Privacy Policy for Haypp

Haypp AB, company reg. no. 559174-2738, ("The Company" or “We”) is the responsible company for the processing of your personal data when using the Company Website (www.haypp.com) (“the Website”), mobile website or contacting the Company through our Customer Service. We are strongly committed to protecting personal data.  This privacy statement describes why and how we collect and use personal data and provides information about individuals’ rights.  It applies to personal data provided to us, both by individuals themselves or by others. We may use personal data provided to us for any of the purposes described in this privacy statement or as otherwise stated at the point of collection.


Which personal data do we collect?

The company collects information at first directly from you as a customer. We collect the following personal information from you.

- Name and social security number

- Address

- Phone number and email

- Payment details

- Account information

- IP address and information about your use of the Company's Website

- Information about visitor statistics, which of our goods or offers you have been interested in, how you have interacted with our newsletters

- Information about your purchases


How we use the information collected

The Company processes personal information mainly for the purposes stated below and for any additional purposes stated at the point of collection:

- In order to manage your order / purchase and manage your user account;

- Enable good customer service / manage customer service issues, such as managing your requests, correcting incorrect information, or sending information you have requested e.g. newsletters;

- Information relating to the ordering of a service is stored and analyzed, and constitutes the basis for offers and promotion of both general and targeted nature;

- In order to manage customer profiles, conduct analyzes and market research;

- For system administration and for obtaining statistical data about the behavior and patterns of our users, this does however not identify an individual but occurs at an aggregated level;

- In order to develop, deliver and improve our products and services through analysis of your behavior on our Website;

- We may process your personal information through profiling. We analyze information about your usage of our Websites, which of our products, services and offers you have been interested in, which of our newsletters you have interacted with, information about your purchases and information about your account, in order to provide you with the most relevant offers. This information may be anonymized and transferred to our partners. This is done at an entirely anonymous and aggregated level.

- In order to send you information and marketing via digital communication, as you have an active customer relationship with us please note that you can chose to opt out at any time.

- In order to provide you with relevant recommendations, offers and custom-made services based on what others with similar behavior have been interested in, what kind of service you have chosen, looked at and shown interest in;

- In order to help us develop our Website to be more useful and to enhance your user experience of the platforms offered by the Company, by customizing the display of services to the device being used;

- In order to provide you with important messages such as information about changes in our terms and policies;

- In order to fulfill legal obligations (eg requirements in the Bookkeeping Act etc)


Regarding your birth date

We ask you to provide your birth date when first entering the Website and when placing an order. We require this information in order to verify your age. The legal basis of processing of this data is our obligation to comply with age limit limitations for the sale of nicotine products.


Information that may be disclosed

We may share information with other companies that process data on our behalf in order for us be able to perform our services, for example analysis, distribution, IT services or other services to maintain and apply our terms of use and delivery terms. We may also disclose information to companies for usage in the evaluation and disclosure of reviews of our services and our Website, as well as market research. However, we always apply a high level of security and confidentiality when processing all personal data.

 

The Company only collaborates with third parties who processes personal data within the EU / EEA or with companies that maintain the same level of protection as in the EU / EEA by, for example,  joined the so-called Privacy Shield-EU-US Shield Agreement.


About cookies

We use cookies when you visit the Website. Read more about how we use cookies in our Cookie Policy.


Lawful basis, storage and disclosure of personal data

By submitting information to the Company, you grant your permission to the Company to register, store and process your personal data for the specified purposes. The lawful bases for processing are

 

(a) Contract: the processing is necessary in order for the company to fulfil the purchase contract between you and the Company.

 

(b) Legal obligation: the processing is necessary for the Company’s legal compliance, e.g. the Bookkeeping act.

 

(c) Legitimate interests: the processing is necessary for the Company’s legitimate interests or the legitimate interests of a third party.  

 

The Company stores your personal data for as long as you are a customer with us, i.e as long as you have not unsubscribed from your account with the Company. This means that the personal data will be erased when they are no longer relevant or necessary for the purposes for which they were collected. .If you do not have an account with us, your information will be stored for two years from your last purchase and then deleted. Some information may be retained during a longer period due to other legal requirements, such as the Bookkeeping Act. We always apply a high level of security and confidentiality when processing all personal data.


Your rights and choices

You have certain specific legal rights that you can enforce against us. A summary of these rights follows below.

 

Right to access/extracts from the register. You have the right to know what personal data about you we are processing. Upon request from you, we will provide you with information in writing about our processing of your personal data, free of charge.

 

Right to data portability. You have the right to request a copy of the personal data you have provided to us in a structured, commonly used and machine-readable format. Provided that it is technologically possible, in Haypp’s sole discretion, you also have the right to request that we transfer this personal data to another controller. The right to data portability applies to personal data that is processed via automated means, and that is based on the performance of a contract.

 

Correction of erroneous information. You have the right to request that we correct erroneous or incomplete information about yourself. If you have an account you may also correct certain information by logging in.

 

Deletion of certain data. You have the right to request that we delete your personal data under certain conditions, for example if your personal data is no longer necessary for the purpose for which we collected the data, if you object to a weighing of legitimate interests we have carried out and support for our legitimate interest is lacking, if your personal data was processed in an unlawful manner or if your personal data has to be deleted in order to fulfill a legal obligation.

In certain cases, we must retain your personal data despite your request, owing to legal requirements such as accounting and tax legislation, or for example if we need to retain certain data in order to establish, enforce or defend a legal claim.

 

Right to restrict processing of your personal data. You have the right to demand a restriction on our processing of your personal data in certain cases. If, for example, you claim that your personal data is incorrect, you can request a restriction on processing for a period of time that will give us the opportunity to check if your personal data is correct.

 

Right to object to our processing of personal data. You have the right, under certain conditions, to object to our processing of your personal data.

 

You have the right to object to processing that is based on the legal grounds of our legitimate interest. However, we may continue processing your data despite your objection to the processing if we have compelling legitimate reasons for the processing that override your privacy interests.
 


Questions and complaits

If you have any questions regarding our processing of your personal data, or if you would like to present a request about an excerpt from the registry, data portability, correction or deletion – or present an objection or a restriction – please contact us at

 

Haypp AB, company reg no. 559174-2738

 

Kungsgatan 27, SE-111 56 Stockholm, Sweden
 

Customer Service Phone number: +44 1929 290 005

 

If you have a complaint regarding the Company’s processing of your personal data, you have the right to submit such complaints to the competent data protection authority.


Changes to the privacy policy

The Company reserves the right to make changes to this privacy notice. Any such changes are published on the Website www.haypp.com. We therefore encourage you to periodically review this privacy notice for any changes.


In the event that our site contains links to third party websites, or material published by third parties, these links are for information purposes only. Due to the fact that the Company has no control over the content of these websites, we cannot be held responsible for it. Further, the Company is not responsible for any loss that might arise from the use of these links. For example, at the checkout at www.haypp.com, there are links to our external payment provider, Klarna. This website applies its own privacy policy and the Company is not responsible for any personal data that you may provide on these pages.

 

This privacy policy is applicable from December 20, 2018