This Privacy Policy describes how Zimravenghulau ("we", "us", or "our") collects, uses, and protects your personal information when you visit our website zimravenghulau.world and use our services. We are committed to ensuring that your privacy is protected in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection laws.
1. Data Controller
The data controller responsible for your personal data is:
Zimravenghulau
Gräddvägen 3
906 20 Umeå
Sweden
Email: online@zimravenghulau.world
2. Personal Data We Collect
We may collect and process the following categories of personal data:
2.1 Information You Provide
- Name and contact information (email address, phone number)
- Delivery address for order fulfillment
- Payment information (processed securely by third-party payment providers)
- Communications and correspondence with our team
- Any other information you choose to provide
2.2 Automatically Collected Information
- IP address and approximate location
- Browser type and version
- Device information and operating system
- Pages visited and time spent on our website
- Referral source and navigation patterns
- Cookie data (see our Cookie Policy for details)
3. Purposes of Processing
We process your personal data for the following purposes:
- Order Processing: To process and fulfill your orders, including payment processing and delivery
- Customer Service: To respond to your inquiries and provide customer support
- Communication: To send order confirmations, updates, and service-related notifications
- Legal Compliance: To comply with applicable laws, regulations, and legal obligations
- Website Improvement: To analyze usage patterns and improve our website functionality
- Marketing: With your consent, to send promotional communications about our products (for example, by email); you can unsubscribe at any time
4. Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contract Performance: Processing necessary to fulfill our contractual obligations to you
- Consent: Where you have given explicit consent for specific processing activities
- Legitimate Interests: Processing necessary for our legitimate business interests, such as fraud prevention and website security
- Legal Obligation: Processing necessary to comply with legal requirements
We do not currently use your personal data for automated decision-making that has legal or similarly significant effects on you.
Where providing personal data is necessary for entering into or performing a contract (e.g., to process an order or customer request), we will clearly indicate this at the time of data collection. If you do not provide the required information, we may be unable to process your order or respond to your request.
5. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Order and transaction data: 7 years for tax and accounting purposes
- Customer service communications: 3 years from the last interaction
- Marketing preferences: Until you withdraw consent or request deletion
- Website analytics data (if analytics cookies are enabled): up to 26 months
After the retention period expires, we will securely delete or anonymize your personal data.
6. Your Rights
Under GDPR, you have the following rights regarding your personal data:
- Right of Access: Request a copy of the personal data we hold about you
- Right to Rectification: Request correction of inaccurate or incomplete data
- Right to Erasure: Request deletion of your personal data in certain circumstances
- Right to Restriction: Request limitation of processing in certain circumstances
- Right to Data Portability: Receive your data in a structured, machine-readable format
- Right to Object: Object to processing based on legitimate interests or direct marketing
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent (withdrawal does not affect processing that took place before you withdrew consent)
Where processing is based on consent (including cookies and marketing), you can withdraw that consent using the cookie settings on our website and/or by using the unsubscribe options provided in marketing emails.
To exercise any of these rights, please contact us at online@zimravenghulau.world. We will respond to your request within 30 days.
7. Data Sharing
We may share your personal data with:
- Service Providers: Third parties who assist us with order fulfillment, payment processing, and delivery services
- Legal Authorities: When required by law or to protect our legal rights
- Marketing/Advertising service providers: With your consent, where applicable, to deliver and measure marketing communications on our behalf
We do not sell your personal data to third parties.
8. International Transfers
Your personal data may be transferred to and processed in countries outside the European Economic Area (EEA). When such transfers occur, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for data transmission
- Secure data storage with access controls
- Regular security assessments and updates
- Employee training on data protection
10. Children's Privacy
Our website and services are not directed to individuals under the age of 18. We do not knowingly collect personal data from children. If you become aware that a child has provided us with personal data, please contact us immediately.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal requirements. We will notify you of any material changes by posting the updated policy on our website with a new effective date.
12. Complaints
If you are not satisfied with how we handle your personal data, you have the right to lodge a complaint with your local data protection authority. In Sweden, this is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten).
Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us:
Zimravenghulau
Gräddvägen 3
906 20 Umeå
Sweden
Email: online@zimravenghulau.world