Privacy Policy
Effective from: 26 July 2025 (Last updated: 26 July 2025)
1. What Personal Data We Collect
| Category | Examples |
|---|---|
| Identity & Contact Information | name, address, email, phone number |
| Payment & Transaction Data | order ID, payment token (we never store full card numbers), Swish or PayPal reference |
| Delivery & Returns Info | tracking number, delivery status |
| Communication | email, chat, customer service interactions |
| Technical Data | IP address, device ID, cookie ID, logs |
2. Purpose and Legal Basis
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Processing orders, delivery, and returns | Contract (b) |
| Fulfilling accounting and consumer law obligations | Legal obligation (c) |
| Customer service, statistics, fraud prevention | Legitimate interest (f) |
| Newsletters, personalized marketing, non-essential cookies | Consent (a) |
3. Data Retention
- Accounting and order data is retained for at least 7 years in accordance with the Swedish Bookkeeping Act.
- Customer account data is kept while the account is active, or for up to 3 years after last interaction.
- Marketing consents are stored until withdrawn.
- Technical logs are deleted or anonymized after a maximum of 12 months.
- In certain cases, retention periods may be extended due to legal requirements or judicial proceedings.
4. Recipients and Data Transfers
We only share data with necessary partners for the purposes outlined above.
- Payments: Stripe, PayPal, Swish (SCC/EU-US DPF for third-country transfers)
- Shipping: PostNord, DHL (within EU/EEA)
- IT & Email Hosting: Swedish hosting provider, cloud services (using SCCs or equivalent safeguards)
- Analytics & Marketing: Google Analytics, Meta Ads – only after your consent
We are not responsible for the data practices or actions of third-party partners beyond our direct control.
5. Automated Decision-Making
We do not make automated decisions that have legal or significant effects on you. Limited profiling may occur for personalized marketing – only after consent.
6. Cookies
Archstudio.se uses cookies to enhance your experience:
- Necessary cookies – required for core website functions
- Analytics cookies – help us understand visitor patterns
- Marketing cookies – used for personalized ads
You choose which non-essential cookies we may use via our cookie banner. See our Cookie Policy for more information.
7. Data Security
- All traffic is encrypted via HTTPS/TLS.
- PCI-compliant payment processing – we never store full card details.
- Firewalls, intrusion protection, and regular security updates.
- Role-based access to personal data.
8. Your Rights
- Request access to your personal data
- Request correction or deletion
- Object to or request restriction of processing based on legitimate interest
- Receive your data in a structured, machine-readable format (data portability)
- Withdraw your consent at any time
Contact us at: privacy@archstudio.se
We will respond within 30 days.
9. Complaints
If you believe your data has been handled improperly, you may contact the Swedish Authority for Privacy Protection (IMY): imy.se
10. Children
This website is not intended for children under 16. We do not knowingly process children’s data without parental consent.
11. Policy Updates
We may update this privacy policy as needed. The most recent version is always published on archstudio.se along with the date of the update.
12. Accuracy of Provided Information
Arch Studio is not responsible for the accuracy or timeliness of information submitted by users via forms on the website.
13. External Links
We are not responsible for the privacy practices or content of third-party websites linked from our site.
Contact
A and A Kungsten AB – Arch Studio
Box 24009, 104 50 Stockholm, Sweden
Email:contact@archstudio.se
Privacy Policy
Effective from: 26 July 2025 (Last updated: 26 July 2025)
1. What Personal Data We Collect
| Category | Examples |
|---|---|
| Identity & Contact Information | name, address, email, phone number |
| Payment & Transaction Data | order ID, payment token (we never store full card numbers), Swish or PayPal reference |
| Delivery & Returns Info | tracking number, delivery status |
| Communication | email, chat, customer service interactions |
| Technical Data | IP address, device ID, cookie ID, logs |
2. Purpose and Legal Basis
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Processing orders, delivery, and returns | Contract (b) |
| Fulfilling accounting and consumer law obligations | Legal obligation (c) |
| Customer service, statistics, fraud prevention | Legitimate interest (f) |
| Newsletters, personalized marketing, non-essential cookies | Consent (a) |
3. Data Retention
- Accounting and order data is retained for at least 7 years in accordance with the Swedish Bookkeeping Act.
- Customer account data is kept while the account is active, or for up to 3 years after last interaction.
- Marketing consents are stored until withdrawn.
- Technical logs are deleted or anonymized after a maximum of 12 months.
- In certain cases, retention periods may be extended due to legal requirements or judicial proceedings.
4. Recipients and Data Transfers
We only share data with necessary partners for the purposes outlined above.
- Payments: Stripe, PayPal, Swish (SCC/EU-US DPF for third-country transfers)
- Shipping: PostNord, DHL (within EU/EEA)
- IT & Email Hosting: Swedish hosting provider, cloud services (using SCCs or equivalent safeguards)
- Analytics & Marketing: Google Analytics, Meta Ads – only after your consent
We are not responsible for the data practices or actions of third-party partners beyond our direct control.
5. Automated Decision-Making
We do not make automated decisions that have legal or significant effects on you. Limited profiling may occur for personalized marketing – only after consent.
6. Cookies
Archstudio.se uses cookies to enhance your experience:
- Necessary cookies – required for core website functions
- Analytics cookies – help us understand visitor patterns
- Marketing cookies – used for personalized ads
You choose which non-essential cookies we may use via our cookie banner. See our Cookie Policy for more information.
7. Data Security
- All traffic is encrypted via HTTPS/TLS.
- PCI-compliant payment processing – we never store full card details.
- Firewalls, intrusion protection, and regular security updates.
- Role-based access to personal data.
8. Your Rights
- Request access to your personal data
- Request correction or deletion
- Object to or request restriction of processing based on legitimate interest
- Receive your data in a structured, machine-readable format (data portability)
- Withdraw your consent at any time
Contact us at: privacy@archstudio.se
We will respond within 30 days.
9. Complaints
If you believe your data has been handled improperly, you may contact the Swedish Authority for Privacy Protection (IMY): imy.se
10. Children
This website is not intended for children under 16. We do not knowingly process children’s data without parental consent.
11. Policy Updates
We may update this privacy policy as needed. The most recent version is always published on archstudio.se along with the date of the update.
12. Accuracy of Provided Information
Arch Studio is not responsible for the accuracy or timeliness of information submitted by users via forms on the website.
13. External Links
We are not responsible for the privacy practices or content of third-party websites linked from our site.
Contact
A and A Kungsten AB – Arch Studio
Box 24009, 104 50 Stockholm, Sweden
Email:contact@archstudio.se


