Last updated: January 2024
Blomsterstudion is committed to protecting your personal data in accordance with the General Data Protection Regulation (GDPR). This page outlines how we comply with GDPR requirements and explains your rights under this regulation.
We process your personal data based on the following legal grounds:
Blomsterstudion acts as the data controller for personal information collected through our services and website.
Contact details:
VÀsterlÄnggatan 47
111 29 Stockholm
Sweden
Email: [email protected]
Under GDPR, you have the following rights regarding your personal data:
You can request confirmation of whether we process your personal data and obtain a copy of that data.
You can request correction of inaccurate personal data or completion of incomplete data.
You can request deletion of your personal data in certain circumstances, including when it is no longer necessary for the purposes it was collected.
You can request that we limit how we use your data in specific situations.
You can request your personal data in a structured, commonly used format and have it transferred to another controller.
You can object to processing based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you can withdraw that consent at any time.
You have the right to file a complaint with the Swedish Data Protection Authority if you believe we have violated your data protection rights.
To exercise any of these rights, please contact us at [email protected] with the subject line "GDPR Request." We will respond to your request within one month, as required by GDPR.
Please include sufficient information for us to verify your identity and specify which right you wish to exercise.
We process the following categories of personal data:
We primarily process data within the European Economic Area. If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
We retain personal data only as long as necessary for the purposes outlined in our Privacy Policy or as required by law. Retention periods vary depending on the type of data and purpose:
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
We implement appropriate technical and organizational measures to ensure data security, including:
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR.
The supervisory authority responsible for monitoring our GDPR compliance is:
Swedish Data Protection Authority (Integritetsskyddsmyndigheten)
Box 8114
104 20 Stockholm
Sweden
Website: www.imy.se