1. General provisions
1.3 Eva Solo is the controller responsible for your personal data. All inquiries to Eva Solo can be made via the contact details provided under Item 7.
2. The personal data we collect, and the purposes of, and the legal basis for, our data processing
2.1 When you visit our Website, we automatically collect data concerning you and your use of the Website, such as the type of browser you use, the search terms you use on the Website, your IP address, including your network location, and information about your computer.
2.1.1 The purpose of this is to enhance the user experience and functionality of our Website, and to carry out targeted marketing, including retargeting via Facebook and Google. This data processing is necessary in order for us to pursue our interests in improving our Website and in presenting you with relevant offers.
2.1.2 The legal basis for our processing is point (f) of Article 6(1) of the GDPR.
2.2 When you purchase a product or communicate with us on our Website, we collect the data you provide us with, such as your name, address, e-mail address, telephone number, payment method, information about which products you purchase and may have returned, your delivery preferences and information about the IP address from which your order was placed.
2.2.1 The purpose of this is for us to be able to supply the products you have ordered and otherwise to fulfil our agreement with you, including in order to administrate your right to cancel and right of complaint. We may also process data concerning your purchases in order to comply with legal requirements such as for bookkeeping and accounting purposes. Your IP address is collected when you make a purchase for the purpose of protecting our interest in fraud prevention.
2.2.2 The legal basis for our processing of your data for this purpose is points (b), (c) and (f) of Article 6(1) of the GDPR.
2.3 When you subscribe to our newsletter, we collect data on your e-mail address and where you subscribed.
2.3.1 The purpose of this is to pursue our interest in being able to supply newsletters to you.
2.3.2 The legal basis for our processing is point (f) of Article 6(1) of the GDPR.
3. Recipients of Personal Data
3.1 Data on your name, address, e-mail address, telephone number and order number and specific delivery preferences are transferred by us to GLS, Danske Fragtmænd, UPS, Dachser or other carrier contracted for delivery of the purchased items to you.
3.2 Data may be transferred to external service partners who process personal data on our behalf. We use external service partners for services such as the technical operation of our Website, the mailing of newsletters and targeted marketing. These external service partners are data processors and are subject to our instructions for processing the data we are responsible for as the controller. Data processors are not permitted to use your data for any purpose other than fulfilment of their service agreement with us, and are subject to a non-disclosure agreement concerning those data. We have signed written data processor agreements with all data processors who process personal data on our behalf.
3.3 Three of these data processors: Google LLC (for Google Analytics), Facebook Inc. and The Rocket Science Group LCC (for MailChimp) are located in the USA. The necessary warranties for transferring data to the USA are provided through the data processor’s certification under EU-U.S. Privacy Shield; see Article 45 of the GDPR.
3.3.1 a copy of Google LLC's certification is available here: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI
3.3.2 a copy of Facebook Inc.'s certification is available here: https://www.privacyshield.gov/participant?id=a2zt0000000GnywAAC&status=Active.
3.3.3 a copy of The Rocket Science Group LCC’s certification is available here: https://www.privacyshield.gov/participant?id=a2zt0000000TO6hAAG&status=Active.
4. Your rights
4.1 In the interests of transparency surrounding the processing of your data, in our role as the controller responsible for your data, we are required to inform you of your rights.
4.2 Right of access
4.2.1 You have the right at any time to request information from us concerning, among other things, what data we have registered concerning you, the purpose of our registration of your data, which categories of personal data and recipients of personal data there might be, together with information about where the data were obtained from.
4.2.2 You have the right to be issued with a copy of the personal data we process concerning you. If you would like a copy of your personal data, please submit a written request to firstname.lastname@example.org. You may be asked to provide proof of your identity.
4.3 Right to rectification
4.3.1 You have the right to have inaccurate personal data concerning you rectified by us. If you become aware of inaccuracies in the data we have registered concerning you, we urge you to make a written request to us for rectification of those data.
4.4 Right to erasure
4.4.1 In certain cases you have the right to have all or certain personal data erased by us, for example, if you withdraw your consent, and where there is no other legal ground for the processing. Insofar as continued processing of your data is necessary, for example, for our compliance with a legal obligation, or for the establishment, exercise or defence of legal claims, we are not obliged to erase your personal data.
4.5 Right to restriction of processing
4.5.1 In certain cases, you have the right to obtain restriction of the processing of your personal data to consist solely of storage, if, for example, you believe that the data we process concerning you are inaccurate.
4.6 Right to data portability
4.6.1 In certain cases, you have the right to receive from us the personal data you have provided to us, in a structured, commonly used and machine-readable format and have the right to transmit those data to another controller.
4.7 Right to object
4.7.1 You have the right to object at any time to our processing of your personal data for direct marketing purposes, which includes the profiling undertaken in order to be able to target our direct marketing.
4.7.2 You also have the right to object, at any time, on grounds relating to your particular situation, to the processing of personal data concerning you, which we undertake based on our legitimate interests; see Items 2.1 and 2.3.
4.8 Right to withdraw consent
4.8.1 You have the right at any time to withdraw any consent you have given us for a given processing of personal data. If you wish to withdraw your consent to receiving our newsletter, you may at any time unsubscribe via the link at the bottom of our newsletter. You may also withdraw your consent by contacting us at email@example.com.
4.9 Right of complaint
4.9.1 You have the right at any time to lodge a complaint concerning our processing of your personal data with the Danish Data Inspection Authority (Datatilsynet), Borgergade 28, 5, DK-1300 Copenhagen K, Denmark. Your complaint may be lodged by e-mailing firstname.lastname@example.org or telephoning +45 33 19 32 00.
5. Erasure of personal data
5.1 Data collected concerning your use of our Website (see Item 2.1) will be deleted at the latest when you have not accessed the Website for 26 months.
5.2 Data collected at the time when you first subscribed to our newsletter will be deleted when your consent to receiving our newsletters is withdrawn, unless we have another basis for processing the data.
5.3 Data collected in connection with a purchase you made on our Website (see Item 2.2) will in the first instance be erased five years from the end of the calendar year in which your purchase was made. Those data may, however, be retained for longer if we have a legitimate need to retain them for longer, for example, for the establishment, exercise or defence of legal claims, or for compliance with a legal obligation. Accounting materials are retained for five years until the end of a financial year for compliance with the requirements of the Danish Bookkeeping Act.
6.1 We have implemented appropriate technical and organisational security measures to prevent personal data from being accidentally or unlawfully destroyed, lost, altered or impaired or brought to the knowledge of unauthorised third parties or abused.
6.2 Only employees with a legitimate need for access to your personal data for the performance of their work will have access to those data.
7. Contact details
7.1 Eva Solo A/S is the controller responsible for the personal data collected via our Website.
Eva Solo A/S
Måløv Teknikerby 18-20
Tel. no.: +45 36 73 20 60