Controller and contact
The primary controller for the website, ticket sales and event operations is S.C. Flowers Market Holland S.R.L., CUI RO31556279, J23/3468/2013, Șoseaua București–Urziceni nr. 55A, comuna Afumați, județul Ilfov, România. For questions and data-rights requests, contact office@flowersmarket.ro · +40 756 068 600 with the subject “FLOWERX data protection”. Requests are handled through the contact above and directed to the appropriate responsible person.
NETOPIA Financial Services S.A. is planned as a separate controller for future online-card processing but receives no data in the current bank-transfer flow. Exhibitors and sponsors become independent controllers only when you interact directly with them or explicitly choose to share data.
Data we collect
Website and security
IP address, technical identifiers, browser/device, timestamps, pages and technical events, security logs and consent preferences.
Order and attendee
Name, email, phone, product, quantity, named attendees, language, access entitlements, order and status.
Billing
Individual/company type, legal name, address, country, city, postcode, VAT ID, invoice data and NEXUS identifiers. We do not request a Romanian personal numeric code in checkout.
Bank transfer
FLOWERX reference, amount, currency, due date, receipt status, NEXUS document identifier, payer and transaction explanation. No card data is collected in this flow.
Access and support
Hashed QR token, scans, day/zone, re-entry, requests, correspondence, complaints and audit.
Professional forms
Company, contact, role, category, website, stand/partnership preferences, message and lead source.
Why we use data and our legal basis
| Purpose | Typical data | Legal basis |
|---|---|---|
| Catalogue, reservation until the proforma due date, order, ticket, My FLOWERX and support | Identity, contact, product, attendees, access | Contract and pre-contract steps · Art. 6(1)(b) GDPR |
| Transfer, invoice, accounting, tax and reconciliation | Billing, receipt, order | Contract and legal obligation · Art. 6(1)(b)–(c) |
| Security, fraud prevention, audit, rate limiting and legal defence | IP, logs, identifiers, history | Legitimate interest · Art. 6(1)(f) |
| Check-in, re-entry, safety and zone operations | Ticket, QR hash, scans | Contract and legitimate interest |
| Stand, sponsorship, press and contact inquiries | Professional details and message | Pre-contract steps and legitimate interest |
| FLOWERX marketing | Email and preference | Separate consent · Art. 6(1)(a); withdraw at any time |
| Non-essential analytics/cookies | Identifiers and interactions | Consent under the cookie policy |
| Atmosphere photo/video and venue security | Image, voice, incident | Legitimate interest; consent for individualised uses where required |
Required data, attendees and sensitive information
Required fields are necessary for the contract, invoice, ticket delivery or response to an inquiry. Without them we cannot process the order or provide the service. Marketing is always optional and unchecked by default.
Where a buyer enters another attendee's data, the buyer confirms that they may provide it and have given this policy to that person. The attendee may directly request access, correction or object.
Checkout does not collect special-category data. If you voluntarily provide accessibility, allergy, medical or religious details to request an accommodation, we use them narrowly, restrict access and, where appropriate, rely on explicit consent under Article 9(2)(a) GDPR. Do not send unnecessary details.
Bank transfer, NEXUS and the financial process
For bank-transfer orders, the FLOWERX reference, amount, currency, payer and bank-document explanation imported into NEXUS are used to reconcile the receipt. Automatic confirmation occurs only for a validated, previously unused, full and exact payment. Partial, excess, late, foreign-currency or ambiguous payments are reviewed by authorised finance staff.
After receipt confirmation, billing data is used in NEXUS ERP for partner identification/creation, invoice issue, readback and PDF archive. Timeouts do not trigger blind resubmission: we first check whether the document already exists. The invoice is accessible only to authorised personnel and the buyer through secured channels.
NETOPIA remains planned for future online payment but receives no data in the current bank-transfer flow.
Who may receive data
- the payer's and Organizer's banks — execution and evidence of the bank transfer;
- NEXUS ERP — bank-receipt reconciliation, invoicing, accounting and archiving;
- transactional email provider — proformas, reminders, confirmations, magic links, tickets, invoices and operational notices;
- Google Ireland Limited — GA4, Google Ads, Tag Manager and Maps, only after the applicable choice;
- Vimeo and Cloudflare — external video delivery, only after External media consent;
- hosting, maintenance and security providers — infrastructure under restricted access and contractual duties;
- ROMEXPO and event operators — only where required for access, safety, badges, requested support or services;
- accountants, lawyers, auditors, insurers and authorities — for legal duties, legitimate interests or legal defence.
