Privacy Policy
APRIL 16:
VAVA OBJECTS operates this store and website, including all related information, content, features, tools, products and services, in order to provide you, the customer, with a curated shopping experience (the "Services"). VAVA OBJECTS is based in Sweden and powered by Shopify. This Privacy Policy describes how we collect, use, and disclose your personal information when you visit, use, or make a purchase or other transaction using the Services or otherwise communicate with us. If there is a conflict between our Terms of Service and this Privacy Policy, this Privacy Policy controls with respect to the collection, processing, and disclosure of your personal information.
Please read this Privacy Policy carefully. By using and accessing any of the Services, you acknowledge that you have read this Privacy Policy and understand the collection, use, and disclosure of your information as described in this Privacy Policy.
Personal information we collect or process
When we use the term "personal information," we are referring to information that identifies or can reasonably be linked to you or another person, as defined under the General Data Protection Regulation (GDPR) and applicable Swedish law. Personal information does not include information that is collected anonymously or that has been de-identified. We may collect or process the following categories of personal information, depending on how you interact with the Services:
- Contact details including your name, address, billing address, shipping address, phone number, and email address.
- Financial information including payment card information, transaction details, form of payment, payment confirmation and other payment details.
- Account information including your username, password, security questions, preferences and settings.
- Transaction information including the items you view, put in your cart, add to your wishlist, or purchase, return, exchange or cancel and your past transactions.
- Communications with us including the information you include in communications with us, for example, when sending a customer support inquiry.
- Device information including information about your device, browser, or network connection, your IP address, and other unique identifiers.
- Usage information including information regarding your interaction with the Services, including how and when you interact with or navigate the Services.
As a company based in Sweden and operating within the European Economic Area, we process your personal information on the following legal bases under the GDPR:
- Performance of a contract: Processing necessary to fulfill your orders and provide our Services.
- Legitimate interests: Processing for fraud prevention, security, and improving our Services, where these interests are not overridden by your rights.
- Consent: Where you have given us explicit consent, such as for marketing communications.
- Legal obligation: Processing required to comply with applicable Swedish and EU law.
Personal information sources
We may collect personal information from the following sources:
- Directly from you including when you create an account, visit or use the Services, communicate with us, or otherwise provide us with your personal information;
- Automatically through the Services including from your device when you use our products or services or visit our websites, and through the use of cookies and similar technologies;
- From our service providers including when we engage them to enable certain technology and when they collect or process your personal information on our behalf;
- From our partners or other third parties.
How we use your personal information
Depending on how you interact with us or which of the Services you use, we may use personal information for the following purposes:
- Provide, Tailor, and Improve the Services. We use your personal information to provide you with the Services, including to process your payments, fulfill your orders, remember your preferences, send notifications related to your account, process purchases, returns, exchanges or other transactions, create and manage your account, arrange for shipping, and create a customized shopping experience for you.
- Marketing and Advertising. We use your personal information for marketing and promotional purposes, such as to send marketing communications by email or postal mail, only where we have your consent or another valid legal basis under GDPR. You may withdraw your consent at any time.
- Security and Fraud Prevention. We use your personal information to authenticate your account, provide a secure payment and shopping experience, and detect or take action regarding possible fraudulent or illegal activity.
- Communicating with You. We use your personal information to provide you with customer support and to maintain our business relationship with you.
- Legal Compliance. We use your personal information to comply with applicable Swedish and EU law, including responding to valid legal process or requests from authorities such as Integritetsskyddsmyndigheten (IMY), Sweden's data protection authority.
How we disclose personal information
In certain circumstances, we may disclose your personal information to third parties for legitimate purposes subject to this Privacy Policy. Such circumstances may include:
- With Shopify, vendors and other third parties who perform services on our behalf (e.g. IT management, payment processing, data analytics, customer support, cloud storage, fulfillment and shipping).
- With business and marketing partners to provide marketing services, where permitted under GDPR. You can exercise your rights to opt-out of targeted advertising here.
- When you direct, request us or otherwise consent to our disclosure of certain information to third parties, such as to ship you products.
