Privacy Policy

Information on How We Process Your Personal Data

  1. Introduction
    This privacy policy (“Privacy Policy”) describes how Yabie processes personal data about you when you use and order from us via the web interface. Yabie is responsible for the personal data processing described in this Privacy Policy as the data controller. We want you to feel secure about how we handle your personal data, so we ask you to read through this Privacy Policy, which we may update from time to time. If we change the Privacy Policy, the new version will apply from the date of publication on Yabie’s website. You can see when we last updated the Privacy Policy at the top of the document.
  2. How We Collect Your Personal Data
    The data we process about you is mainly collected directly from you when you visit and order from us via Yabie’s website.
  3. How We Process Your Personal Data
    3.1 Introduction
    We only process your personal data if the processing is permitted under applicable data protection legislation. This means, among other things, that we must have a legal basis for the purposes of the processing. Below, we describe in more detail the categories of personal data we process, the purposes for which we process them, and the legal bases for our processing of your personal data, including how long the data about you is stored with us.

    3.2 To Manage Orders/Purchases, etc.
    Purpose of Processing:
    To (i) manage your orders/purchases (including sending and handling order confirmations and canceled deliveries, as well as notifying deliveries), (ii) receive payment and, where applicable, issue refunds, (iii) prevent misuse of our suppliers’ services or prevent, investigate, and address crimes.

    Categories of Personal Data:

    • First and last name
    • Contact details, such as email address, phone number, and address
    • Order information
    • Payment method
  4. Legal Basis:
    The processing is necessary for the performance of a contract for the purchase of goods from us. In other cases, the processing is necessary to satisfy our legitimate interest in preventing misuse of our, our suppliers’, or partners’ services or to prevent, investigate, and address crimes, or to otherwise protect legal interests.

    Storage Period:
    We process and store your personal data as long as necessary to fulfill our contract with you, but no longer than two (2) years from your last order.

    3.3 Legal Claims
    We may process your personal data to fulfill our legal obligations under, for example, laws or other regulations that we are subject to, or court or authority decisions that require us to process data about you. We may also process your personal data to establish, assert, or defend legal claims, for example, in the event of an impending or ongoing dispute.
  5. Security Measures
    We take security measures to ensure that our handling of your personal data is done securely. For example, the systems in which personal data is stored are only accessible to our employees and service providers who need the data to perform their tasks. They are also informed about the importance of security and confidentiality concerning the personal data we process. We take appropriate security measures and standards to protect your personal data against unauthorized access, unauthorized disclosure, and misuse. We also monitor our systems to detect vulnerabilities.
  6. With Whom We Share Your Personal Data
    Access to your personal data is limited to persons who need such access for the purposes described in section 3 above. Your personal data is also shared with our suppliers who provide Yabie’s website and enable payments via Yabie’s website. We share personal data with these suppliers so that they can perform services on our behalf. We enter into data processing agreements with suppliers who process personal data on our behalf and take other appropriate measures to ensure that your personal data is processed in a manner consistent with this Privacy Policy. In addition to the personal data we are responsible for, your personal data is also processed by the payment service provider we have contracted to handle your payments. We may also share your personal data with, for example, the Police, the Tax Agency, or other authorities when we are required to do so by law or other regulations or by court or authority decisions.
  7. Where We Process Your Personal Data
    We aim to always process your personal data within the EU/EEA. However, since our supplier of Yabie’s website operates internationally, your personal data may be transferred to countries outside the EU/EEA according to the agreements we have with the supplier. We ensure that the transfer is made in accordance with applicable data protection legislation before the data is transferred, for example, by ensuring that the country to which the data is transferred meets the requirements for an adequate level of protection according to the EU Commission’s decision, or by ensuring that the transfer is covered by appropriate safeguards such as standard contractual clauses decided by the EU Commission and additional appropriate measures to protect your rights and freedoms.
  8. Your Rights
    You have rights in relation to us and our processing of your personal data. Information about your rights and how to exercise them is provided below. Please note that your rights apply to the extent provided by applicable data protection legislation and that there may be exceptions to the rights. Please also note that we may need more information from you to, among other things, confirm your identity before we proceed with your request to exercise your rights. To exercise your rights or request more information about them, please contact us, preferably via email.

    7.1 Right of Access
    You have the right to receive confirmation of whether we process personal data concerning you. If so, you also have the right to access this personal data through a so-called register extract and additional information about the current processing, such as the purpose(s) of the processing, the categories of personal data involved, and the recipients to whom the personal data has been disclosed.

    7.2 Right to Rectification
    You have the right to have incorrect data about you corrected without undue delay. You may also have the right to complete incomplete data.

    7.3 Right to Erasure
    You can request that we delete your personal data without undue delay if:

    • The personal data is no longer necessary for the purposes for which it was collected or otherwise processed;
    • Our processing of personal data is based on your consent, and you withdraw your consent to the processing in question;
    • You object to processing that we carry out based on a balance of interests, and your objection outweighs our or another’s legitimate interest in the processing;
    • The personal data has been processed unlawfully;
    • The personal data must be deleted to comply with a legal obligation.
  9. 7.4 Right to Restriction of Processing
    You have the right to request that we restrict the processing of your personal data if:

    • You dispute the accuracy of the personal data, for a period that allows us to verify whether the data is accurate or not;
    • The processing is unlawful, and you oppose the deletion of your personal data and instead request that we restrict its use;
    • We no longer need to process the data for the purposes for which it was collected, but you need the data to establish, assert, or defend legal claims;
    • You have objected to the processing that we carry out based on a balance of interests and are awaiting verification of whether your objection outweighs our or another’s legitimate interest in continuing the processing.
  10. 7.5 Right to Object
    You have the right to object to such processing of your personal data that is based on our or another’s legitimate interest. If so, we must, to continue the processing, be able to demonstrate compelling legitimate grounds that outweigh your interests, rights, and freedoms.

    7.6 Right to Data Portability
    If we process your personal data based on a contract with you or based on your consent, you have the right to receive the personal data you have provided to us and that concerns you in an electronic format. You have the right to have the data in question transferred from us directly to another data controller, where technically feasible. Please note that this right to so-called data portability does not cover data processed manually by us.7.7 Right to Withdraw Your Consent
    If our processing of your personal data is based on your consent, you always have the right to withdraw your consent at any time. A withdrawal of your consent does not affect the legality of the processing that took place based on the consent before it was withdrawn.

Complaints to the Supervisory Authority
In Sweden, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten) is the authority responsible for overseeing the application of applicable data protection legislation. If you believe that we are processing your personal data incorrectly, we encourage you to contact us first so we can review your concerns. However, you can always file your complaint with the Swedish Authority for Privacy Protection.

Download PDF