Information regarding the processing of personal data
1. October Stockholm and your personal data
It is of high importance to October Stockholm that your privacy is protected when you are using any of our services. Here you will find information about what personal data we are collecting and processing, why we are doing so and how we are using it. You are welcome to contact us if you have any questions, just use the contact information which you will find at the bottom of this page. The personal data that is collected is processed according to the General Data Protection Regulation (GDPR). GDPR regulates the processing of personal data for all companies and organizations that are handling personal data.
2. When do we collect and process data from you?
October Stockholm collects your personal data when you’re choosing to submit it through forms on our website. Personal data is collected when you are performing the following actions;
- When you’re subscribing to our newsletter.
- When you’re making purchases at octoberstockholm.com.
- When you are contacting us using mail.
3. Which personal data do we collect?
When you are subscribing to our newsletter October Stockholm collects your email address. This is done so we can send you our newsletter.
When you are making a purchase at octoberstockholm.com the following personal data is required of you; email address, postal code, first name, last name, address, mobile phone number, customer IP-number, and national id number. If you choose a different delivery address than the billing address we’re also collecting the following personal data; last name, first name, delivery C/O (optional), delivery address, delivery postcode and delivery mobile phone number. The data collection is necessary for us to be able to deliver the products to you and to be able to contact you about your order.
When you are contacting October Stockholm through the section “Contact us” on our website your email and name will be collected so we’re able to answer you.
4. October Stockholm the data controller
October Stockholm AB, org. nr 556982-8006, Bergsgatan 13A, 85236 Sundsvall, is the data controller for all the processing of personal data that October Stockholm determines the purpose for. Personal data is most commonly processed when October Stockholm is handling purchases and subscriptions.
5. The purpose of processing personal data and the legal basis
October Stockholm is processing personal data for the following purposes:
- To handle purchases/orders. We process the data to be able to complete a purchase, this includes payment, shipping and confirmation of purchase. October Stockholm is in this case processing your personal data to be able to fulfil the purchase agreement. The legal basis for this purpose is a contractual agreement.
- To handle incoming questions from visitors/customers. We use the personal data to be able to contact the visitor/customer and to answer their questions. The legal basis for this purpose is a legitimate interest because the processing of personal data is necessary to be able to fulfil the customer service matter.
- For when a visitor/customer subscribes to our newsletter (if a visitor chooses to receive newsletters). The legal basis for this is based on consent. If the visitor/customer wish to withdraw their consent, then we will discard the personal data that is collected during the signup process.
- To evaluate, develop and improve our services and customer experience for all of our customers (by marketing and customer analysis). The processing of data is done because of both October Stockholm and our customers interests in the evaluation, development and improvement of our services and customers experience. The legal basis of this purpose is therefore based upon a legitimate interest.
By using the forms on our website, you approve October Stockholm to process your personal data according to the purposes listed above. We do not sell your information to third parties.
6. How are we protecting your data?
When you are using the forms on our website you can be ensured that your personal data reaches the intended recipient. The personal data you provide is stored on a secure server and it is of high importance to us that it is protected from loss, destruction, abuse, unauthorized access or changes. The server is maintained by a third part company that applies robust security measures to make sure that the data is safe and secure.
We use third-party suppliers to perform various services, such as handle digital payment-solutions, email marketing, server hosting and to conduct statistical analysis. When October Stockholm uses a third-party supplier, we are only working with suppliers that follows the GDPR-legislation.
8. How long do we store your personal data?
The data regarding your purchases made at October Stockholm are stored and processed at a maximum of 24 months. This does not apply to the invoice which is stored for 7 years according to Swedish accounting legislation.
The personal data that is collected during the newsletter signup process is stored until the consent is withdrawn. If a subscriber withdraws their consent October Stockholm will discard the data within 30 days.
9. Your rights concerning personal data
If you want information from us about your personal data and how it is being processed or if you want to correct personal data, you are entitled the following rights:
- The right of access to your personal data. You have the right to obtain a verification from us regarding whether or not we are processing your personal data and also, where that is the case, gain access to the personal data.
- The right to erasure (also known as the right to be forgotten). If you request your personal data to be erased October Stockholm will discard the data.
- The right of rectification. You have the right to demand personal data that is incorrect rectified. October Stockholm will then quickly examine the need for correction of the data.
- The right to data portability. If you would like to have your personal data transferred to another organization, you have right to demand the data to be exported.
- Right to object to processing.
- Right to restriction of processing.
- The Right to file a complaint to the supervisory authority (Datainspektionen). You may file complaints to the appropriate supervisory authority if you consider October Stockholm to be breaking the rules of the General Data Protection Regulation.
If you want to invoke any of your rights you can contact October Stockholm, using the contact information below. Our goal is to give you an answer within 30 days from the date that we received your message.
If you want to contact October Stockholm regarding your personal data or invoke any of your rights you’re welcome to send an e-mail to firstname.lastname@example.org.