Privacy Policy
Last updated:
1. Introduction
Inventorysafe ("we", "us", or "our"), located at Kista Science Tower, Färögatan 33, 164 51 Kista, Sweden, operates the website https://inventorysafe.world (the "Website"). We are committed to protecting and respecting your privacy in accordance with Regulation (EU) 2016/679, the General Data Protection Regulation ("GDPR"), the Swedish Data Protection Act (Dataskyddslag 2018:218), and other applicable data protection legislation.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you visit our Website or place an order for our products. Please read this policy carefully to understand our views and practices regarding your personal data and how we treat it.
2. Data Controller
The data controller responsible for your personal data is:
- Company Name: Inventorysafe
- Address: Kista Science Tower, Färögatan 33, 164 51 Kista, Sweden
- Email: inquiry@inventorysafe.world
- Website: https://inventorysafe.world
3. Personal Data We Collect
We may collect and process the following categories of personal data:
3.1 Data You Provide Directly
- Full name — provided via our order form
- Email address — provided via our order form
- Phone number (optional) — provided via our order form
- Message content — provided via our order form
- Consent records — your consent to data processing and cookie preferences
3.2 Data Collected Automatically
- IP address
- Browser type and version
- Operating system
- Referring website
- Pages visited and time spent on each page
- Date and time of access
- Device type and screen resolution
- Cookie identifiers (see our Cookie Policy)
4. Legal Basis for Processing
We process your personal data based on the following legal grounds under Article 6 of the GDPR:
- Consent (Art. 6(1)(a)): When you submit the order form with the consent checkbox selected, or when you accept optional cookies. You may withdraw consent at any time.
- Contract Performance (Art. 6(1)(b)): Processing necessary to fulfill your order and deliver our products to you.
- Legitimate Interest (Art. 6(1)(f)): For website security, fraud prevention, and improving our services, provided such interests are not overridden by your rights and freedoms.
- Legal Obligation (Art. 6(1)(c)): Where we are required to process data to comply with applicable laws, such as tax regulations and consumer protection laws.
5. Purposes of Processing
We use the personal data we collect for the following purposes:
- To process and fulfill your orders
- To communicate with you regarding your order status
- To respond to your inquiries and provide customer support
- To comply with legal obligations (e.g., tax and accounting requirements)
- To improve and optimize our Website and user experience
- To analyze website traffic and usage patterns (with your consent)
- To deliver relevant marketing communications (with your consent)
- To ensure the security and integrity of our Website
6. Data Sharing and Disclosure
We do not sell, rent, or trade your personal data to third parties. We may share your data with:
- Service Providers: Third-party companies that assist us with order fulfillment, shipping, payment processing, email communication, and website hosting. These providers are contractually bound to process data only on our behalf and in accordance with our instructions.
- Legal Authorities: Where required by law, regulation, legal process, or governmental request.
- Business Transfers: In connection with a merger, acquisition, or sale of all or a portion of our assets, where personal data may be transferred as part of the transaction.
All third-party processors are located within the European Economic Area (EEA) or are subject to appropriate safeguards as required by GDPR, such as Standard Contractual Clauses (SCCs) approved by the European Commission.
7. International Data Transfers
We primarily store and process data within the EEA. If data is transferred outside the EEA, we ensure that appropriate safeguards are in place, including:
- EU Commission adequacy decisions
- Standard Contractual Clauses (SCCs)
- Binding Corporate Rules
8. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected:
- Order data: Retained for 5 years from the date of the order to comply with Swedish tax legislation (Bokföringslagen) and consumer protection laws.
- Consent records: Retained for the duration of the consent period plus 1 year.
- Analytics data: Retained for up to 26 months, then anonymized or deleted.
- Communication records: Retained for 2 years from the date of the last communication.
After the retention period expires, data is securely deleted or anonymized so that it can no longer be associated with you.
9. Your Rights Under GDPR
As a data subject, you have the following rights under the GDPR:
- Right of Access (Art. 15): You have the right to obtain confirmation of whether we process your personal data and to request a copy of that data.
- Right to Rectification (Art. 16): You have the right to request correction of inaccurate or incomplete personal data.
- Right to Erasure (Art. 17): You have the right to request deletion of your personal data where there is no compelling reason for its continued processing.
- Right to Restriction of Processing (Art. 18): You have the right to request that we restrict the processing of your data in certain circumstances.
- Right to Data Portability (Art. 20): You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
- Right to Object (Art. 21): You have the right to object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent (Art. 7(3)): Where processing is based on consent, you may withdraw that consent at any time without affecting the lawfulness of processing carried out prior to withdrawal.
- Right to Lodge a Complaint: You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at www.imy.se or any other competent supervisory authority.
To exercise any of these rights, please contact us at inquiry@inventorysafe.world. We will respond to your request within 30 days.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- HTTPS encryption for all data transmitted between your browser and our Website
- Access controls limiting data access to authorized personnel only
- Regular security assessments and updates
- Secure storage of personal data with encryption at rest
- Employee training on data protection and privacy
11. Cookies
Our Website uses cookies and similar tracking technologies. For detailed information about the types of cookies we use, their purposes, and how to manage your preferences, please refer to our Cookie Policy.
12. Third-Party Links
Our Website may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to review the privacy policies of any third-party websites you visit.
13. Children's Privacy
Our Website and products are not intended for individuals under the age of 18. We do not knowingly collect personal data from children. If we become aware that a child has provided personal data, we will take steps to delete that data promptly.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or regulatory guidance. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this page periodically.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:
- Inventorysafe
- Kista Science Tower, Färögatan 33, 164 51 Kista, Sweden
- Email: inquiry@inventorysafe.world