FI EN SV

Privacy Policy

This is a privacy policy in accordance with the EU General Data Protection Regulation (GDPR). Prepared on March 29, 2026.

1. Data Controller

Hanna Grönvall
Email: hgronvall@hotmail.com

2. Name of the register

Customer and contact register.

3. Purpose of processing personal data

Personal data is processed for managing the customer relationship, answering inquiries, and planning and implementing services. The data is not used for automated decision-making or profiling.

4. Data content of the register

The following information, which the user voluntarily provides via the contact form, may be stored in the register:

  • First and last name
  • Email address
  • Phone number
  • Message content (e.g., voluntary health-related information)

5. Regular sources of information

Data is regularly obtained from the customer themselves via the website's contact form or email.

6. Regular disclosures and transfer of data

Data is not regularly disclosed to other parties. The website's contact form is implemented using third-party technology (Formspree), which processes the data and securely forwards it to the controller's email. Data is not transferred outside the EU or EEA.

7. Principles of register protection

Digitally processed personal data is protected and stored in a system that only the controller has access to. Logging into the system requires a password.

8. Right of inspection and right to demand correction of data

Every person in the register has the right to check the information stored about them in the register and to demand the correction of any incorrect information or the completion of incomplete information. If a person wants to check the information stored about them or demand a correction, the request must be sent in writing to the controller.

9. Other rights related to the processing of personal data

A person in the register has the right to request the deletion of personal data concerning them from the register ("right to be forgotten"). Other rights under the GDPR, such as the restriction of processing, also apply. Requests must be sent in writing to the controller.