- With our affiliates or otherwise within our corporate group.
- In connection with a business transaction such as a merger, to comply with any applicable legal obligations, to enforce any applicable terms of service or policies, and to protect or defend the Services, our rights, and the rights of our users or others.
Relationship with Shopify
The Services are hosted by Shopify, which collects and processes personal information about your access to and use of the Services. Information you submit to the Services will be transmitted to and shared with Shopify as well as third parties that may be located in countries other than Sweden or the EEA. Where personal information is transferred outside the EEA, appropriate safeguards are in place, such as Standard Contractual Clauses. To learn more about how Shopify uses your personal information and any rights you may have, you can visit the Shopify Consumer Privacy Policy. You may also exercise rights related to data processed by Shopify via the Shopify Privacy Portal.
Third party website and links
The Services may provide links to websites or other online platforms operated by third parties. If you follow links to sites not affiliated or controlled by us, you should review their privacy and security policies and other terms and conditions. We do not guarantee and are not responsible for the privacy or security of such sites. Our inclusion of such links does not imply any endorsement of the content on such platforms or of their owners or operators, except as disclosed on the Services.
Children's data
The Services are not intended to be used by children under the age of 16. We do not knowingly collect any personal information about children. If you are the parent or guardian of a child who has provided us with their personal information, you may contact us using the contact details set out below to request that it be deleted.
Security and retention of your information
We implement appropriate technical and organizational measures to protect your personal information, in accordance with GDPR requirements. However, no security measures are perfect or impenetrable. We recommend that you do not use unsecure channels to communicate sensitive or confidential information to us.
How long we retain your personal information depends on different factors, such as whether we need the information to maintain your account, to provide you with Services, comply with legal obligations (including Swedish accounting law, which may require us to retain certain records for up to 7 years), resolve disputes or enforce other applicable contracts and policies.
Your rights and choices
As a resident of Sweden or the European Economic Area, you have the following rights under the GDPR in relation to your personal information:
- Right to Access. You have the right to request access to the personal information we hold about you.
- Right to Erasure ("Right to be Forgotten"). You have the right to request that we delete personal information we maintain about you, subject to certain exceptions.
- Right to Rectification. You have the right to request that we correct inaccurate personal information we maintain about you.
- Right to Data Portability. You have the right to receive a copy of the personal information we hold about you in a structured, commonly used, machine-readable format, and to request that we transfer it to a third party where technically feasible.
- Right to Object. You have the right to object to our processing of your personal information for direct marketing purposes or where we rely on legitimate interests as our legal basis.
- Right to Restriction of Processing. You have the right to ask us to restrict our processing of your personal information in certain circumstances.
- Right to Withdraw Consent. Where we rely on consent to process your personal information, you have the right to withdraw this consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Managing Communication Preferences. You may opt out of receiving promotional emails at any time by using the unsubscribe option in our emails. If you opt out, we may still send you non-promotional emails, such as those about your account or orders.
You may exercise any of these rights by contacting us using the contact details provided below. We will respond to your request within one month, as required under GDPR. We may need to verify your identity before processing your request.
Complaints
If you have complaints about how we process your personal information, please contact us using the contact details provided below. You also have the right to lodge a complaint with Sweden's data protection authority:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
Website: www.imy.se
Email: imy@imy.se
Internationals transfers
As a Swedish company, we store and process your personal information primarily within the European Economic Area. Where we transfer your personal information outside the EEA, we will rely on recognized transfer mechanisms such as the European Commission's Standard Contractual Clauses to ensure your data remains protected to EEA standards.
Changes to this privacy policy
We may update this Privacy Policy from time to time, including to reflect changes to our practices or for other operational, legal, or regulatory reasons. We will post the revised Privacy Policy on this website, update the "Last updated" date and provide notice as required by applicable law, including GDPR.
Contact
Should you have any questions about our privacy practices or this Privacy Policy, or if you would like to exercise any of the rights available to you, please contact us at:
VAVA OBJECTS
Sweden
Email: info@vavaobjects.com
For the purpose of applicable data protection laws, including the GDPR, we are the data controller of your personal information.