Política de privacidad

Ecozzie is responsible for the processing of personal data as reflected in this privacy statement (the “Policy”). Ecozzie acts as the data controller for the processing described below.

Contact details

Ecozzie
info@ecozzie.com
Kwikstaartlaan 42, Box C788
3704.  Zeist, Utrecht. The Netherlands.
KVK number: 96501685 · BTW/VAT number: NL005213857B80

Personal data we process

We process personal data because you use our services and/or because you provide them to us. This may include:

  • Identification and contact data: first and last name, e-mail address.
  • Account data: username, password (stored hashed), preferences.
  • Content you add: plant profiles, care logs, notes, photos and other user-generated content associated with your account.
  • Technical data: IP address, device and browser type, language, time zone, approximate location (derived from IP), session identifiers.
  • Usage data: information about your activity on our website/app.
  • Cross-site browsing data where third-party cookies are accepted (e.g., analytics/ads).
  • Billing data (if you purchase paid features): name, address, tax identifiers, transaction details (processed via payment providers).

Special and/or sensitive personal data

Our services are not intended for children under 16 years old, unless with parental/guardian consent. We cannot verify ages. We encourage parents to be involved in their children’s online activities. If you believe we have collected data about a minor without consent, contact info@ecozzie.com and we will delete it.

Purposes and legal bases

We process your personal data for the following purposes and on the following legal bases under the GDPR:

  • Account creation and service delivery (e.g., storing your plant records and care history, enabling QR code features).
    Legal basis: performance of a contract (Art. 6(1)(b)).
  • Customer support and service communications (responding to enquiries, notifying about changes or incidents).
    Legal basis: performance of a contract (Art. 6(1)(b)) and legitimate interests in service quality (Art. 6(1)(f)).
  • Payments and invoicing (when applicable).
    Legal basis: performance of a contract (Art. 6(1)(b)) and legal obligation for tax/accounting (Art. 6(1)(c)).
  • Newsletter and marketing communications (when you subscribe).
    Legal basis: consent (Art. 6(1)(a)); you may withdraw at any time.
  • Analytics and service improvement (measuring usage to improve features and performance).
    Legal basis: consent for non-essential cookies (Art. 6(1)(a)); legitimate interests for strictly necessary analytics where applicable (Art. 6(1)(f)).
  • Security and fraud prevention (e.g., logging access, abuse prevention).
    Legal basis: legitimate interests (Art. 6(1)(f)) and legal obligations (Art. 6(1)(c)).

Automated decision-making

Ecozzie does not make decisions based solely on automated processing that produce legal effects or similarly significant effects on individuals. We are humans behind screens that talk about plants and nature.

How long we keep personal data

We keep data no longer than necessary for the purposes for which it was collected. Typical retention periods are:

  • Account and user-generated content (plant profiles, care logs): retained while your account is active; deleted upon account deletion.
  • Support communications: up to 24 months after closure of the request.
  • Newsletter data: until you unsubscribe or withdraw consent.
  • Technical logs: 12-24 months, unless needed longer for security/incidents.
  • Cookies: according to each cookie’s expiry (see Cookies section).
  • Billing and tax records: retained for the statutory period (typically 7 years in the Netherlands).

Sharing personal data with third parties

We share data with third-party processors where necessary to provide our services and to comply with the law. We sign data processing agreements to ensure an appropriate level of security and confidentiality. Ecozzie remains responsible for such processing. We will only share data with other third parties when you have given explicit consent or when required by law.

Categories of recipients may include:

  • Hosting and infrastructure: web hosting, backups, content delivery and security (these providers may process IP addresses and technical logs).
  • WordPress plugins and service providers strictly necessary to operate the site (e.g., Elementor/Forms, user account plugins, performance and security plugins) to the extent they process personal data on our behalf.
  • Analytics: Google Analytics for aggregated usage statistics (subject to your cookie choices).
  • Email and marketing: Mailchimp for newsletters and service emails (only if you subscribe or we need to send essential service messages).
  • Payments: payment gateways and financial institutions for processing transactions (if/when paid features are offered).

International transfers

Some providers may be located outside the European Economic Area (EEA), including in the United States. Where such transfers occur, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, additional technical and organizational measures to protect your data.

Cookies (and similar technologies)

Ecozzie uses functional, analytical and (where consented) tracking cookies. Cookies are small files stored on your device to ensure the site works properly, remember preferences, measure usage and, where applicable, tailor content/ads.

On your first visit we inform you about cookies and request your consent for non-essential cookies. You can withdraw consent at any time via your browser settings and/or our cookie banner settings. You can also delete cookies via your browser.

Third parties may set cookies via our site (e.g., analytics, embedded content, social media). Below is an example:

  • Cookie: Google Analytics
    Name: _utma (and similar, depending on configuration)
    Function: measures website traffic (analytics)
    Retention: up to 24 months

For full details, please see our separate Política de cookies, which lists cookies used, purposes and lifetimes, and allows you to change your preferences.

Your rights

You have the right to request access to, rectification or erasure of your personal data; to restrict or object to processing; and to data portability. Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of processing before withdrawal.

To exercise your rights, contact info@ecozzie.com. To verify your identity, we may ask for limited information. If you send ID documentation, please redact your photo, MRZ, document number and BSN. We aim to respond within 4 weeks.

You also have the right to lodge a complaint with the Dutch supervisory authority (Autoriteit Persoonsgegevens): https://autoriteitpersoonsgegevens.nl/nl/contact-met-de-autoriteit-persoonsgegevens/tip-ons

How to delete your account

You can request deletion of your account and associated content (including plant records and care logs) by contacting info@ecozzie.com  or directly on your profile settings. Note that we may retain certain data where required by law (e.g., billing records).

Security

We take appropriate technical and organizational measures to protect your data against unauthorized access, alteration, disclosure or destruction, including encryption in transit (HTTPS), access controls, backups and monitoring. If you believe your data is not adequately secured or suspect misuse, contact info@ecozzie.com.

Changes to this Policy

We may update this Policy from time to time. If we make material changes, we will notify you through the website or by email. The date of the latest update will be indicated here: September 22nd 2025.