This privacy policy explains how the web pages and services on www.whitelilies.lol, which are developed and operated by the developer WhiteLilies on behalf of White Lilies (HK) Supply chain Limited, collect, use and safeguard your information. White Lilies (HK) Supply chain Limited has its registered place of business at Rm 703 7/F Winfield Commercial Building, 6-8A Prat Avenue, Tsim Sha Tsui, Hong Kong (HK).
White Lilies (HK) Supply chain Limited is a company providing computer integrated systems design, professional, scientific and technical computing services, and related support from Rm 703 7/F Winfield Commercial Building, 6-8A Prat Avenue, Tsim Sha Tsui, Hong Kong (HK). The services and tools made available through this website are developed and operated by the developer WhiteLilies and are offered to you the visitor and customer.
This policy is written to be plain and readable. Where the terms WhiteLilies, White Lilies or the Company appear below, they refer to the operator White Lilies (HK) Supply chain Limited and to the developer WhiteLilies where the context reasonably indicates the development team.
We ask that you read this policy together with our terms of service, which you can reach from the footer of any page. This policy governs information we gather when you visit our website, when you send us an enquiry, and when you use the systems that we build and operate for our customers.
This policy applies to personal data collected through the public pages of www.whitelilies.lol, through direct email and telephone correspondence with us, and through contact forms that you complete on our site. It does not apply to the separate systems or applications that may be operated under a customer agreement with your employer, unless those systems direct you to a privacy notice of their own.
Personal data means information relating to an identified or identifiable natural person, such as your name, email address, telephone number or any other detail that could reasonably identify you. Where we serve professional customers, the information we hold is usually business contact information belonging to the business rather than personal information about an individual in a private capacity.
If you are unsure whether this policy applies to a particular contact with us, we will be glad to clarify when you reach us at relay@whitelilies.lol.
The amount and type of information we collect depends on how you use our site and services. We aim to collect only what is useful and to avoid surplus data.
When you send us a message through our contact page, we receive the name, email address and message that you choose to type. When you telephone us at +15154814552, we may hear and later record business details such as your company name and the reason for your call, but we keep call content only for the purpose you give it for.
We are a Business to Business operation. When you ask us for a quote or an order, we collect your organisation name, the contact name and role, email, telephone, delivery address and the specifics of the flowers or computing services you have requested. These details support the order you asked us to fulfil.
Like most websites, our server logs record the internet protocol address of the device you used, the pages you visited, the approximate time and date, and the type of browser you ran. We keep these records at a summary level to fix errors, guard against misuse and understand which of our pages are genuinely useful.
We do not seek to gather your precise location, stored files or private browsing activity, and we have no interest in your personal correspondence beyond the messages you send to us.
We gather information in three clear ways, each under a distinct heading so you always know the source.
We do not purchase personal data, we do not trawl social platforms for private profiles, and we do not ask third parties to observe your behaviour across other websites so that we may advertise to you.
We use the information we collect for purposes that are straightforward and closely tied to the reason it was given. Responding to your enquiries and preparing quotations for flower sourcing, cold chain freight, conditioning, grading, event and hotel programs, retail bundles and waste bloom recovery.
Delivering agreed orders and sending you the delivery confirmations, invoices and service notices connected to those transactions.
Providing support and maintenance for computing systems and integrated design services that we operate on your behalf.
Sending genuinely useful service messages, security alerts or policy changes that you have a real interest in receiving.
Improving our website by studying broad, non-identifying usage patterns so we can put the most helpful content where it does the most good.
Meeting our legal and accounting duties, including keeping records we are obliged by Hong Kong law to maintain.
We do not sell your personal information to anyone, and we do not use it for automated profiling that would make decisions about you on our own without human involvement and without your say.
Where the data protection laws of your country apply to our use of your information, we rely on the following bases for taking your details forward.
The contract basis. Most of our processing exists to prepare, perform or support a contract with you or with your organisation, such as an order for cut flowers or an agreement to design and maintain a system.
The legitimate interest basis. For modest actions such as keeping the website secure, answering your message, or sending a relevant service update, we rely on our legitimate interest in running an honest business and your reasonable expectation that an enquiry you send will be answered.
The consent basis. Where we wish to use your details for a purpose that goes beyond the reason you gave them, we will ask for your clear consent first, and you may withdraw that consent at any time without penalty.
The legal obligation basis. We hold a limited set of records because Hong Kong commercial and tax law requires us to keep them, and those records are used only as the law directs.
We keep personal information only for as long as it is genuinely needed for the purpose it was collected, or for as long as the law requires. An enquiry we answer quickly is retired once it is no longer needed to serve you. An order record is kept for the period needed to settle invoices, answer disputes and satisfy tax rules.
Where we can do so, we delete or anonymise obsolete records rather than storing them forever. We review the age and usefulness of contact data on a routine schedule, which we regard as part of running a tidy, trustworthy business.
We do not rent, sell or trade your personal information. The only outside parties that may lawfully see your data are the following, each bound by duty or by contract to protect it.
Before working with anyone, we satisfy ourselves that they protect data responsibly. We do not permit our delivery or hosting partners to use the personal details we share for their own marketing.
A core principle of this policy is that we use your data for the reason you gave it and for nothing that would surprise you. If we wish to repurpose information for a new use that is not compatible with the original purpose, we inform you and obtain a fresh, lawful basis before continuing.
Where the new use would rely on your consent, we pause that use until you agree. This keeps the rule simple: your information follows the job it was given, and it does not quietly migrate into unrelated schemes.
You hold certain rights over the personal information we hold about you, and we take steps to honour them without fuss. Depending on the law that applies to you, these may include the following.
