Nairi — flowers & decor
BouquetsSetsGiftsWeddingsCare guide
Sign in·Sign up

Privacy Policy

Last updated: 2026-05-11

This Privacy Policy describes how Nairi Flowers s.r.o. ("Nairi", "we", "us") collects, uses, and shares personal data when you visit nairiflowers.com, place an order, sign up for our newsletter, or talk to our voice/text assistant.

We aim for transparency over completeness: this document mirrors exactly what the running application does. If something here ever drifts from reality, the reality is the bug.

1. Controller and contact

Nairi Flowers s.r.o.
IČO: 12345678
Registered address: Na Příkopě 22, 110 00 Praha 1, Czech Republic
Billing email: hello@nairiflowers.com
Privacy contact: privacy@nairiflowers.com

2. What personal data we collect

We collect only the data you give us when you interact with the service. Below is the full per-table inventory.

Account

Email, name, phone, profile image, Stripe customer id, role (customer/admin/florist).

Orders

Customer email, customer name, customer phone, recipient name, recipient phone, delivery address, optional VAT id, optional 200-character gift-card text.

Saved addresses

When signed in, you may save delivery addresses for re-use. Each saved address holds recipient name, street, city, postal code, country, optional phone.

Chat sessions and messages

The voice/text assistant captures conversation messages only when you have opted in to the AI chat logs consent category. Without that consent, your chat session is processed in-memory and discarded at the end of the request — nothing is written to our database.

Voice audio is never retained. The audio buffer is streamed to our transcription provider in memory and discarded at the end of the request. The text transcript may be persisted depending on the chat consent category above; the audio itself is not.

Newsletter subscription state

Email, opt-in source, locale at sign-up, double-opt-in confirmation timestamp, and (if you unsubscribe) the channel through which you opted out plus the locale at the time of opt-out.

Wishlists

Saved product / set / gift ids tied to your account.

Cookie consent decisions

A complete history of consent decisions you have made on this site (analytics on/off, AI chat logs on/off), keyed by either your account id or by a cryptographic session id stored in our consent cookie. We retain the history indefinitely as proof that we acted on your consent decisions correctly — this is required by GDPR Article 7(1).

Change history

When you edit your profile or addresses, we record the before/after values and the IP address of the request, scoped to your account. You can request this history via a data export.

Admin audit logs

When a member of our team takes an action that affects your data (e.g., updating an order status), we record the action, the actor, and the before/after. We retain raw IP and user-agent on these rows for two years to detect abuse.

AI usage telemetry

For each call to our AI providers, we record the model name, token counts, cost, and latency. We do not store the message content in this telemetry — that lives under your chat sessions (consent-gated).

Rate-limit state

To prevent abuse, we keep short-term counters keyed by your IP address for sensitive actions (sign-up attempts, search queries). The IP is retained on this row in raw form for the abuse-prevention legitimate interest.

3. Lawful basis

  • Consent (Art. 6(1)(a)) — analytics, AI chat-log persistence, marketing newsletter.
  • Contract performance (Art. 6(1)(b)) — processing orders, delivery arrangement, customer service contact.
  • Legitimate interest (Art. 6(1)(f)) — abuse prevention (rate limits), internal audit logs, fraud detection, error monitoring once enabled.
  • Legal obligation (Art. 6(1)(c)) — retention of order and invoice records under Czech accounting law (Zákon o účetnictví, 10-year retention).

4. Third-party processors

We share personal data with the following service providers strictly as necessary:

ProviderPurposeData sentRegion
StripeCard paymentsCustomer email, address, line items, amountUS (Standard Contractual Clauses)
ResendTransactional + marketing email deliveryRecipient email, HTML message body, RFC 8058 headersUS (EU residency pending domain verification)
OpenAI — gpt-4o-miniCustomer chat (text + RAG)Conversation messages, retrieved product contextUS (no training opt-in via API)
OpenAI — gpt-4o (vision)Internal admin product onboarding (not customer-facing)Product image bytes + promptUS
OpenAI — whisper-1Voice transcription (speech → text)Raw audio buffer (never persisted on our side)US
OpenAI — text-embedding-3-smallCatalog search vector indexProduct text only (no personal data)US
Telegram Bot APIInternal team alerts for new orders / failed deliveriesStrictly PII-scrubbed payloads only — order number, total, delivery method, admin deep link. No customer identity.RU/CIS (Telegram LLC) — legitimate interest, scrubbed
DigitalOcean SpacesObject storage for product images and DSAR data-export bundlesImage bytes; data-export JSON (encrypted at rest, SSE-S3, EU fra1)EU (fra1)
Google PlacesAddress autocomplete in checkout/profileQuery string + ephemeral session token (no full address from us)US (Google LLC)
Google Maps EmbedFooter atelier map (static iframe)Static address string inside iframe sandboxUS — necessary/functional
Better AuthSessions and email/password authenticationEmail, password hash, session tokenSelf-hosted on our infrastructure
SentryError tracking and session replayNot yet enabled at launch. When enabled, it will be gated behind your analytics consent decision; error payloads will be redacted to remove personal identifiers per our locked-in redaction contract.EU (planned)

