GDPR & EEA Compliance
Last Updated: August 2026
This policy explains how Indoor Plant Care Guide complies with the General Data Protection Regulation (GDPR) and applies to all visitors in the European Economic Area (EEA), including the EU, Iceland, Liechtenstein, and Norway.
What is GDPR?
The General Data Protection Regulation (GDPR) is a European Union law that protects the privacy and data rights of individuals in the EEA.
GDPR requires organizations to:
- Be transparent about what data they collect
- Obtain consent before collecting personal data (with limited exceptions)
- Protect personal data with strong security measures
- Allow individuals to access, correct, and delete their data
- Report data breaches within 72 hours
- Appoint a Data Protection Officer (if applicable)
- Have valid legal bases for processing data
Our commitment: Indoor Plant Care Guide fully complies with GDPR.
Legal Basis for Processing
We only process personal data when we have a valid legal basis under GDPR Article 6.
Consent
What data: Email address (when you contact us)
Legal basis: Explicit consent to receive and respond to your message
Your rights: Withdraw consent anytime by emailing us
Our obligation: Stop processing and delete your data within 30 days
Legitimate Interests
What data: Server logs, analytics data, cookies
Legal basis: Legitimate interest in operating and improving the Site
Our interest: Understand traffic, improve performance, prevent fraud
Your rights: Object to processing anytime (see section 6)
Balancing test: Your privacy interests don’t outweigh our legitimate interests (minimal data, anonymized, aggregate analytics)
Legal Obligation
What data: Server logs (for security and fraud prevention)
Legal basis: Legal obligation to prevent misuse and comply with law
Our obligation: Retain only as long as legally required, then delete
Data Protection Rights (GDPR Articles 15-22)
Right to Access (Article 15)
You have the right to know what personal data we process about you.
What you can request:
- Confirmation that we process your data
- Copy of your personal data
- Details about how we use your data
- Information about data recipients
- Retention period
How to request:
Email: [email protected]
Subject: “GDPR – Right to Access”
Include: Your name and email address
Our response time: Within 30 days (extendable to 60 days for complex requests)
Right to Rectification (Article 16)
You have the right to correct inaccurate personal data.
What you can do:
- Request correction of incomplete or inaccurate data
- Request deletion if data is no longer necessary
- Request update of outdated information
How to request:
Email: [email protected]
Subject: “GDPR – Right to Rectification”
Include: Your name, what data needs correction, and corrected information
Our response time: Within 30 days
Right to Erasure / “Right to Be Forgotten” (Article 17)
You have the right to request deletion of your personal data.
We will delete data if:
- Data is no longer necessary for the purpose collected
- You withdraw your consent
- You object to processing and there’s no overriding legitimate interest
- Data has been unlawfully processed
- You request deletion
We may NOT delete data if:
- Required by law
- Necessary for legal claims
- Data is part of a legitimate defense
How to request:
Email: [email protected]
Subject: “GDPR – Right to Erasure”
Include: Your name and confirmation you want all data deleted
Our response time: Within 30 days (data deleted immediately after confirmation)
Right to Restrict Processing (Article 18)
You have the right to restrict how we use your personal data.
You can request we:
- Stop processing your data (but keep it)
- Only process for specific purposes
- Limit who has access to your data
How to request:
Email: [email protected]
Subject: “GDPR – Right to Restrict”
Include: Your name and how you want processing restricted
Our response time: Within 30 days
Right to Data Portability (Article 20)
You have the right to receive your personal data in a portable format.
What we provide:
- Your personal data in a structured format (e.g., CSV, JSON)
- In a commonly used, machine-readable format
- Data you provided to us (not data we generated about you)
How to request:
Email: [email protected]
Subject: “GDPR – Right to Data Portability”
Include: Your name and preferred format
Our response time: Within 30 days
Note: We collect minimal personal data (mainly email). Data portability is straightforward.