You may raise any of these by writing to relay@whitelilies.lol or to our office at the address above. We answer every reasonable request and we will confirm the action we have taken within a sensible period after responding to you.
Where our processing is based on your consent, you may give it or withhold it freely. You may withdraw consent at any time, and withdrawal will not affect the lawfulness of processing we already carried out while you had agreed.
We try to make consent simple and specific rather than buried in dense wording. If ever a request appears unclear, we will ask a short confirming question rather than assume you agreed to a wider use than you intended.
We apply a simple retention discipline so that no record lives longer than it earns its place. Contact enquiries and quotations are reviewed and retired when they become inactive. Transaction and invoice records are held for the statutory period set by commercial and tax law. Security and server logs are kept at summary level and retained only as long as useful for guarding the service.
Where no legal duty requires us to keep a record, we delete or anonymise it as soon as the purpose is complete. This discipline reduces the risk that stale or surplus data might ever be misused.
Our website uses a small number of technical and functional cookies needed for the site to work correctly, such as remembering a temporary preference or keeping a session stable. We do not use advertising or cross-site tracking cookies, and we do not follow you to build a marketing profile.
You can control cookies through your own browser settings, and most browsers allow you to block them entirely. Because our cookies are modest and non-commercial, blocking them should not prevent you from reading our pages or sending us a message.
Should our business be sold, merged or reorganised, customer and contact records may transfer to the buyer or successor so that services can continue without interruption. If that ever happens, we will require the successor to observe a level of data protection at least as strict as the commitments in this policy, and we will update this page to name the new operator.
We will not treat a business transfer as a reason to expose your data to marketing by parties you have never met.
You may ask us to erase personal information we hold about you, and we will act unless the law or an active contract requires us to keep it. When a record relates to an ongoing order, we will complete that order and then remove the surplus detail.
To make an erasure request, write to relay@whitelilies.lol with your name and the address or account you believe we hold. We will treat the request promptly and, where required, pass the erasure on to any third party to whom we lawfully transmitted your details.
Our services are directed at professional customers and are not intended for children. We do not knowingly collect personal information from anyone below the applicable age of consent, and our business pages will not be attractive or appropriate to a young child.
If you are a parent or guardian and you believe your child has sent us personal information without your permission, please write to relay@whitelilies.lol and we will delete it as soon as we can confirm the situation.
We protect personal information with safeguards appropriate to its sensitivity. Access to personal records is limited to the staff who need it to serve you, and they are required to treat it confidentially. Our website is served over a secure connection, and we follow standard hygiene practices for systems under our care.
No method of transmission or storage is perfect, and we cannot promise absolute safety against every possible intrusion. We do promise to handle your data carefully, to replace weak controls quickly when we learn of them, and to tell you plainly if a failure ever touches your information.
We keep technical logs to keep the site stable and to detect abuse such as automated attacks, attempts to break in, or attempts to overload our servers. These logs capture addresses and timestamps at summary level and are not mined for personal trivia.
We reserve the right to disclose information to lawful authorities if we discover evidence of criminal or harmful behaviour against our systems or our customers, acting only as the law permits.
We do not make significant decisions about you solely through automated means, without human involvement, where such a decision would have a serious effect on you. Any scoring, filtering or ranking that might occur inside our supply systems is technical configuration rather than an assessment of you as a person.
Should that ever change, we will update this policy to say so clearly and to set out how you can seek human review.
If a security failure ever puts your personal information at real risk, we will act without delay. Where the law requires it, we will notify the relevant authority and, where the risk is high, we will tell you directly so you can take sensible precautions.
We keep a record of any incident that touches personal data, and we review what went wrong so that the same failure does not repeat.
Your information may be processed by the operator or by service partners in Hong Kong and other locations chosen for the reliable running of our systems. Where personal data crosses borders, we rely on safeguards that the relevant law recognises, such as standard contractual clauses, or we process only in jurisdictions considered to offer an adequate level of protection for the purpose.
We will not scatter your data across uncontrolled servers, and we will only move it where the protection travels with it.
In addition to access controls and secure connections, we apply sensible measures such as keeping software updated, limiting privileges, using strong authentication where it matters, and reviewing access from time to time. We treat security as a continuous duty rather than a single tick box.
We welcome and investigate reports of weakness in our pages or systems, and we aim to correct a confirmed fault quickly and without defensiveness.
Our pages may point to external websites, such as delivery or payment partners, that we do not control. We hope you find them useful, but we are not responsible for their content or their privacy practices, and this policy stops applying the moment you leave our pages.
Before you share personal data on an external site, we encourage you to read that site own privacy notice so your choice is an informed one.
We will update this policy from time to time as our services, technology or legal duties change. The date at the top of this page tells you when the most recent revision was made, and any change becomes effective when the revised text is published here.
Where a change is important and might affect the choices you rely on, we will draw it to the attention of customers we hold a current address for, rather than letting you discover it accidentally.
You share a small duty in keeping data accurate and safe. Please provide us with current details and tell us when something important changes, such as a delivery address or a contact email. When you send us information by mail or telephone, only send what is needed for the enquiry.
Where you act for an organisation, you confirm that you are authorised to share the business data you put before us, and we will treat that data as belonging to the organisation you represent.
White Lilies (HK) Supply chain Limited, Rm 703 7/F Winfield Commercial Building, 6-8A Prat Avenue, Tsim Sha Tsui, Hong Kong (HK). Company developer WhiteLilies.
For any question about this policy or about data we may hold about you, please email relay@whitelilies.lol or call +15154814552. We will answer clearly, and if you are not satisfied with how we handle a rightful request, you may lodge a complaint with your local data protection authority, whose details we will gladly point you toward.