Data Protection Policy

Data Protection Policy for Apovi


1. Introduction

1.1. Apovi.se is committed to protecting its customers' privacy and data security. This data protection policy describes our practices for handling personal data collected through our e-commerce platform.

2. Scope

2.1. This policy applies to all personal data collected, processed, stored or transmitted by [Company Name] in the course of providing e-commerce services to customers.


3. Data collection and processing

3.1. We collect and process personal data necessary to provide our e-commerce services and fulfil customer orders. This may include, but is not limited to, the following:

Name, address and contact information (email, telephone number)
Payment and billing information
Order history and preferences
Communication records related to customer support

3.2. We collect personal data directly from customers or through automated means, such as cookies and similar technologies. We only collect data that is relevant, necessary and legal for the purpose for which it is processed.


4. Purpose and legal basis for the processing

4.1. We process personal data for the following purposes:

Fulfill customer orders and provide requested services
Manage customer accounts and provide customer support
Improve our e-commerce platform and services
Analyze customer preferences and behaviour to customize the user experience
To comply with legal obligations

4.2. The legal basis for processing personal data may include:

Consent: When express consent is obtained for specific processing activities
Contractual necessity: When processing is necessary for the fulfilment of a contract with the customer
Legal Obligations: When processing is required to comply with applicable laws and regulations


5. Data Storage

5.1. We retain personal data only as long as necessary to fulfil the purposes for which it was collected or as required by law. The storage period may vary depending on the type of data and applicable legal requirements.


6. Data Security

6.1. We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure or destruction. These measures include, but are not limited to:

Encryption of sensitive data during transmission and storage
Regular safety assessments and audits
Access controls and limited system permissions
Employee training on data protection best practices


7. Sharing of personal data

7.1. We may share personal data with third parties only for the purposes described in this policy or as required by law. Third parties may include:

Payment processors and financial institutions for payment processing
Shipping and logistics providers for order fulfillment
IT service providers to maintain and support our e-commerce platform


7.2. We ensure that all third parties with whom personal data is shared have appropriate data protection measures in place and comply with applicable privacy laws.


8. Rights of the data subject

8.1. Individuals have the following rights to their data:

Right of access: Request information about the personal data we hold
Right to correction: Request correction of incorrect or incomplete information
Right to erasure: Request erasure of personal data, according to legal requirements
Right to object: Object to the processing of personal data under certain circumstances
Right to limitation: Request limitation of the processing of personal data
Right to data portability: Request transfer of personal data to another service provider