Right to Object (Article 21)
You have the right to object to processing of your personal data.
You can object to:
- Processing based on legitimate interests
- Processing for direct marketing
- Processing for profiling
What happens after objection:
- We will stop processing unless we have overriding legitimate interest
- We will explain why we can’t comply (if applicable)
How to object:
Email: [email protected]
Subject: “GDPR – Right to Object”
Include: Your name and reason for objection
Our response time: Within 30 days
Right Not to Be Subject to Automated Decision-Making (Article 22)
You have the right not to be subject to automated decisions that produce legal or similarly significant effects.
Our practice: We do not make automated decisions about you. All decisions are made by humans.
Data Processing Agreement (DPA)
For businesses and organizations: If you process data on behalf of an organization, you may need a Data Processing Agreement (DPA) with us.
We are happy to sign a standard DPA or provide our DPA template.
To request a DPA:
Email: [email protected]
Subject: “DPA Request”
Include: Your organization name and data processing description
Response time: Within 15 business days
International Data Transfers
Important: The United States does not have the same data protection level as the EEA.
If you’re in the EEA and your data is transferred to the US (for hosting or analytics), we ensure adequate safeguards:
Standard Contractual Clauses (SCCs)
We use Standard Contractual Clauses (SCCs) with all US-based service providers to ensure data protection equivalent to GDPR.
Service providers using SCCs:
- Cloudflare (hosting)
- Google Analytics (analytics)
- Google AdSense (advertising, when launched)
Adequacy Decisions
We only transfer data to countries with:
- Adequacy decisions from the European Commission, OR
- Standard Contractual Clauses in place
Your Rights
You have the right to:
- Know about international transfers
- Request what safeguards are in place
- Object to transfers
- Request data stay within the EEA
To request: Email [email protected] with “Data Transfer Inquiry”
Cookie Consent & Preferences
Consent for Non-Essential Cookies
Essential cookies: We set without consent (necessary for Site function)
Non-essential cookies: We ask for consent before setting
How to manage:
- Accept/reject cookies on our cookie banner
- Update preferences anytime in browser settings
- Withdraw consent anytime
Cookie Types
| Type | Purpose | Consent Required | Retention |
| Session cookies | Technical necessity | No | Session |
| Preference cookies | Remember settings | No | 1 year |
| Analytics cookies | Understanding traffic | Yes (GDPR) | 38 months |
| Advertising cookies | Show relevant ads | Yes (GDPR) | 13 months |
Your choice: You can disable non-essential cookies without losing Site functionality.
Data Security
Security Measures
We implement:
- HTTPS encryption: All data in transit is encrypted
- Firewall protection: Network-level security
- Secure hosting: Industry-standard security practices
- Limited access: Only authorized personnel access personal data
- Regular monitoring: We monitor for suspicious activity
- Annual reviews: We review security practices annually
Data Breach Notification
If a data breach occurs affecting your personal data:
- EEA residents: We notify you within 72 hours (as required by GDPR)
- All residents: We notify promptly
- Information provided: What data was affected, what we’re doing, what you should do
To report a breach: Email [email protected]
Data Retention
We retain personal data only as long as necessary:
| Data | Retention | Reason |
| Email inquiries | 30 days after resolved | Responding to requests |
| Server logs | 90 days | Security/troubleshooting |
| Analytics data | 38 months | Understanding trends |
| Cookies | Session or 1 year | Technical necessity |
| Contact form data | 60 days | Follow-up purposes |
| Deletion requests | 1 year | Legal compliance |
After retention period: Data is permanently deleted and cannot be recovered.
Contact & Complaints
Data Protection Inquiries
For any GDPR-related questions or to exercise your rights:
Email: [email protected]
Requests we handle:
- Access requests
- Deletion requests
- Correction requests
- Data portability requests
- Objections
- DPA requests
- Data security inquiries
Response time: Within 30 days (or as specified per request)
Supervisory Authority / Data Protection Authorities
EEA residents have the right to lodge a complaint with their local Data Protection Authority.
