GDPR
Privacy Policy (GDPR Compliance Statement) for ASA Flower Bulbs
This Privacy Policy explains how ASA Flower Bulbs (“we,” “us,” or “our,” the Data Controller), located in Israel, collects, uses, and protects the limited personal data of visitors, particularly those from the European Economic Area (EEA), via our website, asa.co.il.
1. The Data Controller
The Data Controller responsible for your personal data is:
-
Legal Name: ASA Flower Bulbs
-
Location: Israel
-
Privacy Contact Email: info@asa.co.il (Please use this email for all data subject requests, including access, deletion, and rectification.)
2. Personal Data We Collect and Our Lawful Basis
We collect very limited personal data, primarily to respond to inquiries and analyze website performance. We do not offer sign-up, accounts, or e-commerce purchases.
| Activity/Source | Types of Personal Data Collected | Purpose of Processing | Lawful Basis (GDPR Article 6) | Retention Period |
| Contact Form | Name, Email Address, Message Content, (Technical: IP Address) | To respond to your direct inquiry regarding our flower manufacturing business. | Legitimate Interest (Responding to business inquiries) | Up to 3 years from the last contact. |
| Website Cookies (Google Analytics & Hotjar) | IP Address (anonymized), Browser Type, Pages Visited, Time Spent, Mouse Movements/Clicks (Hotjar) | To analyze website traffic, understand visitor interaction, and improve our website structure and performance. | Consent (Obtained via cookie banner) | Varies by cookie, typically 14 months for analytics data. |
3. Cookies and Tracking Technologies
We use cookies and similar technologies (like Google Analytics and Hotjar) to distinguish you from other users and analyze your use of the website.
-
Your Consent: We will not use non-essential cookies (Analytics, Hotjar) without your explicit consent. You can manage or withdraw your consent at any time via the cookie settings on our website.
-
Google Analytics: We use Google Analytics to collect statistics on website usage. We aim to implement IP address masking where possible to reduce identifiability.
-
Hotjar: We use Hotjar to understand user behavior on the site, which may involve recording mouse movements and scrolls. This data is aggregated and anonymized.
4. Sharing Your Personal Data
We only share your data with the third-party providers that enable our services. Since we are based in Israel, all data processing involves international transfers outside the EEA.
-
Recipients:
-
Google Analytics / Hotjar: For website performance analysis.
-
Upress Hosting: Our physical hosting provider in Israel, where contact form data is stored.
-
-
International Transfer Safeguards: Israel has been recognized by the European Commission as providing an adequate level of protection for personal data (an “Adequacy Decision”). This decision ensures that your data receives safeguards comparable to those in the EU when transferred to Israel. We also ensure our processors (like Google) rely on robust legal mechanisms like Standard Contractual Clauses (SCCs).
5. Data Security and Retention
-
Security: We have implemented appropriate security measures, including SSL/HTTPS encryption across the entire website, to protect your data from accidental loss, unauthorized access, or disclosure.
-
Retention: We only retain personal data for as long as necessary to fulfill the purposes we collected it for. Specifically, contact form leads are retained for up to 3 years to allow for necessary follow-up and legal defense.
6. Your Rights (EEA Data Subjects)
Under the GDPR, if you are a resident of the EEA, you have the following rights regarding your personal data. You can exercise these rights by contacting us at info@asa.co.il.
-
Right to Access: The right to ask for a copy of the personal data we hold about you.
-
Right to Rectification: The right to have inaccurate data corrected or completed.
-
Right to Erasure (“Right to be Forgotten”): The right to request the deletion of your personal data where there is no good reason for us to continue processing it.
-
Right to Restrict Processing: The right to ask us to suspend the processing of your data in certain scenarios.
-
Right to Object: The right to object to processing that is based on our legitimate interest.
-
Right to Withdraw Consent: Where we rely on consent (e.g., for analytics cookies), you have the right to withdraw that consent at any time.