Privacy Policy

Last updated: 27 July 2026

This policy explains what personal data Lumina Botanical Gardens collects, why we collect it, and what rights you have over it. We handle personal data in line with the EU General Data Protection Regulation (GDPR) 2016/679 and the Cyprus Law providing for the Protection of Natural Persons with regard to the Processing of Personal Data, Law 125(I)/2018.

Who is responsible for your data

The data controller is LUMINA GARDENS LTD, trading as Lumina Botanical Gardens, registration number HE 475170.

  • Address: 2 Ithakis Str, 7640, Kornos-Larnaca, Cyprus
  • Email: luminabotanicalgardens@gmail.com
  • Phone: +357 99973631

What we collect, and why

Tea house reservations

When you request a table through our reservations form we collect your name, email address, phone number, party size, the date and time you requested, any message you add, and the IP address the request came from.

We use this to contact you and hold your table. The lawful basis is Article 6(1)(b) GDPR — steps taken at your request before entering into a contract. The IP address is kept for spam prevention under Article 6(1)(f), our legitimate interest in keeping the form usable.

Reservation records are deleted 12 months after the reservation date.

Shop orders

When you buy from us we collect your name, billing and delivery address, email address, phone number, and the details of what you ordered. We need this to take payment, deliver your order, and handle returns. The lawful basis is Article 6(1)(b) — performance of a contract.

Order and invoice records are kept for as long as Cyprus tax and accounting law requires (currently six years) under Article 6(1)(c), compliance with a legal obligation.

Payments

Card payments are processed by Stripe. Your card number is entered directly into Stripe’s systems and never reaches our website or our staff. We receive only confirmation of the payment and the last four digits of the card. Stripe acts as an independent controller for fraud prevention purposes — see the Stripe Privacy Policy.

Customer accounts

If you create an account we store your name, email address, password (encrypted, never in readable form) and your saved addresses. You can edit or delete these at any time from your account page.

Emails and phone calls

If you email or call us we keep the correspondence so we can deal with your query and refer back to it. We delete it once it is no longer needed.

Server logs

Our hosting provider keeps standard access logs, including IP addresses, for security and troubleshooting. These are held under Article 6(1)(f) and rotated automatically.

Cookies

We use only cookies that are strictly necessary to run the website. We do not use advertising cookies, and we do not currently run any analytics or tracking service.

  • woocommerce_cart_hash, woocommerce_items_in_cart, wp_woocommerce_session_* — remember what is in your basket while you shop. Without these the shop cannot work.
  • woocommerce_recently_viewed — powers the «recently viewed products» display.
  • __stripe_mid, __stripe_sid — set by Stripe on the checkout page to detect fraudulent payments.
  • wordpress_logged_in_* — only set if you log in to an account.

Because these cookies are strictly necessary to provide a service you have asked for, we do not need to ask your consent for them. You can still block or delete cookies in your browser settings, but the basket and checkout will stop working if you do. If we ever add analytics or marketing cookies, we will ask for your consent first and update this page.

Who we share data with

We do not sell your personal data. We share it only with the service providers we need to run the business:

  • Stripe — payment processing.
  • Our web host — stores the website and its database.
  • Our email provider — delivers order and reservation emails.
  • Delivery couriers — receive the name, address and phone number needed to deliver your parcel.
  • Our accountant and, where legally required, the Cyprus tax authorities.

Where a provider processes data outside the European Economic Area, that transfer is covered by the European Commission’s Standard Contractual Clauses or an adequacy decision.

Your rights

Under the GDPR you have the right to:

  • ask for a copy of the personal data we hold about you;
  • have inaccurate data corrected;
  • ask us to delete your data, where we have no legal reason to keep it;
  • ask us to restrict how we use it;
  • receive your data in a portable, machine-readable format;
  • object to processing we carry out on the basis of legitimate interests;
  • withdraw consent at any time, where we relied on consent.

To exercise any of these, email us at luminabotanicalgardens@gmail.com. We will respond within one month.

If you are not satisfied with our response you can complain to the Office of the Commissioner for Personal Data Protection, 15 Kypranoros Street, 1061 Nicosia, Cyprus — www.dataprotection.gov.cy.

Security

The website is served over an encrypted HTTPS connection, access to the admin area is restricted and password-protected, and card data never touches our systems. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your data.

Children

Our shop is not intended for children. We do not knowingly collect personal data from anyone under 16. Children are welcome to visit the gardens and attend workshops accompanied by an adult, who makes the booking.

Changes to this policy

If we change how we handle personal data we will update this page and the date at the top.