Privacy Notice (Personal Data Processing)
Our website address is: https://naboistockholm.com
This Privacy Notice explains how NABOI (“we”, “us”, “our”) collects and processes your personal data when you use our website, create an account, place an order, contact us, or subscribe to our newsletter.
We are committed to protecting your privacy and handling your data in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
1. What is “personal data”?
“Personal data” means any information that relates to an identified or identifiable natural person. This includes your name, contact details, online identifiers, and information related to your orders.
2. Data Controller (Who is responsible?)
The data controller responsible for processing your personal data is:
NABOI
Registered address: Athos väg 22A, 18492 Åkersberga, Sweden
VAT number: SE831002234101
Email: info@naboistockholm.com
3. What data we collect
We only collect data that is necessary for the purposes described below. Depending on how you use our website, we may process:
- Identity & contact data: name, email address, phone number, billing and shipping address
- Order & transaction data: purchased items, order details, payments (processed via payment providers), refunds, returns
- Account data: login and account details (if you create an account)
- Customer support data: messages you send us and related correspondence
- Technical data: IP address, browser type, device information, and website usage data (via cookies and similar technologies)
We do not require national identification numbers for purchases on our website.
4. How we collect your data
We collect data:
- directly from you when you place an order, create an account, or contact us
- automatically through your use of the website (cookies and analytics)
- from service providers necessary to fulfil your order (e.g. payment processors and delivery services)
5. Why we process your data (purposes)
We process your personal data to:
- manage your registration and customer account (if created)
- process and deliver your orders and provide customer service
- handle returns, refunds, complaints, and other requests
- send service-related communications (order confirmations, shipping updates)
- send marketing messages/newsletters only if you have consented (you can unsubscribe at any time)
- improve our website, services, and user experience
- meet legal obligations (e.g. accounting and tax requirements)
If you provide personal data of third parties (e.g. for gift delivery), you confirm that you have informed them and obtained permission where required.
6. Legal basis for processing
We process personal data based on one or more of the following legal grounds:
- performance of a contract
- legal obligation
- legitimate interests (e.g. customer support, fraud prevention, service improvement)
- consent (e.g. marketing and non-essential cookies)
You can withdraw your consent at any time.
7. Data retention (how long we keep data)
We retain personal data only as long as necessary:
- account data: while your account is active
- order data: as required for order fulfilment and legal obligations (e.g. accounting laws)
- customer support data: as needed to resolve requests
- marketing data: until you unsubscribe or withdraw consent
- cookies and analytics data: according to retention settings
We may retain data longer where required by law or for legal claims.
8. Who we share data with (recipients)
We share your data only where necessary with trusted service providers, such as:
- hosting and IT providers
- payment service providers
- shipping and courier services
- analytics providers
- email marketing tools (if used)
All providers are required to protect your data and process it only on our instructions.
We may also disclose data to authorities if required by law.
9. International data transfers
Some of our service providers may be located outside the European Economic Area (EEA).
In such cases, we ensure that appropriate safeguards are in place, such as:
- Standard Contractual Clauses (SCCs) approved by the European Commission
- or other lawful transfer mechanisms under GDPR
10. Your rights under GDPR
You have the right to:
- access your personal data
- request correction of inaccurate data
- request deletion (where applicable)
- restrict processing
- object to processing (especially for marketing)
- data portability
- withdraw consent at any time
To exercise your rights, contact us at: info@naboistockholm.com
You also have the right to lodge a complaint with a supervisory authority in your country of residence or work.
For Sweden:
Swedish Authority for Privacy Protection (IMY)
11. Cookies
Cookies are small text files stored on your device. We use cookies to:
- ensure website functionality
- remember preferences
- analyze traffic and improve performance
- support marketing (where applicable)
Non-essential cookies are only used with your consent via our cookie banner.
You can manage cookies through your browser settings or consent tool.
12. Automated decision-making
We do not use automated decision-making or profiling that produces legal or similarly significant effects.
13. Data security
We apply appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, or misuse, including encryption and secure processing by trusted providers.
14. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The latest version will always be available on the Website.
15. Contact
If you have any questions regarding this Privacy Policy or data protection, please contact us at:
info@naboistockholm.com