Valid from 2018-05-25
Mysbod.se (Nellispresenter AB) Privacy Policy
Nellispresenter AB cares about your privacy and always strives for a high level of data protection (e.g. we would never sell your personal data to another company).
This privacy policy explains how we collect and use your personal information. It also describes your rights and how you can exercise them.
It is important that you read and understand the privacy policy and feel confident about our processing of your personal data.
What is personal data and what is processing of personal data?
Personal data is any kind of information that can be directly or indirectly attributed to a natural person who is alive.
For example, images and sound recordings processed on a computer can be personal data even if no names are mentioned.
Encrypted data and various types of electronic identities (e.g. IP numbers) are personal data if they can be linked to natural persons.
Processing of personal data is anything that happens to personal data. Any action taken with personal data constitutes processing, whether or not it is carried out by automated means.
Examples of common processing operations are collection, recording, organization, structuring, storage, processing, transfer and erasure.
Who is responsible for the personal data we collect?
Nellispresenter AB, org. no. 559126-6332, with address Kalmarvägen 14, 590 38 Kisa, is responsible for the company's processing of personal data.
What personal data do we collect about you as a customer and for what purpose (why)?
Purpose:
To be able to handle orders/purchases.
Processing carried out:
* Delivery (including notification and contacts regarding the delivery).
* Handling of complaints and warranty cases.
Categories of personal data:
Name, IP number, contact details provided by the customer (e.g. address, e-mail, personal/corporate identity and telephone number).
Payment information, purchase information (e.g. which item has been ordered or whether the item should be sent to a different address).
legal basis
Performance of the purchase contract. This collection of your personal data is necessary for the performance of our obligations under the sales contract.
If the information is not provided, our obligations cannot be fulfilled and we are therefore forced to refuse you the purchase.
Applies from 2018-05-25
Retention period:
Until the purchase has been completed (including delivery and payment) and for a period of 36 months thereafter in order to be able to handle any complaints and warranty issues.
Purpose:
To fulfill the legal obligations of the company.
Processes carried out:
Necessary processing for the fulfillment of the company's legal obligations according to legal requirements, court decisions or decisions by the authorities (e.g. Accounting Act, Money Laundering Act).
Categories of personal data:
Name, IP number, contact details provided by the customer (e.g. address, delivery address, e-mail, personal/corporate identity and telephone number).
Payment information. Information about the time of purchase.
legal basis
Legal obligation. This collection of your personal data is required by law. If the data is not provided, our legal obligation cannot be fulfilled and we are therefore forced to refuse you the purchase.
Retention period:
Until the completion of the purchase (including delivery and payment) and for a period of one year and seven years thereafter.
Who may we share your personal data with?
Data processors. Where it is necessary for us to provide our services, we share your personal data with companies that are so-called data processors for us.
A data processor is a company that processes the information on our behalf and according to our instructions. We have data processors who help us with:
1) Transportation (logistics companies and freight forwarders).
2) IT services (companies that handle the necessary operation, technical support and maintenance of our IT solutions).
3) Disclosure of delivery information to third parties may occur when ordering certain products in order to fulfill the order.
4) Truspilot - to collect customer reviews.
When your personal data is shared with data processors, it is only done for purposes that are compatible with the purposes for which we have collected the information (e.g. to fulfill our obligations under the purchase agreement).
Companies that are independent data controllers. We also share your personal data with certain companies that are independent controllers.
The fact that the company is an independent data controller means that we do not control how the information provided to the company is processed.
Independent data controllers with whom we share your personal data are:
1) Government authorities (police, tax authorities or other authorities) if we are required to do so by law or on suspicion of a crime.
2) Companies offering payment solutions (card acquirers, banks and other payment service providers).
When your personal data is shared with a company that is an independent data controller, it is subject to that company's privacy policy and data processing practices.
How long do we keep your personal data?
We never keep your personal data longer than necessary for the respective purpose. See more about the specific storage periods under each purpose.
Where do we process your personal data?
We always aim to process your personal data within the EU/EEA. However, in the case of system support and maintenance, we may need to transfer the information to a country outside the EU/EEA, e.g. if we share your personal data with a processor who, either itself or through a subcontractor, is established or stores information in a country outside the EU/EEA.
In cases where personal data is processed outside the EU/EEA, the level of protection is guaranteed either by a decision from the European Commission that the country in question ensures an adequate level of protection or by the use of so-called appropriate safeguards. Examples of appropriate safeguards are an approved code of conduct in the recipient country, standard contractual clauses, binding corporate rules or Privacy Shield.
