GDPR & EEA Compliance

Last Updated: August 2026

This policy explains how Indoor Plant Care Guide complies with the General Data Protection Regulation (GDPR) and applies to all visitors in the European Economic Area (EEA), including the EU, Iceland, Liechtenstein, and Norway.

What is GDPR?

The General Data Protection Regulation (GDPR) is a European Union law that protects the privacy and data rights of individuals in the EEA.

GDPR requires organizations to:

  • Be transparent about what data they collect
  • Obtain consent before collecting personal data (with limited exceptions)
  • Protect personal data with strong security measures
  • Allow individuals to access, correct, and delete their data
  • Report data breaches within 72 hours
  • Appoint a Data Protection Officer (if applicable)
  • Have valid legal bases for processing data

Our commitment: Indoor Plant Care Guide fully complies with GDPR.

Legal Basis for Processing

We only process personal data when we have a valid legal basis under GDPR Article 6.

Consent

What data: Email address (when you contact us)

Legal basis: Explicit consent to receive and respond to your message

Your rights: Withdraw consent anytime by emailing us

Our obligation: Stop processing and delete your data within 30 days

Legitimate Interests

What data: Server logs, analytics data, cookies

Legal basis: Legitimate interest in operating and improving the Site

Our interest: Understand traffic, improve performance, prevent fraud

Your rights: Object to processing anytime (see section 6)

Balancing test: Your privacy interests don’t outweigh our legitimate interests (minimal data, anonymized, aggregate analytics)

Legal Obligation

What data: Server logs (for security and fraud prevention)

Legal basis: Legal obligation to prevent misuse and comply with law

Our obligation: Retain only as long as legally required, then delete

Data Protection Rights (GDPR Articles 15-22)

Right to Access (Article 15)

You have the right to know what personal data we process about you.

What you can request:

  • Confirmation that we process your data
  • Copy of your personal data
  • Details about how we use your data
  • Information about data recipients
  • Retention period

How to request:

Email: [email protected]

Subject: “GDPR – Right to Access”

Include: Your name and email address

Our response time: Within 30 days (extendable to 60 days for complex requests)

Right to Rectification (Article 16)

You have the right to correct inaccurate personal data.

What you can do:

  • Request correction of incomplete or inaccurate data
  • Request deletion if data is no longer necessary
  • Request update of outdated information

How to request:

Email: [email protected]

Subject: “GDPR – Right to Rectification”

Include: Your name, what data needs correction, and corrected information

Our response time: Within 30 days

Right to Erasure / “Right to Be Forgotten” (Article 17)

You have the right to request deletion of your personal data.

We will delete data if:

  • Data is no longer necessary for the purpose collected
  • You withdraw your consent
  • You object to processing and there’s no overriding legitimate interest
  • Data has been unlawfully processed
  • You request deletion

We may NOT delete data if:

  • Required by law
  • Necessary for legal claims
  • Data is part of a legitimate defense

How to request:

Email: [email protected]

Subject: “GDPR – Right to Erasure”

Include: Your name and confirmation you want all data deleted

Our response time: Within 30 days (data deleted immediately after confirmation)

Right to Restrict Processing (Article 18)

You have the right to restrict how we use your personal data.

You can request we:

  • Stop processing your data (but keep it)
  • Only process for specific purposes
  • Limit who has access to your data

How to request:

Email: [email protected]

Subject: “GDPR – Right to Restrict”

Include: Your name and how you want processing restricted

Our response time: Within 30 days

Right to Data Portability (Article 20)

You have the right to receive your personal data in a portable format.

What we provide:

  • Your personal data in a structured format (e.g., CSV, JSON)
  • In a commonly used, machine-readable format
  • Data you provided to us (not data we generated about you)

How to request:

Email: [email protected]

Subject: “GDPR – Right to Data Portability”

Include: Your name and preferred format

Our response time: Within 30 days

Note: We collect minimal personal data (mainly email). Data portability is straightforward.

Right to Object (Article 21)

You have the right to object to processing of your personal data.

You can object to:

  • Processing based on legitimate interests
  • Processing for direct marketing
  • Processing for profiling

What happens after objection:

  • We will stop processing unless we have overriding legitimate interest
  • We will explain why we can’t comply (if applicable)

How to object:

Email: [email protected]

Subject: “GDPR – Right to Object”

Include: Your name and reason for objection

Our response time: Within 30 days

Right Not to Be Subject to Automated Decision-Making (Article 22)

You have the right not to be subject to automated decisions that produce legal or similarly significant effects.

Our practice: We do not make automated decisions about you. All decisions are made by humans.

Data Processing Agreement (DPA)

For businesses and organizations: If you process data on behalf of an organization, you may need a Data Processing Agreement (DPA) with us.

We are happy to sign a standard DPA or provide our DPA template.

To request a DPA:

Email: [email protected]

Subject: “DPA Request”

Include: Your organization name and data processing description

Response time: Within 15 business days

International Data Transfers

Important: The United States does not have the same data protection level as the EEA.

If you’re in the EEA and your data is transferred to the US (for hosting or analytics), we ensure adequate safeguards:

Standard Contractual Clauses (SCCs)

We use Standard Contractual Clauses (SCCs) with all US-based service providers to ensure data protection equivalent to GDPR.

