We use cookies to enhance your browsing experience and analyze site traffic. Your privacy matters to us.

Blomsterstudion
Advertising Content
  • Home
  • Our Story
  • Services
  • Visit Us

GDPR Compliance

Last updated: January 2024

Our Commitment to Data Protection

Blomsterstudion is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights under this regulation.

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contractual necessity: Processing is necessary to fulfill our service agreements with you
  • Legitimate interests: We process data to improve services and maintain business operations
  • Consent: For marketing communications and optional services, we obtain your explicit consent
  • Legal obligations: To comply with accounting, tax, and other legal requirements

Data Controller Information

Blomsterstudion acts as the data controller for personal information collected through our services and website.

Contact details:
VÀsterlÄnggatan 47
111 29 Stockholm
Sweden
Email: [email protected]

Your GDPR Rights

Under GDPR, you have the following rights regarding your personal data:

Right to Access

You can request confirmation of whether we process your personal data and obtain a copy of that data.

Right to Rectification

You can request correction of inaccurate personal data or completion of incomplete data.

Right to Erasure

You can request deletion of your personal data in certain circumstances, including when it is no longer necessary for the purposes it was collected.

Right to Restriction of Processing

You can request that we limit how we use your data in specific situations.

Right to Data Portability

You can request your personal data in a structured, commonly used format and have it transferred to another controller.

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes.

Right to Withdraw Consent

Where processing is based on consent, you can withdraw that consent at any time.

Right to Lodge a Complaint

You have the right to file a complaint with the Swedish Data Protection Authority if you believe we have violated your data protection rights.

How to Exercise Your Rights

To exercise any of these rights, please contact us at [email protected] with the subject line "GDPR Request." We will respond to your request within one month, as required by GDPR.

Please include sufficient information for us to verify your identity and specify which right you wish to exercise.

Data Processing Activities

We process the following categories of personal data:

  • Identity data: name, contact preferences
  • Contact data: email address, delivery address
  • Transaction data: order details, service selections, payment information
  • Technical data: IP address, browser type, device information
  • Usage data: how you interact with our website and services
  • Marketing data: preferences for receiving communications

International Data Transfers

We primarily process data within the European Economic Area. If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.

Data Retention

We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. Retention periods vary depending on the type of data and purpose:

  • Order and transaction data: 7 years for accounting purposes
  • Marketing consent records: until consent is withdrawn
  • Website analytics data: 26 months
  • Inquiry data: 2 years from last contact

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.

Data Security Measures

We implement appropriate technical and organizational measures to ensure data security, including:

  • Encryption of data in transit and at rest
  • Access controls limiting who can view personal data
  • Regular security assessments and updates
  • Employee training on data protection
  • Incident response procedures

Data Breach Notification

In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.

Supervisory Authority

The supervisory authority responsible for monitoring our GDPR compliance is:

Swedish Data Protection Authority (Integritetsskyddsmyndigheten)
Box 8114
104 20 Stockholm
Sweden
Website: www.imy.se

Blomsterstudion

Contemporary floral design for discerning clients across Sweden.

Navigate

  • Our Story
  • Services
  • Visit Us

Information

  • Privacy Policy
  • GDPR
  • Cookies Policy
  • Terms of Use

Contact

[email protected]

© 2024 Blomsterstudion. All arrangements are unique creations.