5. Retention

  • Voice audio: 0 retention. Discarded at the end of the request.
  • Chat messages: 90 days from your last message in that session. If you withdraw the AI chat logs consent, your existing messages are deleted immediately.
  • Orders and invoices: retained indefinitely as required by Czech accounting law. On erasure, your personal details are removed from the order record (tombstoned) but the financial details are preserved.
  • Saved addresses, wishlists, change history: deleted on erasure.
  • Cookie consent decisions: retained indefinitely (Art. 7(1) proof of consent).
  • Newsletter subscription state: retained indefinitely on a suppression list (RFC 8058 industry best practice — we keep the record of your opt-out so we never mail you again by mistake).
  • Admin audit logs: 2 years, purged weekly. Rows recording right-of- erasure executions are preserved indefinitely as legal proof of fulfilment.
  • AI usage telemetry: 1 year, purged weekly.
  • Backups: 7 daily, 4 weekly, 12 monthly. Encrypted at rest.

6. Your rights

Right of access (Art. 15)

You can download a portable copy of your personal data from /account/data-export when signed in, or anonymously at /data-export-anonymous (email-verification required). We deliver your data within 30 days.

Right to erasure (Art. 17)

You can permanently anonymise your account from /account/erasure when signed in, or anonymously at /erasure-anonymous. Past order records will be preserved with all personal details removed, as required by Czech tax law (the financial record stays — your identity does not).

Right to withdraw consent (Art. 7(3))

For cookies and AI chat logs: manage at /account/privacy. For newsletter: every marketing email carries a one-click unsubscribe link (RFC 8058) in the inbox interface plus a clickable link in the body.

Rectification, restriction, portability, objection

Contact privacy@nairiflowers.com. We will respond within 30 days.

Right to lodge a complaint

You can complain to the Czech supervisory authority: Úřad pro ochranu osobních údajů (ÚOOÚ), www.uoou.cz, Pplk. Sochora 27, 170 00 Praha 7.

7. International transfers

Stripe, Resend, OpenAI, and Google are US-based providers. Where data is transferred outside the EEA, the transfer is covered by Standard Contractual Clauses or relies on GDPR Article 49 derogations (necessary for contract performance, where applicable).

8. Cookies

We use four cookies, all classified as necessary. For the full list and how to withdraw consent for any optional cookie we add in the future, see our Cookie Policy.

9. Children's data

Our service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe we have, please contact us.

10. Changes to this policy

We may update this policy from time to time. Material changes will be notified by email to active newsletter subscribers and surfaced as a banner on the next visit. The "Last updated" date at the top of this page is always current.

11. Contact

privacy@nairiflowers.com — for any privacy question or to exercise any of the rights above.

Nairi — flowers & decor

Hand-tied bouquets and quiet floral design from our atelier on Na Příkopě 22.

Catalog

  • Bouquets
  • Gift sets
  • Gifts & add-ons
  • Build a bundle
  • Weddings
  • Interior decor
  • 24/7 Pickup Locker
  • Care guide

Opening hours

Mon
09:00–20:00
Tue
09:00–20:00
Wed
09:00–20:00
Thu
09:00–20:00
Fri
09:00–20:00
Sat
10:00–19:00
Sun
10:00–19:00

Atelier

  • Na Příkopě 22Praha 1, 110 00
  • +420606608009
  • nairiflowers@gmail.com

© 2026 Premium Nairi s.r.o.· IČO 22107096· DIČ CZ22107096

Terms·Privacy·Cookies·Returns·Request my data·Erase my data
  • VISA
  • Pay
  • GPay
Home
Profile

A few cookies before you browse

We use a handful of cookies to keep the site working and (with your permission) understand how it's used. Pick what you're OK with. Privacy policy