Privacy and GDPR
Privacy notice
Nordy only uses personal data needed to operate the shop, deliver orders, answer enquiries and meet legal obligations.
Last updated:
Seller information
- Legal name
- PASTEL ARTWEAR AS
- Organisation number
- 932695138
- Registered in
- Foretaksregisteret
- VAT status
- Not registered in the Norwegian VAT Register
- Business address
- Schübelers gate 7A, 0577 Oslo, Norway
- Return address
- Schübelers gate 7A, 0577 Oslo, Norway
- post@nordy.no
- Telephone
- Will be published before the online shop opens
1. Data controller
The legal seller identified below is the data controller for Nordy's processing of personal data. Privacy enquiries may be sent to the contact address that will be published before the online shop opens.
2. Data we process
- Order data: name, email address, delivery address, products, size, amount, language and order status.
- Payment data: payment provider, payment reference and payment status. Nordy does not store full card details.
- Enquiries: the content of emails or other messages you send and information needed to handle the matter.
- Technical data: IP address, timestamp, requested page, browser information and security logs that may be recorded by the web server or hosting provider.
3. Purposes and legal bases
- Order, payment, delivery, returns and customer service – necessary to enter into or perform a contract under GDPR Article 6(1)(b).
- Accounting, transaction records, consumer rights and other legal requirements – necessary to comply with a legal obligation under Article 6(1)(c).
- Website security, abuse prevention and troubleshooting – Nordy's legitimate interest in a secure and stable service under Article 6(1)(f).
- Optional analytics or marketing will only be used with valid consent under Article 6(1)(a). Such tracking is not currently enabled.
4. Who receives the data
Data is shared only where necessary with providers that help Nordy deliver the service: Hostinger for hosting, Stripe and Klarna for Klarna payments, Vipps MobilePay for Vipps payments, the selected carrier for delivery, and any accounting or IT provider.
Payment providers are independent controllers for parts of their processing, including identity checks, payment assessments and fraud prevention. Their own privacy notices apply to that processing.
5. Retention and deletion
Order and accounting data needed as accounting documentation is normally kept for five years after the end of the relevant financial year. Customer-service enquiries are normally deleted no later than 12 months after the matter is closed unless longer retention is needed to document a legal claim.
Ordinary technical logs shall have the shortest practical retention period. The final logging and security retention used by Hostinger will be documented before launch. Data is deleted or anonymised when its purpose and any statutory retention period have ended.
6. International transfers
Some providers may process data outside Norway. Transfers outside the EEA must have a valid transfer basis and appropriate safeguards, such as an adequacy decision or the EU Standard Contractual Clauses. Provider privacy notices contain further details.
7. Your rights
- Request access to personal data Nordy holds about you.
- Request correction, deletion or restriction where the conditions are met.
- Object to processing based on legitimate interests.
- Request data portability for data processed on the basis of contract or consent.
- Withdraw consent without affecting processing carried out before withdrawal.
- Complain to the Norwegian Data Protection Authority if you believe the rules have been breached.
8. Security and automated decisions
Nordy uses access controls, encrypted transport, limited data access and other appropriate technical and organisational measures. Nordy does not use personal data for its own automated decision-making or profiling. Payment providers may carry out their own automated checks under their terms.