What are your rights as a data subject?
Right of access (so-called 'record extracts'). We are always open and transparent about how we process your personal data and if you want to get a deeper insight into what personal data we process about you, you can request access to the data.
Please note that if we receive a request for access, we may ask for additional information to ensure that your request is handled effectively and that the information is provided to the right person.
Right to rectification. You can request that your personal data be rectified if it is inaccurate. Within the limits of the stated purpose, you also have the right to complete any incomplete personal data.
Right to erasure. You can request the erasure of personal data we process about you if: The data is no longer necessary for the purposes for which it was collected or processed.
You object to a balancing of interests we have made based on legitimate interest and your reason for objecting outweighs our legitimate interest.
You object to processing for direct marketing purposes.
The personal data is processed unlawfully.
The personal data must be erased to comply with a legal obligation to which we are subject.
Personal data has been collected about a child (under the age of 13) for whom you have parental responsibility and the collection has taken place in the context of offering information society services (e.g. social media).
Please note that we may have the right to refuse your request if there are legal obligations that prevent us from immediately deleting certain personal data. These obligations come from accounting and tax legislation, banking and money laundering legislation, but also from consumer rights legislation. It may also be that the processing is necessary for the establishment, exercise or defense of legal claims.
Should we be prevented from complying with a request for erasure, we will instead block the personal data from being used for purposes other than the purpose preventing the requested erasure.
Right to restriction. You have the right to request that our processing of your personal data be restricted. If you contest the accuracy of the personal data we process, you can request a restriction of processing for the time we need to verify the accuracy of the personal data. If we no longer need the personal data for the identified purposes, but you need it to establish, exercise or defend legal claims, you can request restricted processing of the data by us. This means that you can request that we do not delete your data.
If you have objected to a legitimate interest assessment that we have made as a lawful basis for a purpose, you can request restricted processing for the time we need to verify whether our legitimate interests outweigh your interests in having the data erased.
If processing has been restricted under any of the situations above, we may only process the data for the establishment, exercise or defense of legal claims, for the protection of the rights of another person or if you have given your consent, in addition to the storage itself.
Right to object to certain types of processing. You always have the right to opt out of direct marketing and to object to any processing of personal data based on a balance of interests.
Legitimate interest: Where we use a balance of interests as the legal basis for a purpose, you have the possibility to object to the processing. In order to continue processing your personal data after such an objection, we need to be able to demonstrate a compelling legitimate ground for the processing in question that overrides your interests, rights or freedoms. Otherwise, we may only process the data for the establishment, exercise or defense of legal claims.
Direct marketing (including analyses carried out for direct marketing purposes): You have the possibility to object to the processing of your personal data for direct marketing purposes. The objection also covers the analysis of personal data (so-called profiling) carried out for direct marketing purposes. Direct marketing refers to all types of marketing outreach (e.g. by post, email and SMS). Marketing activities where you as a customer have actively chosen to use one of our services or otherwise sought us out to find out more about our services do not count as direct marketing.
If you object to direct marketing, we will stop processing your personal data for that purpose as well as cease all types of direct marketing activities.
How is your personal data protected?
We have put in place security measures to protect your personal data against unlawful or unauthorized processing (such as unauthorized access, loss, destruction or damage).
Only those people who actually need to process your personal data in order for us to fulfill our stated purposes have access to it.
What does it mean that the DPA is the supervisory authority?
The DPA is responsible for monitoring the application of the legislation, and anyone who believes that a company is handling personal data incorrectly can lodge a complaint with the DPA.
What are cookies and how do we use them?
Cookies are a small text file consisting of letters and numbers sent from our web server and stored on your browser or device.
We store and process information about our customers to create anonymous statistics in our e-commerce solution in order to improve our services for our customers.
Can you control the use of cookies yourself?
Yes, you can. Your browser or device allows you to change the settings for the use and scope of cookies. Go to your browser or device settings to learn more about how to adjust your cookie settings. Examples of things you can adjust include blocking all cookies, accepting only first-party cookies or deleting cookies when you close your browser. Please note that some of our services may not work if you block or delete cookies. You can read more about cookies in general on the website of the Swedish Post and Telecom Authority, www.pts.se
We may make changes to our privacy policy. The latest version of the privacy policy is always available here on the website.
The privacy policy was last updated on 2025-11-21