Last updated: January 2024

Our Commitment

Nordisk Gardinedesign is committed to complying with the General Data Protection Regulation (GDPR). We take our responsibilities as a data controller seriously and have implemented policies and procedures to ensure we meet our obligations under this regulation.

Your Rights Under GDPR

The GDPR provides you with specific rights regarding your personal data:

Right to Access

You have the right to request a copy of the personal data we hold about you. We will provide this information within one month of your request, free of charge.

Right to Rectification

If personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will make necessary corrections promptly.

Right to Erasure

You may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose or you withdraw consent.

Right to Restrict Processing

You can request that we limit the processing of your personal data while we verify its accuracy or assess the legitimacy of a complaint.

Right to Data Portability

You have the right to receive your personal data in a structured, commonly used format and to transfer it to another data controller.

Right to Object

You can object to processing of your personal data based on legitimate interests or for direct marketing purposes.

Rights Related to Automated Decision Making

You have the right not to be subject to decisions based solely on automated processing that significantly affect you.

How We Process Your Data

We process personal data only when we have a lawful basis to do so. The legal bases we rely on include:

  • Consent you have provided
  • Necessity for contract performance
  • Compliance with legal obligations
  • Legitimate interests that do not override your rights

Data Protection Measures

We implement appropriate technical and organizational measures to ensure security of your personal data:

  • Encryption of data in transit and at rest
  • Access controls limiting data access to authorized personnel
  • Regular security assessments and updates
  • Staff training on data protection practices
  • Secure data storage and backup procedures

Data Breach Procedures

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify the Danish Data Protection Agency within 72 hours. If the breach is likely to result in high risk to you, we will also notify you directly.

Third-Party Processors

When we engage third-party service providers who process personal data on our behalf, we ensure they provide sufficient guarantees of compliance with GDPR requirements through appropriate contractual arrangements.

International Data Transfers

Your data is primarily processed within the European Economic Area. Any transfers to countries outside the EEA are conducted with appropriate safeguards such as standard contractual clauses approved by the European Commission.

Exercising Your Rights

To exercise any of your GDPR rights, please contact us at [email protected]. We will respond to your request within one month. If your request is complex or we receive numerous requests, we may extend this period by a further two months, notifying you of the extension and reasons within the first month.

Complaints

If you are not satisfied with how we handle your personal data or your rights request, you may lodge a complaint with the Danish Data Protection Agency:

Datatilsynet
Carl Jacobsens Vej 35
2500 Valby
Denmark

Contact

For GDPR-related inquiries, contact us at:

Nordisk Gardinedesign
Strandvejen 142
2900 Hellerup
Denmark
[email protected]