Privacy policy
COOKIE AND PRIVACY POLICY AT POMPdeLUX ApS
POMPdeLUX strives to ensure that your personal information is protected when you use our services. Therefore, we have developed a policy on how your personal information is processed and protected. This policy applies to any processing we perform of your personal information.
1. GENERAL
1.1 This policy describes how POMPdeLUX ApS collects and processes the personal data you provide to us, or that we collect about you when you shop directly on our website, www.pompdelux.com.
2. CONTACT INFORMATION FOR THE DATA CONTROLLER
2.1 POMPdeLUX ApS is the data controller for the personal data we collect.
2.2 POMPdeLUX ApS shares data responsibility with Facebook for personal data collected using Facebook's analysis tool "Facebook Page Insights" when you visit our Facebook page. Read more under section 3.4.
2.3 If you have any questions or comments about this privacy policy, or if you wish to exercise one or more of your rights described in section 6, you can contact: POMPdeLUX ApS
A.P. Møllers Allé 55,
2791 Dragør
Phone: (+45) 53888950
Email: hello@pompdelux.dk
3. WHAT PERSONAL DATA WE COLLECT, FOR WHAT PURPOSES, AND THE LEGAL BASIS FOR PROCESSING
3.1 When you visit the website, we collect information about your use of the website, such as the type of browser you use, search terms you use, your IP address, including your network location, and information about the device you use to visit the website. We also collect information about which products and services you click on and add to your cart. The information is collected, among other things, using cookies. Read more in our cookie policy.
3.1.1 The purpose is:
3.1.1.1 to compile statistics so we can analyze how our customers use and navigate our website, so we can optimize the user experience and the website's functionality
3.1.1.2 to provide you with product suggestions that we believe you may be interested in on our website
3.1.1.3 to market our products to you, including via Facebook and Google
3.1.1.4 to improve the security of our site 3.1.2 The legal basis for processing is Article 6(1)(f) of the EU General Data Protection Regulation (GDPR).
3.2 When you purchase a product or communicate with us on the website, we collect the information you provide yourself, such as name, address, email address, phone number, payment method, information about the time of purchase, which products you buy and possibly return, delivery preferences, and information about the IP address from which the order is placed.
3.2.1 The purpose is:
3.2.1.1 to register you as a customer and deliver the products you have ordered and otherwise fulfill our agreement with you
3.2.1.2 to manage your rights to return and complain 3.2.1.3 to prevent fraud 3.2.1.4 to comply with legal requirements, including bookkeeping and accounting
3.2.2 The legal basis for processing is Article 6(1)(b) (sections 3.2.1.1 - 2.), Article 6(1)(c) (section 3.2.1.4), and Article 6(1)(f) (section 3.2.1.3) of the GDPR.
3.3 When you sign up for our newsletter, including SMS and customer surveys, we collect information about your name, email address, IP address, and possibly mobile number. We also collect information about when you signed up for the newsletter, when you unsubscribed from the newsletter, and information about where and when you open the newsletter. You can unsubscribe from SMS news at any time by following the instructions in a received SMS.
3.3.1 The purpose is:
3.3.1.1 to deliver newsletters/SMS or customer surveys to you
3.3.1.2 to compile statistics for optimizing the newsletters and for marketing our services
3.3.1.3 to document your consent to receive the newsletter
3.3.2 The legal basis for processing is Article 6(1)(f) of the GDPR. 3.4 When you visit our Facebook page, please be aware that we use Facebook's analysis tool "Facebook Page Insights" to get statistics on visitors and to gain insight into user behavior on our Facebook page, including the number of likes, who likes, the number of page views and interactions with the page, withdrawal of likes, and the reach of posts, etc. In this context, we and Facebook collect information as joint data controllers. When you visit our Facebook page, you will have access to information about this processing. You can get more information here: https://www.facebook.com/legal/terms/information_about_page_insights_data We and Facebook have entered into an agreement on joint data responsibility. You can read the agreement here: https://www.facebook.com/legal/terms/page_controller_addendum
4. LEGITIMATE INTERESTS PURSUED BY PROCESSING
As mentioned above, our processing of your personal data is partly based on the balancing of interests rule in Article 6(1)(f) of the GDPR. We have weighed our legitimate interests in marketing, improving the website, security, and preventing fraud against your interests to ensure that your interests or fundamental rights or freedoms do not outweigh our interests. If you want more information about the balancing of interests we have conducted, you can contact us at the address listed in section 2.
5. RECIPIENTS OF PERSONAL DATA
5.1 Information about your name, address, email, phone number, order number, and specific delivery preferences is disclosed to Bring, GLS, DHL, FeedEx, or another carrier responsible for delivering the purchased goods to you. When purchasing goods that are not in our own stock, the mentioned information may be disclosed to the manufacturer or importer of the respective goods, who will then handle the delivery.
