GDPR Compliance
Last Updated: August 4, 2026
Our Commitment to GDPR
Blomster Stockholm is committed to compliance with the General Data Protection Regulation (GDPR) and protecting the privacy rights of individuals in the European Union and European Economic Area. This page outlines how we fulfill our obligations under GDPR.
Data Controller Information
Entity Name: Blomster Stockholm
echo-meadow.guru: echo-meadow.guru
Address: Artillerigatan 42, 114 45 Stockholm, Sweden
Contact Email: [email protected]
Lawful Basis for Processing
We process personal data under the following lawful bases as defined by GDPR Article 6:
- Consent (Article 6(1)(a)): When you explicitly agree to processing through form submissions or opt-in mechanisms
- Contract (Article 6(1)(b)): When processing is necessary to fulfill service agreements or pre-contractual measures
- Legal Obligation (Article 6(1)(c)): When required by Swedish or EU law
- Legitimate Interests (Article 6(1)(f)): For business operations that do not override your fundamental rights
Your Rights Under GDPR
As a data subject, you have the following rights:
Right to Access (Article 15)
You may request confirmation of whether we process your personal data and obtain a copy of that data along with information about processing activities.
Right to Rectification (Article 16)
You may request correction of inaccurate personal data or completion of incomplete data.
Right to Erasure (Article 17)
You may request deletion of your personal data when it is no longer necessary for the purposes collected, when you withdraw consent, or when you object to processing.
Right to Restriction (Article 18)
You may request limitation of processing when you contest data accuracy, object to processing, or when processing is unlawful but you prefer restriction over deletion.
Right to Data Portability (Article 20)
You may request transfer of your data in a structured, commonly used, machine-readable format when processing is based on consent or contract and carried out by automated means.
Right to Object (Article 21)
You may object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making (Article 22)
We do not engage in automated decision-making or profiling that produces legal effects or similarly significant impacts.
Data Protection Measures
We implement appropriate technical and organizational measures to ensure data security, including:
- Encryption of data in transit and at rest where appropriate
- Access controls limiting data access to authorized personnel only
- Regular security assessments and updates
- Staff training on data protection principles
- Data minimization practices to collect only necessary information
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by Article 33. If the breach poses a high risk, we will also notify affected individuals without undue delay.
International Data Transfers
We primarily process data within the European Economic Area. Any transfers outside the EEA will only occur with appropriate safeguards in place, such as Standard Contractual Clauses or adequacy decisions.
Data Retention Periods
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law:
- Consultation requests and correspondence: 3 years from last contact
- Service delivery records: Duration of service plus 2 years
- Technical logs: 12 months
- Marketing consent records: Until consent is withdrawn
Exercising Your Rights
To exercise any of your GDPR rights, please contact us at:
Email: [email protected]
Subject Line: "GDPR Request - [Specify Right]"
We will respond to your request within one month of receipt. In complex cases, this period may be extended by two additional months with notification and explanation.
Right to Lodge a Complaint
If you believe we have not processed your personal data in accordance with GDPR, you have the right to lodge a complaint with the relevant supervisory authority:
Swedish Authority for Privacy Protection (IMY)
Website: www.imy.se
Address: Box 8114, 104 20 Stockholm, Sweden
Children's Privacy
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware of such collection, we will delete the data promptly.
Updates to GDPR Compliance
We review and update our GDPR compliance practices regularly to reflect changes in regulations, business operations, or data processing activities.