Last updated: 2026-08-07

1. General information

This Privacy Policy explains how UAB GREEN ROSE processes personal data when you use the test.green-rose.eu website, purchase products from our online store, contact us or subscribe to our newsletter.

Data controller:
UAB GREEN ROSE
Company registration number: 302769484
VAT number: LT100006836613
Address: Laisvės pr. 117A, LT-06118 Vilnius, Lithuania
Email: info@test.green-rose.eu
Telephone: +370 656 44183

When processing personal data, we comply with applicable data protection legislation, including the General Data Protection Regulation (GDPR).

2. What personal data we collect

Depending on how you use our website or services, we may collect the following information:

  • your first name and surname;
  • telephone number;
  • email address;
  • delivery and billing address;
  • order details;
  • payment information, to the extent necessary to process and manage your order;
  • information contained in your correspondence with us;
  • newsletter subscription details;
  • account details if you register on the website;
  • technical information about your use of the website, including your IP address, browser type, device information, cookies and data collected through similar technologies.

3. Why we process your data and the legal grounds we rely on

We process your personal data for the following purposes:

3.1. Processing and managing orders
We process your data so that we can receive your order, confirm your purchase, prepare the products, arrange delivery, manage exchanges or returns and contact you regarding the fulfilment of your order. Legal basis: performance of a contract and taking steps before entering into a contract.

3.2. Accounting and compliance with legal obligations
We process data to issue invoices, manage payments, maintain accounting records and fulfil other obligations required by law. Legal basis: compliance with a legal obligation.

3.3. Handling enquiries, requests and complaints
We process data so that we can answer your questions and handle your requests, complaints or other communications. Legal basis: performance of a contract, compliance with a legal obligation or our legitimate interest in providing high-quality customer service and protecting our rights.

3.4. Direct marketing
Where you have provided separate consent, we process your email address and any other relevant information you provide to send newsletters, offers, promotions and product updates.
Legal basis: your consent.

3.5. Website operation, security and improvement
We process technical data, cookie data and information about how the website is used to ensure that it functions properly, protect it against misuse, analyse website traffic and improve its functionality. Legal basis: the need to operate the website, our legitimate interests and, where applicable, your consent to non-essential cookies.

3.6. Establishing, exercising or defending legal claims
Where necessary, we may process personal data to establish, exercise or defend legal claims. Legal basis: our legitimate interest in protecting our rights.

4. Where we obtain your data

We usually receive personal data directly from you when you:

  • place an order;
  • register on the website;
  • subscribe to the newsletter;
  • contact us by email, telephone or through another communication channel;
  • use our website.

In certain cases, we may also receive data from our service providers, such as payment or delivery partners, where this is necessary to process and manage your order.

5. Whether you are required to provide personal data

Certain information is necessary for us to enter into and perform a sales contract, deliver products, issue accounting documents or respond to your enquiry.

If you do not provide the required information, we may be unable to accept or fulfil your order, provide the requested service or respond to your enquiry. Where data is processed on the basis of consent, providing it is voluntary.

6. Who we may share your data with

Where necessary, we may share your personal data with the following categories of recipients:

  • payment service providers, including Montonio, Mollie, Stripe, Paysera and PayPal;
  • our newsletter service provider, Omnisend;
  • hosting, server, IT maintenance and website administration providers, including Hostinger and Hostex;
  • delivery, logistics and courier partners;
  • accounting, audit, legal and consultancy service providers;
  • national or local authorities, regulatory bodies and law enforcement agencies where disclosure is required by law.

We engage data processors only to the extent necessary to provide a particular service and take appropriate measures to ensure that your data is processed securely and lawfully.

7. Transfers of personal data outside the European Economic Area

Some of our service providers or their subprocessors may operate outside the European Economic Area. In such cases, personal data is transferred only where a lawful transfer mechanism is in place, such as:

  • an adequacy decision adopted by the European Commission;
  • Standard Contractual Clauses;
  • other appropriate safeguards permitted under the GDPR.

