Privacy Policy

Privacy Policy

Effective from: 26 July 2025 (Last updated: 26 July 2025)

1. What Personal Data We Collect

Category Examples
Identity & Contact Information name, address, email, phone number
Payment & Transaction Data order ID, payment token (we never store full card numbers), Swish or PayPal reference
Delivery & Returns Info tracking number, delivery status
Communication email, chat, customer service interactions
Technical Data IP address, device ID, cookie ID, logs

2. Purpose and Legal Basis

Purpose Legal Basis (GDPR Art. 6)
Processing orders, delivery, and returns Contract (b)
Fulfilling accounting and consumer law obligations Legal obligation (c)
Customer service, statistics, fraud prevention Legitimate interest (f)
Newsletters, personalized marketing, non-essential cookies Consent (a)

3. Data Retention

  • Accounting and order data is retained for at least 7 years in accordance with the Swedish Bookkeeping Act.
  • Customer account data is kept while the account is active, or for up to 3 years after last interaction.
  • Marketing consents are stored until withdrawn.
  • Technical logs are deleted or anonymized after a maximum of 12 months.
  • In certain cases, retention periods may be extended due to legal requirements or judicial proceedings.

4. Recipients and Data Transfers

We only share data with necessary partners for the purposes outlined above.

  • Payments: Stripe, PayPal, Swish (SCC/EU-US DPF for third-country transfers)
  • Shipping: PostNord, DHL (within EU/EEA)
  • IT & Email Hosting: Swedish hosting provider, cloud services (using SCCs or equivalent safeguards)
  • Analytics & Marketing: Google Analytics, Meta Ads – only after your consent

We are not responsible for the data practices or actions of third-party partners beyond our direct control.

5. Automated Decision-Making

We do not make automated decisions that have legal or significant effects on you. Limited profiling may occur for personalized marketing – only after consent.

6. Cookies

Archstudio.se uses cookies to enhance your experience:

  • Necessary cookies – required for core website functions
  • Analytics cookies – help us understand visitor patterns
  • Marketing cookies – used for personalized ads

You choose which non-essential cookies we may use via our cookie banner. See our Cookie Policy for more information.

7. Data Security

  • All traffic is encrypted via HTTPS/TLS.
  • PCI-compliant payment processing – we never store full card details.
  • Firewalls, intrusion protection, and regular security updates.
  • Role-based access to personal data.

8. Your Rights

  • Request access to your personal data
  • Request correction or deletion
  • Object to or request restriction of processing based on legitimate interest
  • Receive your data in a structured, machine-readable format (data portability)
  • Withdraw your consent at any time

Contact us at: privacy@archstudio.se
We will respond within 30 days.

9. Complaints

If you believe your data has been handled improperly, you may contact the Swedish Authority for Privacy Protection (IMY): imy.se

10. Children

This website is not intended for children under 16. We do not knowingly process children’s data without parental consent.

11. Policy Updates

We may update this privacy policy as needed. The most recent version is always published on archstudio.se along with the date of the update.

12. Accuracy of Provided Information

Arch Studio is not responsible for the accuracy or timeliness of information submitted by users via forms on the website.

13. External Links

We are not responsible for the privacy practices or content of third-party websites linked from our site.


Contact

A and A Kungsten AB – Arch Studio
Box 24009, 104 50 Stockholm, Sweden
Email:contact@archstudio.se

Privacy Policy

Effective from: 26 July 2025 (Last updated: 26 July 2025)

1. What Personal Data We Collect

Category Examples
Identity & Contact Information name, address, email, phone number
Payment & Transaction Data order ID, payment token (we never store full card numbers), Swish or PayPal reference
Delivery & Returns Info tracking number, delivery status
Communication email, chat, customer service interactions
Technical Data IP address, device ID, cookie ID, logs

2. Purpose and Legal Basis

Purpose Legal Basis (GDPR Art. 6)
Processing orders, delivery, and returns Contract (b)
Fulfilling accounting and consumer law obligations Legal obligation (c)
Customer service, statistics, fraud prevention Legitimate interest (f)
Newsletters, personalized marketing, non-essential cookies Consent (a)

3. Data Retention

  • Accounting and order data is retained for at least 7 years in accordance with the Swedish Bookkeeping Act.
  • Customer account data is kept while the account is active, or for up to 3 years after last interaction.
  • Marketing consents are stored until withdrawn.
  • Technical logs are deleted or anonymized after a maximum of 12 months.
  • In certain cases, retention periods may be extended due to legal requirements or judicial proceedings.

4. Recipients and Data Transfers

We only share data with necessary partners for the purposes outlined above.

  • Payments: Stripe, PayPal, Swish (SCC/EU-US DPF for third-country transfers)
  • Shipping: PostNord, DHL (within EU/EEA)
  • IT & Email Hosting: Swedish hosting provider, cloud services (using SCCs or equivalent safeguards)
  • Analytics & Marketing: Google Analytics, Meta Ads – only after your consent

We are not responsible for the data practices or actions of third-party partners beyond our direct control.

5. Automated Decision-Making

We do not make automated decisions that have legal or significant effects on you. Limited profiling may occur for personalized marketing – only after consent.

6. Cookies

Archstudio.se uses cookies to enhance your experience:

  • Necessary cookies – required for core website functions
  • Analytics cookies – help us understand visitor patterns
  • Marketing cookies – used for personalized ads

You choose which non-essential cookies we may use via our cookie banner. See our Cookie Policy for more information.

7. Data Security

  • All traffic is encrypted via HTTPS/TLS.
  • PCI-compliant payment processing – we never store full card details.
  • Firewalls, intrusion protection, and regular security updates.
  • Role-based access to personal data.

8. Your Rights

  • Request access to your personal data
  • Request correction or deletion
  • Object to or request restriction of processing based on legitimate interest
  • Receive your data in a structured, machine-readable format (data portability)
  • Withdraw your consent at any time

Contact us at: privacy@archstudio.se
We will respond within 30 days.

9. Complaints

If you believe your data has been handled improperly, you may contact the Swedish Authority for Privacy Protection (IMY): imy.se

10. Children

This website is not intended for children under 16. We do not knowingly process children’s data without parental consent.

11. Policy Updates

We may update this privacy policy as needed. The most recent version is always published on archstudio.se along with the date of the update.

12. Accuracy of Provided Information

Arch Studio is not responsible for the accuracy or timeliness of information submitted by users via forms on the website.

13. External Links

We are not responsible for the privacy practices or content of third-party websites linked from our site.


Contact

A and A Kungsten AB – Arch Studio
Box 24009, 104 50 Stockholm, Sweden
Email:contact@archstudio.se