Basic: Google tags are not downloaded before the relevant consent. Details are in the Cookie policy.

Measurement events exclude names, email, phone, VAT ID, address, form content and tokens. Enhanced Conversions is disabled. You can change consent without losing essential functionality; refusal does not increase price or prevent ticket purchase.

13

Security and incidents

Controls include role-based access, strong authentication, encrypted connections, form protection, monitoring, audit and backups. Internal access is need-to-know.

No control removes all risk. We investigate incidents and notify ANSPDCP and affected people where GDPR requires. Never send unnecessary bank details by email or contact form.

14

Minors and other people’s data

The website and checkout are not designed to collect children's marketing consent directly. For a minor attendee, the buyer/legal representative must provide only necessary data and follow event rules. If data is found to have been collected improperly, we will erase it or seek proper authorisation.

15

Changes and policy version

We may update this policy for service, supplier or legal changes. Material changes will be highlighted on the website and, where an active relationship is affected, through an appropriate channel. Versions relevant to consent and contracts remain in the audit register.

Version: FLOWERX-PRIV-2026-09-25-R3 · last updated 25 September 2026.

Super Early BirdBuy ticket€79↗
FLOWERX

European Floral Design & Events Summit

ROMEXPO · PAVILION C222–24.01.2027Bucharest · Romania
Get tickets ↗

Organizer · Merchant · Invoice issuer

S.C. Flowers Market Holland S.R.L.

Șoseaua București–Urziceni nr. 55A
Comuna Afumați · Județul Ilfov · România
CUI
RO31556279
Trade Register
J23/3468/2013
office@flowersmarket.ro+40 756 068 600

Event

ProgrammeSpeakersExhibitorsTickets

Participate

ExhibitPartnersVisit

FLOWERX

AboutPressContactSitemap

Legal

Terms & conditionsPrivacyAccessibilityFAQ

Consumer protection

Consumer information

ANPCSubmit a complaint↗Alternative Dispute Resolution — ANPCOpen the SAL platform↗
© 2027 FLOWERX · S.C. FLOWERS MARKET HOLLAND S.R.L.
LegalBuilt by Aysa — The Agency ↗

FLOWERX · PRIVACY

You choose what we enable.

Essential technologies keep the website and checkout working. Analytics, advertising and external media remain off until you choose.

Cookie policy →
Customize optional services