Privacy Policy
Last updated:
1. Introduction
Xunrovarthexrova ("we", "us", "our") is committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, store, and protect your personal data when you visit our website at https://xunrovarthexrova.world and use our services.
This policy is drafted in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Swedish Data Protection Act (Dataskyddslagen 2018:218), the ePrivacy Directive (2002/58/EC), and other applicable data protection legislation.
2. Data Controller
The data controller responsible for your personal data is:
- Company: Xunrovarthexrova
- Address: Sergelgatan 16, 111 57 Stockholm, Sweden
- Email: touch@xunrovarthexrova.world
- Website: https://xunrovarthexrova.world
If you have any questions about this Privacy Policy or how we handle your personal data, please contact us using the details above.
3. Data We Collect
We may collect and process the following categories of personal data:
3.1 Data You Provide Directly
- Contact information: full name, email address, phone number (if provided)
- Messages: any text you submit through our order form
- Consent records: your consent to data processing and acceptance of our policies
3.2 Data Collected Automatically
- Technical data: IP address, browser type and version, operating system, device type
- Usage data: pages visited, time spent on pages, referring URL, click patterns
- Cookie data: information collected through cookies and similar technologies (see our Cookie Policy)
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under GDPR Article 6(1):
- Consent (Art. 6(1)(a)): When you submit our order form and explicitly consent to data processing. You may withdraw your consent at any time.
- Contractual necessity (Art. 6(1)(b)): To process and fulfill your order or to take pre-contractual steps at your request.
- Legitimate interests (Art. 6(1)(f)): To improve our website, prevent fraud, and ensure network security, provided these interests are not overridden by your rights.
- Legal obligation (Art. 6(1)(c)): To comply with applicable legal and regulatory requirements.
5. Purpose of Data Processing
We use your personal data for the following purposes:
- To process and manage your orders and inquiries
- To communicate with you regarding your order or questions
- To improve our website and services
- To comply with legal obligations
- To ensure the security and proper functioning of our website
- To analyze website usage through anonymized analytics (with your consent)
6. Data Sharing and Recipients
We do not sell, rent, or trade your personal data to third parties. We may share your data with:
- Service providers: trusted third-party providers who assist with website hosting, email delivery, and order processing, bound by data processing agreements
- Legal authorities: when required by law, regulation, or legal process
- Business transfers: in connection with a merger, acquisition, or sale of assets, with appropriate safeguards
7. International Data Transfers
If your data is transferred outside the European Economic Area (EEA), we will ensure appropriate safeguards are in place, such as Standard Contractual Clauses (SCCs) approved by the European Commission, or transfers to countries with an adequacy decision.
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Order data: retained for up to 3 years after the last interaction, or as required by applicable law (e.g., Swedish Bookkeeping Act requires retention for 7 years for accounting purposes)
- Consent records: retained for the duration of the consent and for a reasonable period afterward to demonstrate compliance
- Analytics data: anonymized and aggregated data may be retained indefinitely; identifiable analytics data is retained for up to 26 months
- Cookie data: see our Cookie Policy for specific retention periods
After the retention period expires, your data will be securely deleted or anonymized.
9. Your Rights Under GDPR
Under the GDPR, you have the following rights regarding your personal data:
- Right of access (Art. 15): You have the right to request a copy of the personal data we hold about you.
- Right to rectification (Art. 16): You can request correction of inaccurate or incomplete data.
- Right to erasure (Art. 17): You can request deletion of your personal data ("right to be forgotten"), subject to legal retention requirements.
- Right to restriction (Art. 18): You can request that we restrict the processing of your data in certain circumstances.
- Right to data portability (Art. 20): You can request to receive your data in a structured, commonly used, machine-readable format.
- Right to object (Art. 21): You can object to processing based on legitimate interests or for direct marketing purposes.
- Right to withdraw consent (Art. 7(3)): You may withdraw your consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
- Right to lodge a complaint: You have the right to file a complaint with Integritetsskyddsmyndigheten (IMY), the Swedish Data Protection Authority (Drottninggatan 29, 104 20 Stockholm, Sweden; imy.se).
To exercise any of these rights, please contact us at touch@xunrovarthexrova.world. We will respond within 30 days of receiving your request.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- HTTPS encryption for all data transmitted between your browser and our website
- Access controls to limit data access to authorized personnel only
- Regular security assessments and updates
- Secure data storage with appropriate backup procedures
- Employee training on data protection and privacy best practices
While we strive to protect your personal data, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but commit to promptly notifying affected individuals and relevant authorities in the event of a data breach, in accordance with GDPR Article 33 and 34.
11. Children's Privacy
Our website and products are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that we have collected data from a minor without appropriate consent, we will take steps to delete that data promptly.
12. Cookies and Tracking
Our website uses cookies and similar technologies. For detailed information about the cookies we use, their purposes, and how to manage your preferences, please see our Cookie Policy.
13. Links to Third-Party Websites
Our website may contain links to external websites. We are not responsible for the privacy practices of those websites. We encourage you to read the privacy policies of any external website you visit.
14. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. Any significant changes will be communicated through our website. The "Last updated" date at the top of this page indicates when this policy was last revised. We encourage you to review this page periodically.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
- Email: touch@xunrovarthexrova.world
- Address: Sergelgatan 16, 111 57 Stockholm, Sweden
- Website: https://xunrovarthexrova.world