The General Data Protection Regulation (GDPR) grants individuals within the European Union comprehensive rights regarding their personal data. Fika Bakery is committed to full compliance with GDPR requirements and respecting your data protection rights.
Data Controller
For the purposes of GDPR, the data controller is:
Fika Bakery
Storgatan 47
411 38 Göteborg
Sweden
Email: [email protected]
Your Rights Under GDPR
Right to Access
You have the right to request confirmation of whether we process your personal data and to obtain access to such data. You may request a copy of your personal data in a commonly used electronic format.
Right to Rectification
If your personal data is inaccurate or incomplete, you have the right to request that we correct or complete it without undue delay.
Right to Erasure
Also known as the "right to be forgotten," you may request deletion of your personal data when it is no longer necessary for the purposes for which it was collected, when you withdraw consent, or when you object to processing and there are no overriding legitimate grounds.
Right to Restriction of Processing
You may request that we limit the processing of your personal data in certain circumstances, such as when you contest the accuracy of the data or object to processing.
Right to Data Portability
Where processing is based on consent or contract and is carried out by automated means, you have the right to receive your personal data in a structured, commonly used, and machine-readable format and to transmit that data to another controller.
Right to Object
You have the right to object to processing of your personal data based on legitimate interests or for direct marketing purposes. We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Right to Withdraw Consent
Where processing is based on consent, you have the right to withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing based on consent before withdrawal.
Right to Lodge a Complaint
You have the right to lodge a complaint with a supervisory authority, particularly in the EU member state of your residence, place of work, or place of alleged infringement if you believe our processing of your personal data violates GDPR.
How to Exercise Your Rights
To exercise any of the rights described above, please contact us at [email protected]. Include sufficient information to allow us to identify you and understand your request.
We will respond to your request within one month of receipt. In complex cases, we may extend this period by two additional months, and we will inform you of any such extension.
We will verify your identity before processing requests to ensure the security of your personal data. This may require additional information from you.
Legal Bases for Processing
We process your personal data only when we have a legal basis to do so:
- Contract performance: Processing is necessary to fulfill our contractual obligations to you, such as completing orders
- Legal obligation: Processing is required to comply with legal requirements
- Legitimate interests: Processing is necessary for our legitimate business interests, such as improving services, provided your rights do not override these interests
- Consent: You have given explicit consent for processing for specific purposes, such as receiving marketing communications
Data Protection Measures
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
- Encryption of personal data in transit and at rest
- Regular security assessments and updates
- Access controls limiting data access to authorized personnel
- Staff training on data protection principles
- Incident response procedures for data breaches
Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay and within 72 hours of becoming aware of the breach, as required by GDPR.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected or as required by law. Specific retention periods depend on the type of data and purpose:
- Order and transaction data: Retained for accounting and legal purposes for up to 7 years
- Marketing communications: Retained until you unsubscribe or withdraw consent
- Website analytics: Typically aggregated and anonymized within 26 months
Third-Party Processing
When we engage third-party processors, we ensure they provide sufficient guarantees to implement appropriate technical and organizational measures in compliance with GDPR. We enter into data processing agreements that define the subject matter, duration, nature, and purpose of processing.
International Transfers
If we transfer personal data outside the European Economic Area, we ensure appropriate safeguards are in place, such as:
- Standard contractual clauses approved by the European Commission
- Adequacy decisions confirming that the recipient country provides adequate protection
- Your explicit consent for the transfer
Contact Information
For questions, concerns, or to exercise your rights under GDPR, contact us:
Email: [email protected]
Postal Address: Fika Bakery, Storgatan 47, 411 38 Göteborg, Sweden
You may also contact the Swedish Data Protection Authority (Integritetsskyddsmyndigheten) if you have concerns about our data practices.