Service providers using SCCs:

  • Cloudflare (hosting)
  • Google Analytics (analytics)
  • Google AdSense (advertising, when launched)

Adequacy Decisions

We only transfer data to countries with:

  • Adequacy decisions from the European Commission, OR
  • Standard Contractual Clauses in place

Your Rights

You have the right to:

  • Know about international transfers
  • Request what safeguards are in place
  • Object to transfers
  • Request data stay within the EEA

To request: Email [email protected] with “Data Transfer Inquiry”

Cookie Consent & Preferences

Consent for Non-Essential Cookies

Essential cookies: We set without consent (necessary for Site function)

Non-essential cookies: We ask for consent before setting

How to manage:

  • Accept/reject cookies on our cookie banner
  • Update preferences anytime in browser settings
  • Withdraw consent anytime

Cookie Types

TypePurposeConsent RequiredRetention
Session cookiesTechnical necessityNoSession
Preference cookiesRemember settingsNo1 year
Analytics cookiesUnderstanding trafficYes (GDPR)38 months
Advertising cookiesShow relevant adsYes (GDPR)13 months

Your choice: You can disable non-essential cookies without losing Site functionality.

Data Security

Security Measures

We implement:

  • HTTPS encryption: All data in transit is encrypted
  • Firewall protection: Network-level security
  • Secure hosting: Industry-standard security practices
  • Limited access: Only authorized personnel access personal data
  • Regular monitoring: We monitor for suspicious activity
  • Annual reviews: We review security practices annually

Data Breach Notification

If a data breach occurs affecting your personal data:

  • EEA residents: We notify you within 72 hours (as required by GDPR)
  • All residents: We notify promptly
  • Information provided: What data was affected, what we’re doing, what you should do

To report a breach: Email [email protected]

Data Retention

We retain personal data only as long as necessary:

DataRetentionReason
Email inquiries30 days after resolvedResponding to requests
Server logs90 daysSecurity/troubleshooting
Analytics data38 monthsUnderstanding trends
CookiesSession or 1 yearTechnical necessity
Contact form data60 daysFollow-up purposes
Deletion requests1 yearLegal compliance

After retention period: Data is permanently deleted and cannot be recovered.

Contact & Complaints

Data Protection Inquiries

For any GDPR-related questions or to exercise your rights:

Email: [email protected]

Requests we handle:

  • Access requests
  • Deletion requests
  • Correction requests
  • Data portability requests
  • Objections
  • DPA requests
  • Data security inquiries

Response time: Within 30 days (or as specified per request)

Supervisory Authority / Data Protection Authorities

EEA residents have the right to lodge a complaint with their local Data Protection Authority.

Find your authority:

You do NOT need to contact us first to file a complaint.

Data Protection Officer (DPO) Contact

Currently, we do not have a dedicated Data Protection Officer (not required for our size/type).

However, our founder handles all privacy inquiries:

Privacy contact: [email protected]

If we appoint a DPO in the future, we will update this policy.

Legitimate Interests Assessment

For processing based on “legitimate interests,” we conduct Legitimate Interests Assessment (LIA) to ensure:

  • Processing is necessary
  • Your privacy interests don’t outweigh our interests
  • Safeguards are in place

Examples:

Analytics (legitimate interest):

  • Interest: Understand traffic, improve Site
  • Necessity: Required for Site operation
  • Balancing: Anonymized data, user can opt-out, minimal processing
  • Conclusion: Legitimate interest confirmed

Server logs (legitimate interest):

  • Interest: Prevent fraud, troubleshoot security
  • Necessity: Required for Site security
  • Balancing: Minimal data, 90-day retention, limited access
  • Conclusion: Legitimate interest confirmed

Sub-processors & Service Providers

We use service providers that process data on our behalf:

ProviderPurposeCountrySafeguard
CloudflareHosting & CDNUSAStandard Contractual Clauses
Google AnalyticsTraffic analyticsUSAStandard Contractual Clauses
Google AdSenseAdvertisingUSAStandard Contractual Clauses

For each provider, we have:

  • Data Processing Agreement in place
  • Commitment to GDPR compliance
  • Limited access to personal data

Your rights: You can request details about any service provider’s data processing.

Changes to This Policy

We may update this policy when:

  • GDPR requirements change
  • Our processing practices change
  • New service providers are added

How we notify you:

  • Update date posted at top of this page
  • Summary of changes included
  • Continued use of Site implies acceptance

Specific GDPR Provisions

Article 5 – Principles of Processing

Lawfulness, fairness, transparency

  • We only process with valid legal basis
  • We’re transparent about our practices
  • We don’t mislead you

Purpose limitation

  • We use data only for stated purposes
  • We don’t repurpose data secretly

Data minimization

  • We collect only necessary data
  • We don’t over-collect

Accuracy

  • We keep data accurate and up-to-date
  • You can correct inaccuracies

Storage limitation

  • We don’t retain data longer than necessary
  • We delete when no longer needed

Integrity and confidentiality

  • We protect data with security measures
  • We prevent unauthorized access

Article 13 & 14 – Information to Data Subjects

What we tell you:

  • What data we collect
  • Why we collect it (legal basis)
  • Who we share it with
  • How long we keep it
  • Your rights under GDPR
  • How to exercise your rights

You’re reading this now!

Article 25 – Data Protection by Design & Default

We implement:

  • Privacy by design (privacy built in)
  • Privacy by default (privacy is default)
  • Minimization of data collection
  • Limited retention periods
  • User control over data

Summary for EEA Residents

Your GDPR Rights – Quick Reference:

RightWhat it meansHow to exercise
Right to AccessSee what data we haveEmail us “Access Request”
Right to CorrectFix inaccurate dataEmail us with corrections
Right to ErasureDelete your dataEmail us “Deletion Request”
Right to RestrictLimit how we use dataEmail us “Restrict Processing”
Right to PortabilityGet your data in portable formEmail us “Portability Request”
Right to ObjectStop processing your dataEmail us “Object to Processing”
Right to ComplainReport to your data authorityContact your national authority

All requests: [email protected]

Response time: 30 days maximum

For any GDPR, privacy, or data protection questions:

Email: [email protected]

Include:

  • Your name
  • Your country (optional but helpful)
  • Specific question or concern
  • What right you’re exercising (if applicable)