Find your authority:
- EU: European Data Protection Board – Find Your Authority
- Iceland: Persónuvernd
- Norway: Datatilsynet
- Liechtenstein: Office of the Data Protection Commissioner
You do NOT need to contact us first to file a complaint.
Data Protection Officer (DPO) Contact
Currently, we do not have a dedicated Data Protection Officer (not required for our size/type).
However, our founder handles all privacy inquiries:
Privacy contact: [email protected]
If we appoint a DPO in the future, we will update this policy.
Legitimate Interests Assessment
For processing based on “legitimate interests,” we conduct Legitimate Interests Assessment (LIA) to ensure:
- Processing is necessary
- Your privacy interests don’t outweigh our interests
- Safeguards are in place
Examples:
Analytics (legitimate interest):
- Interest: Understand traffic, improve Site
- Necessity: Required for Site operation
- Balancing: Anonymized data, user can opt-out, minimal processing
- Conclusion: Legitimate interest confirmed
Server logs (legitimate interest):
- Interest: Prevent fraud, troubleshoot security
- Necessity: Required for Site security
- Balancing: Minimal data, 90-day retention, limited access
- Conclusion: Legitimate interest confirmed
Sub-processors & Service Providers
We use service providers that process data on our behalf:
| Provider | Purpose | Country | Safeguard |
| Cloudflare | Hosting & CDN | USA | Standard Contractual Clauses |
| Google Analytics | Traffic analytics | USA | Standard Contractual Clauses |
| Google AdSense | Advertising | USA | Standard Contractual Clauses |
For each provider, we have:
- Data Processing Agreement in place
- Commitment to GDPR compliance
- Limited access to personal data
Your rights: You can request details about any service provider’s data processing.
Changes to This Policy
We may update this policy when:
- GDPR requirements change
- Our processing practices change
- New service providers are added
How we notify you:
- Update date posted at top of this page
- Summary of changes included
- Continued use of Site implies acceptance
Specific GDPR Provisions
Article 5 – Principles of Processing
Lawfulness, fairness, transparency
- We only process with valid legal basis
- We’re transparent about our practices
- We don’t mislead you
Purpose limitation
- We use data only for stated purposes
- We don’t repurpose data secretly
Data minimization
- We collect only necessary data
- We don’t over-collect
Accuracy
- We keep data accurate and up-to-date
- You can correct inaccuracies
Storage limitation
- We don’t retain data longer than necessary
- We delete when no longer needed
Integrity and confidentiality
- We protect data with security measures
- We prevent unauthorized access
Article 13 & 14 – Information to Data Subjects
What we tell you:
- What data we collect
- Why we collect it (legal basis)
- Who we share it with
- How long we keep it
- Your rights under GDPR
- How to exercise your rights
You’re reading this now!
Article 25 – Data Protection by Design & Default
We implement:
- Privacy by design (privacy built in)
- Privacy by default (privacy is default)
- Minimization of data collection
- Limited retention periods
- User control over data
Summary for EEA Residents
Your GDPR Rights – Quick Reference:
| Right | What it means | How to exercise |
| Right to Access | See what data we have | Email us “Access Request” |
| Right to Correct | Fix inaccurate data | Email us with corrections |
| Right to Erasure | Delete your data | Email us “Deletion Request” |
| Right to Restrict | Limit how we use data | Email us “Restrict Processing” |
| Right to Portability | Get your data in portable form | Email us “Portability Request” |
| Right to Object | Stop processing your data | Email us “Object to Processing” |
| Right to Complain | Report to your data authority | Contact your national authority |
All requests: [email protected]
Response time: 30 days maximum
For any GDPR, privacy, or data protection questions:
Email: [email protected]
Include:
- Your name
- Your country (optional but helpful)
- Specific question or concern
- What right you’re exercising (if applicable)