8. How long we retain your data

We retain personal data only for as long as necessary to fulfil the purposes described in this Privacy Policy or for as long as required by law.

We generally apply the following principles:

  • order, contract and customer-service data is retained for as long as necessary to fulfil orders, process returns, handle complaints and manage potential legal claims;
  • accounting and payment records are retained for the periods required by law;
  • correspondence and enquiry data is retained for as long as necessary to respond and for a reasonable period afterwards where a dispute or ongoing communication may arise;
  • newsletter subscription data is retained until you withdraw your consent or unsubscribe;
  • account data is retained for as long as the account remains active and for a reasonable period after it is closed where necessary for accounting, disputes or legal claims;
  • cookie data is retained for the lifetime specified for each individual cookie.

9. Cookies and similar technologies

Our website uses cookies and similar technologies. They help us ensure that the website functions properly, remember your preferences, analyse website traffic and, where you have provided consent, present more personalised content or advertising.

We may use the following categories of cookies:

9.1. Functional cookies
These cookies remember your preferences and improve your experience when using the website.

9.2. Funkciniai slapukai
Šie slapukai padeda įsiminti Jūsų pasirinkimus ir pagerina naudojimosi svetaine patirtį.

9.3. Analytics cookies
These cookies help us understand how visitors use the website and allow us to improve it.

9.4. Advertising and targeting cookies
These cookies are used for personalised advertising and remarketing.

Non-essential cookies are used only after you have given consent, where consent is required by law. You can change your cookie preferences at any time through the cookie-management tool available on our website or through your browser settings.

10. Newsletters and direct marketing

We use the Omnisend platform to send newsletters.

If you have agreed to receive newsletters, we may send you information about new products, promotions, offers and other GREEN ROSE-related updates.

You can withdraw your consent at any time by:

  • clicking the unsubscribe link included in any newsletter;
  • emailing us at info@test.green-rose.eu.

Withdrawing your consent does not affect the lawfulness of any processing carried out before the withdrawal.

11. Children’s personal data

Our website and online store are not intended for children to independently use consent-based services without the involvement of a parent or guardian.

Where personal-data processing is based on consent and information-society services are offered directly to a child, a child in Lithuania may provide their own consent from the age of 14.

Where the child is under 14, consent from a parent or guardian is required. If you believe that we have received a child’s personal data without an appropriate legal basis, please contact us.

12. Automated decision-making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

13. Your rights

You have the following rights in relation to your personal data:

  • the right to receive information about how your data is processed;
  • the right to access your personal data;
  • the right to have inaccurate data corrected or incomplete data completed;
  • the right to request deletion of your data where there is a legal basis for doing so;
  • the right to request restriction of processing where there is a legal basis for doing so;
  • the right to data portability where data is processed by automated means on the basis of consent or a contract;
  • the right to object to processing based on legitimate interests;
  • the right to withdraw consent at any time where processing is based on consent;
  • the right to lodge a complaint with the Lithuanian data protection authority.

To exercise your rights, contact us by email at info@test.green-rose.eu or by post at:

UAB GREEN ROSE
Laisvės pr. 117A
LT-06118 Vilnius
Lithuania

We will respond to your request without undue delay and no later than one month after receiving it. Where a request is complex or we receive a large number of requests, this period may be extended in accordance with applicable law.

You may lodge a complaint with the Lithuanian State Data Protection Inspectorate:

Valstybinė duomenų apsaugos inspekcija
L. Sapiegos g. 17
10312 Vilnius
Lithuania
Email: ada@ada.lt
Telephone: +370 5 271 28 04, +370 5 279 1445

14. Changes to this Privacy Policy

We apply appropriate technical and organisational measures to protect personal data against unlawful or accidental destruction, alteration, disclosure, loss, unauthorised access or any other unlawful form of processing.

These measures may include access controls, security measures within information systems, encryption of communications, backups and other proportionate safeguards.

15. Changes to this Privacy Policy

This Privacy Policy may be updated from time to time. The updated version takes effect from the date it is published on the website unless a different effective date is stated.