NETOPIA is not an active recipient while card payment is disabled. We do not sell databases or give attendee lists to sponsors/exhibitors. Sharing with a stand occurs only when an attendee voluntarily scans a badge, completes that recipient's form or gives separate informed consent.
Processing outside the European Economic Area
Google, Vimeo, Cloudflare and other technical providers may involve processing outside the EEA. Every transfer is documented in the provider register and relies on an adequacy decision, applicable EU–US Data Privacy Framework participation or Standard Contractual Clauses, plus supplementary measures where required.
You may request information about the safeguard used for a provider. Passwords, keys, document copies and financial content are not placed in analytics. For Google services, see Google Business Data Responsibility .
How long we retain data
| Category | Period / criterion |
|---|---|
| Invoices, ledgers and financial supporting documents | The applicable statutory period, generally up to 10 years from financial year end, subject to legal exceptions |
| Order, contractual consents and financial audit | As needed for performance, limitation periods and legal defence; then minimised/anonymised |
| Tickets, attendees and QR scans | Up to 12 months after the event, then erased or anonymised unless an incident, dispute or legal duty applies |
| Stand/partnership and professional inquiries | Up to 24 months after last contact or for the negotiation/contract duration |
| Potentially sensitive accessibility/dietary requests | Normally 30 days after the event unless required for an incident |
| GA4 | 14 months for user-level and event-level data; aggregated reports may follow different periods under Google configuration |
| Cookie-choice evidence | For the period needed to demonstrate the choice and handle a dispute, using a pseudonymous identifier |
| Marketing | Until consent is withdrawn or after a documented inactivity period; proof may remain for legal defence |
| Security logs | Normally 6–12 months, longer only for incident investigation |
Periods may be suspended for disputes, chargebacks, fraud, tax audit or authority requests. On expiry, data is erased, anonymised or archived with restricted access.
Your rights
Subject to GDPR conditions, you may request access, correction, erasure, restriction, portability, object to legitimate-interest processing and withdraw consent. Withdrawal does not affect earlier lawful processing. Erasure cannot override fiscal retention or legal defence requirements.
Send requests to office@flowersmarket.ro · +40 756 068 600. We may request proportionate identity verification and normally respond within one month, subject to the GDPR extension for complex requests. You may complain to the Romanian supervisory authority (ANSPDCP) or your competent local authority.
Automated decisions and profiling
We do not use profiling that produces legal or similarly significant effects. Automated controls may limit abuse, expire a reservation at the proforma due date, select the available pricing phase, match an exact receipt through the FLOWERX reference and route exceptions to manual review. An ambiguous, partial, excess or late payment is not automatically confirmed.
Photography, filming and CCTV
FLOWERX may capture atmosphere images for documentation, press and promotion based on legitimate interest, with venue notices. Interviews, testimonials and individualised portraits rely on consent or another documented basis. You may raise a particular objection with staff and it will be genuinely assessed.
ROMEXPO or a security provider may operate CCTV as a separate or joint controller for safety and access; venue notices will identify the relevant system and period.
Cookies, analytics and preferences
Strictly necessary cookies support sessions, CSRF, security and checkout. Google Analytics, Google Ads and external media are separate preference categories and default to off. FLOWERX uses Google Consent Mode v2 Basic: Google tags are not downloaded before the relevant consent. Details are in the Cookie policy.
Measurement events exclude names, email, phone, VAT ID, address, form content and tokens. Enhanced Conversions is disabled. You can change consent without losing essential functionality; refusal does not increase price or prevent ticket purchase.
Security and incidents
Controls include role-based access, strong authentication, encrypted connections, form protection, monitoring, audit and backups. Internal access is need-to-know.
No control removes all risk. We investigate incidents and notify ANSPDCP and affected people where GDPR requires. Never send unnecessary bank details by email or contact form.
Minors and other people’s data
The website and checkout are not designed to collect children's marketing consent directly. For a minor attendee, the buyer/legal representative must provide only necessary data and follow event rules. If data is found to have been collected improperly, we will erase it or seek proper authorisation.
Changes and policy version
We may update this policy for service, supplier or legal changes. Material changes will be highlighted on the website and, where an active relationship is affected, through an appropriate channel. Versions relevant to consent and contracts remain in the audit register.
Version: FLOWERX-PRIV-2026-09-25-R3 · last updated 25 September 2026.