Privacy Policy

INTRODUCTION
Grand Frank AB 556982-3353, (the ”Company”) operates within the market of mail order and e-commerce (the ”Service”). The Company is the data controller for certain processing made regarding your personal data in connection with:

  • You as a customer is provided the Service;
  • You as supplier, or representative of these, enter into cooperation with the Company; and
  • You apply for a position at the Company.

The Company is responsible for ensuring that all personal data is processed correctly and in accordance with applicable data protection legislation.

This privacy policy (hereinafter referred to as the ”Privacy Policy”) describes the Company’s processing of your personal data and has the purpose of assuring you that the Company is processing your information in accordance with applicable data protection legislation.

Personal data means all type of information that may, directly or indirectly, be associated with a living natural person. Within the scope of the Company’s activities there may occur personal data relating to, e.g., given names and surnames, personal ID numbers, telephone numbers, addresses, postal codes, e-mail addresses, etc. (hereinafter collectively referred to as ”Personal Data”).

If you cannot find answers to your questions, please contact the Company. Information on how to contact the Company may be found under the heading “Contact Information” below.

PROCESSING OF PERSONAL DATA
In this section, we describe how we process your Personal Data more in detail.

  • Customers or and potential customers
Purpose Type of processing Categories of Personal Data Categories of Data Subjects
Processing orders from customers. This includes processing for delivery (including notifications and contacts concerning the delivery), processing of orders from customers, identifying customers, processing payment and processing complaints and warranty claims. Name.

Personal ID number.

Contact information (such as e-mail address and phone number).

Payment information.

Purchase information (i.e. which product has been ordered or whether the product should be delivered to another address).

Customers.
Source: Customer.
Lawful Basis: Completion of order. This gathering of your Personal Data is required in order for us to fulfil our commitments as agreed. If the information is not provided, our commitments cannot be fulfilled and we may terminate the contract.
Automated decision-making: This processing does not imply that decisions will be made based on automated processing of Personal Data.
Data Retention: Until the contract has been performed (including delivery and payment) and for a time of up to 36 months thereafter with the purpose of processing any complaints or warranty claims.

 

Purpose Type of processing Categories of Personal Data Categories of Data Subjects
In order to fulfil the Company’s legal obligations regarding purchase of goods or services. This includes the necessary processing for fulfilling the Company’s legal obligations according to law, court rulings (e.g. the Book-keeping Act) or decisions by authorities. Name.

Personal ID number.

Contact information.

Payment history.

Payment information.

Customers.
Source: Customer.
Lawful Basis: Legal obligation.
Automated decision-making: This processing does not imply that decisions will be made based on automated processing of Personal Data.
Data Retention: Until the purchase has been completed (including delivery and payment) and for a time of up to 7 years thereafter.

 

Purpose Type of processing Categories of Personal Data Categories of Data Subjects
Processing customer service matters. The processing includes communication and answering of potential questions related to customer service (via telephone or in digital channels, including social media, including social media), identifying the customer and investigation of potential complaints. Name.

Personal ID number.

Contact information. Correspondence with customer of customer’s representative.

Information on purchase time, potential defects/complaints.

Customers.
Source: Customer.
Lawful Basis: Legitimate interest. The processing is necessary in order to meet ours and the Data Subject’s legitimate interest in processing information regarding customer service matters.
Automated decision-making: This processing does not imply that decisions will be made based on automated processing of Personal Data.
Data Retention: Until the customer service matter has been settled.

 

Purpose Type of processing Categories of Personal Data Categories of Data Subjects
Marketing This includes e.g. marketing mailings regarding our products and services via e-mail and by post. Name.

Contact information.

Professional title.

 

Customers, potential customers.
Source: Customer or representative of customers, potential customers.
Lawful Basis: Consent and legitimate interest. The processing is necessary in order to cater our interest in marketing our products and services.
Automated decision-making: This processing does not imply that decisions will be made based on automated processing of Personal Data.
Data Retention: One year from last contact. Longer after consent.

 

  • Suppliers
Purpose Type of processing Categories of Personal Data Categories of Data Subjects
In order to communicate with contact persons for suppliers and partners. This includes e.g. processing deliveries and cooperation, as well as providing organizational chart and telephone list in order to cooperate internally at the Company. Supplier directory for easier access to contact information. Name.

Contact information.

 

Suppliers and their representatives.
Source: From suppliers.
Lawful Basis: Legitimate interest. The Company has a legitimate interest in processing the Personal Data necessary in order to communicate with contact persons for suppliers and partners.
Automated decision-making: This processing does not imply that decisions will be made based on automated processing of Personal Data.
Data Retention: Until we have received information that the contact person has quit or changed contact information, or for as long as the contractual relationship remains.
  • Job seekers
Purpose Type of processing Categories of Personal Data Impacted Data Subjects
In order to administer a recruitment process. This includes e.g. to review the application and communicate with the applicant. Name.

Personal ID number

Contact information.

Proof of identity.

Information on job seeker’s performances and prior work experience.

Job seekers.
Source: Job seeker and the job seeker’s employer.
Lawful Basis:

Until the position is appointed: completion of agreement.

After the position has been appointed: legitimate interest (or consent).

Automated decision-making: This processing does not mean that decisions will be made based on automated processing of Personal Data.
Data Retention: Up to two years from when the position was appointed. Following completed recruitment process, the information is filed in order to be used at a potential appeal of the recruitment in accordance with e.g. non-discrimination legislation. When there is no longer a possibility to appeal, the information will be destroyed unless there is consent for continued processing.