5.2 Personal data may be disclosed to public authorities if we are required to do so by law, or to the police in case of suspicion of criminal offenses or as part of an investigation of specific criminal offenses. Information about a purchase, including who made the purchase and where the item was delivered, may be disclosed to the card issuer if the cardholder states that the card has been misused in connection with the specific purchase.
5.3 Information may be disclosed to external partners who process the information on our behalf. We use external partners for, among other things, hosting, technical operation, and improvements of the website, sending newsletters, targeted marketing, including re-targeting, and for your evaluation of our company and products. These companies are data processors and act under our instructions, and they process data for which we are data controllers. The data processors may not use the information for any purpose other than fulfilling the agreement with us and are subject to confidentiality regarding these.
5.4 Four of these data processors, Google Analytics by Google LLC, Facebook Inc., Klaviyo, and Shopify, are established in the USA. The necessary guarantees for the transfer of information to the USA are ensured through the data processor's certification under the EU-U.S. Privacy Shield, pursuant to Article 45 of the GDPR. You can see an overview of American companies registered with the DPF here: https://www.dataprivacyframework.gov/s/participant-search.
5.4.1 A copy of Google LLC's certification can be found here: https://www.privacyshield.gov/participant?id=a2zt000000001L5AAI&status=Active 5.4.2 A copy of Meta Inc.'s certification can be found here: https://www.facebook.com/privacy/policies/data_privacy_framework
5.4.3 A copy of Klaviyo's certification can be found here: https://www.klaviyo.com/legal/privacy/privacy-notice
6. YOUR RIGHTS
6.1 To create transparency about the processing of your information, we, as the data controller, must inform you of your rights. If you wish to exercise your rights, you can contact us. You can find our contact information under section 2.
6.2 Right of access
6.2.1 You have the right to be informed, among other things, about what information we have registered about you, the purpose of the registration, the categories of personal data and recipients of information that may exist, and information about where the information originates from. You also have the right to receive a copy of this information.
6.3 Right to rectification
6.3.1 You have the right to have incorrect personal data about yourself corrected. 6.3.2 Information that we have collected in connection with your creation of a customer profile on POMPdeLUX.dk, you can correct yourself via login to your profile.
6.4 Right to erasure
6.4.1 In certain cases, you have the right to have all or some of your personal data deleted by us, for example, if you withdraw your consent and we do not have another legal basis for continuing the processing. To the extent that continued processing of your information is necessary, for example, for us to comply with our legal obligations, or for legal claims to be established, asserted, or defended, we are not obliged to delete your personal data.
6.5 Right to restrict processing to storage
6.5.1 In certain cases, you have the right to have the processing of your personal data restricted to only consist of storage. In such cases, we may only process the information with your consent or for the purpose of establishing, asserting, or defending a legal claim.
6.6 Right to data portability 6.6.1 In certain cases, you have the right to receive personal data that you have provided to us in a structured, commonly used, and machine-readable format and have the right to transfer this information to another data controller.
6.7 Right to object 6.7.1 You have the right at any time to object to our processing of your personal data for direct marketing purposes, including any profiling carried out to target our direct marketing. You also have the right at any time, for reasons relating to your personal situation, to object to the processing of your personal data that we carry out based on our legitimate interests, as mentioned in sections 3 and 4.
6.8 Right to withdraw consent 6.8.1 You have the right at any time to withdraw consent you have given us for a given processing of personal data.
6.9 Right to complain 6.9.1 You have the right at any time to file a complaint with the Data Protection Agency if you are dissatisfied with the way we process your personal data. You can find a complaint form and contact information at www.datatilsynet.dk
7. DELETION OF PERSONAL DATA
7.1 Information collected about your use of the website according to section 3.1 is deleted in accordance with the cookie declaration, which you can find in the cookie policy below.
7.2 Information collected in connection with your subscription to our newsletter, according to section 3.3, is deleted when your consent to the newsletter is withdrawn unless we have another basis for processing the information. We may automatically delete your subscription if you have not been active for a given period. However, we may retain documentation of your consent for 2 years after we last sent you electronic marketing.
7.3 Information collected in connection with purchases you have made on the website according to section 3.2 will generally be deleted 2 years after the end of the calendar year in which you made your purchase. However, information may be stored for a longer period if we have a legitimate need for longer storage, for example, if it is necessary for legal claims to be established, asserted, or defended, or if storage is necessary for us to comply with legal requirements. Accounting material is stored for 5 years until the end of a financial year to comply with the requirements of the Accounting Act.
8. SECURITY
8.1 We have implemented appropriate technical and organizational security measures to prevent personal data from being accidentally or illegally destroyed, lost, altered, or impaired, and to prevent them from coming to the knowledge of unauthorized persons or being misused.
8.2 Only employees who have a real need to access your personal data to perform their work have access to them.
9. CHANGES TO THE PRIVACY POLICY
9.1 If we make changes to the Privacy Policy, you will be informed of this on your next visit to the website.
10. VERSIONS
10.1 This is version 1 of POMPdeLUX ApS’s privacy policy dated 30-09-2024.