 

RECIPIENTS OF PERSONAL DATA AND TRANSFERS TO COUNTRIES OUTSIDE THE EU/EEEA
In our capacity as Personal Data Controller, we may assign the processing specified above to a partner or supplier. Such processing will not be done for other purposes than what is described above. Some partners and suppliers may have parts of their businesses in countries outside of the EU/EEA (so-called Third Countries). Transfer of Personal Data will only be made to such countries that offer an adequate level of data protection, as decided by the EU Commission, or if the supplier has a legally binding and enforceable instrument that guarantees the safety of the Personal Data.

 

YOUR RIGHTS AS DATA SUBJECT
You have the right to:

  • Request information about what type of Personal Data we process and you may request a copy of these (extract from registry);
  • Have incorrect Personal Data corrected and, under certain circumstances, ask us to erase your Personal Data;
  • Have your Personal Data transferred to another controller (right to data portability);
  • Withdraw your consent to the processing of your Personal Data; and
  • Object against the processing of certain Personal Data and request that the processing of your Personal Data is limited.

 

If you are unhappy with the way we process your Personal Data, you may file a complaint with the Data Inspection Board, which is the supervisory authority.

See contact information for asserting your rights under ”Privacy Disclaimer and Contact Information”. However, please note that such limitation or deletion of your Personal Data may result in the Company not being able to provide the Service.

PERSONAL DATA PROTECTION
The Company has undertaken appropriate technical and organizational measures in order to protect Personal Data against loss, abuse, unauthorized access, disclosure, alteration and destruction. The Company’s employees, subcontractors and its suppliers are bound by confidentiality agreements and are obligated to follow the Company’s rules for information and IT security, this Privacy Policy and other internal rules which further regulates the processing of Personal Data.

CHECKOUT
Our checkout solution for Sweden and Germany is provided by Klarna (Klarna AB, Sveavägen 46, 111 34 Stockholm, Sweden) and uses cookies to offer you the best possible, tailored, online experience when you use Klarna’s checkout. The exact cookies and purposes for which they are used can be found here: SE: https://www.klarna.com/se/cookies/
DE: http://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf

AMENDMENTS TO THIS PRIVACY POLICY
The Company retains the right to revise this Privacy Policy from time to time. The date of the latest amendment is indicated at the end of this Privacy Policy. If the Company amends this Privacy Policy, the Company will publish these amendments at www.dropofmindfulness.com. You are therefore recommended to regularly review this Privacy Policy in order to be updated on any amendments. If this Privacy Policy is substantially amended compared to what was stated when the Company obtained your consent, the Company will notify you of these amendments and, if necessary, obtain new consent to the Company’s processing of your Personal Data.

CONTACT INFORMATION
If you have any questions regarding the Privacy Policy or our processing, please contact:

Grand Frank AB, reg. no. 556982-3353
info@grandfrank.com
Tellusborgsvägen 67A
12629 Stockholm
+46 0702457792

The Privacy Policy was adopted on 2020-07-16


Cookies

COOKIES:

Dina rättigheter som konsument

Du har följande rätten att:

Begära information om vilken typ av personuppgifter vi behandlar och du kan begära en kopia av dessa (extrakt från registret):

Har felaktiga personuppgifter korrigerats, och under vissa omständigheter, be oss ta bort dina personuppgifter: Har dina personuppgifter överförts till en annan registeransvarig (rätt till dataportabilitet): Återkalla ditt samtycke till behandlingen av dina personuppgifter; och göra invändningar mot behandlingen av vissa personuppgifter och begära att behandlingen av dina personuppgifter är begränsad. Om du inte är nöjd med hur vi behandlar dina personuppgifter, kan du lämna in ett klagomål till datainspektionen.

 

PERSONLIGT  DATASKYDD

Företaget(Drop Of Mindfulness) har vidtagit lämpliga tekniska och organisatoriska åtgärder för att skydda personuppgifter mot förlust, missbruk, obehörig åtkomst, avslöjande, ändring och förstörelse. Företagets(Drop Of Mindfulness) anställda, underleverantörer och dess leverantörer är bundna av sekretessavtal och är skyldiga att följa företagets regler för information och IT-säkerhet, denna integritetspolicy och andra interna regler som ytterligare reglerar behandlingen av personuppgifter.

 

KLARNA CHECKOUT

Vår kassalösning för Sverige och Tyskland tillhandahålls av Klarna (Klarna AB, Sveavägen 46, 111 34 Stockholm, Sverige) och använder cookies för att erbjuda dig den bästa möjliga, skräddarsydda shoppingupplevelsen när du använder Klarnas kassa. De exakta kakorna och syftena för vilka de används kan hittas här: SE: https://www.klarna.com/se/cookies/

 

DE: http://cdn.klarna.com/1.0/shared/content/policy/cookie/de_de/checkout.pdf

 

ÄNDRINGAR I DENNA PRIVACY POLICY

Företaget(Drop Of Mindfulness) förbehåller sig rätten att ändra denna sekretesspolicy då och då. Datumet för den senaste ändringen anges i slutet av denna sekretesspolicy. Om företaget ändrar denna sekretesspolicy kommer företaget att publicera dessa ändringar på www.dropofmindfulness.se. Du rekommenderas därför att regelbundet granska denna sekretesspolicy för att uppdateras om eventuella ändringar. Om denna sekretesspolicy ändras väsentligt jämfört med vad som anges när företaget erhöll ditt samtycke, kommer företaget att meddela dig om dessa ändringar och, om nödvändigt, få nytt samtycke till företagets behandling av dina personuppgifter.

 

KONTAKTINFORMATION

Om du har några frågor angående sekretesspolicyn eller vår behandling, vänligen kontakta:

 

Grand Frank AB, reg. Nej. 556982-3353

info@grandfrank.com eller info@dropofmindfulness.se

Tellusborgsvägen 67A

12629 Stockholm

Senast uppdaterad 08-06-2020