Privacy Policy
Last updated: 26 June 2026
This Privacy Policy explains how Cardahypop Interior Design ("we", "us", "our") collects, uses, stores, and protects your personal data when you visit our website or contact us. We process personal data in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and applicable national data protection laws in Sweden.
1. Data Controller
The data controller responsible for your personal data is:
Cardahypop Interior Design
Hornsgatan 78, 118 21 Stockholm, Sweden
Email: [email protected]
2. Personal Data We Collect
- Identity data: name, title, company name
- Contact data: email address, telephone number, postal address
- Communication data: messages you send via our contact form or email
- Technical data: IP address, browser type, device information, pages visited
- Cookie data: preferences stored via our cookie consent mechanism (see our Cookie Policy)
3. How We Collect Data
- Directly from you when you fill in our contact form, request a quote, or email us
- Automatically through cookies and similar technologies when you browse our website
- From publicly available business directories where you have listed your company details
4. Purposes and Legal Bases for Processing
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Responding to enquiries and providing quotes | Performance of a contract / steps prior to entering a contract (Art. 6(1)(b)) |
| Delivering our design and styling services | Performance of a contract (Art. 6(1)(b)) |
| Website functionality and security | Legitimate interests (Art. 6(1)(f)) |
| Analytics to improve our website | Consent (Art. 6(1)(a)) - only with your cookie consent |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (where applicable) | Consent (Art. 6(1)(a)) or legitimate interests with opt-out (Art. 6(1)(f)) |
5. Data Retention
- Enquiry and quote records: up to 24 months after last contact
- Client project files: up to 7 years after project completion
- Cookie consent records: 12 months
- Server logs: up to 90 days
6. Data Sharing and Recipients
We do not sell your personal data. We may share data with hosting providers, professional advisers, and public authorities when required by law. Where data is transferred outside the EEA, we ensure appropriate safeguards such as Standard Contractual Clauses.
7. Your Rights Under GDPR
- Right of access (Art. 15) - request a copy of your personal data
- Right to rectification (Art. 16) - correct inaccurate data
- Right to erasure (Art. 17) - request deletion in certain circumstances
- Right to restrict processing (Art. 18)
- Right to data portability (Art. 20) - receive your data in a structured format
- Right to object (Art. 21) - object to processing based on legitimate interests
- Right to withdraw consent (Art. 7(3)) - at any time
- Right to lodge a complaint with your national supervisory authority
To exercise any of these rights, contact us at [email protected]. We will respond within 30 days.
8. Security Measures
We implement appropriate technical and organisational measures including encrypted connections (HTTPS), access controls, regular backups, and staff training on data protection.
9. Automated Decision-Making
We do not use automated decision-making or profiling that produces legal or similarly significant effects on individuals.
10. Children
Our services are directed at adults and businesses. We do not knowingly collect data from children under 16.
11. Changes to This Policy
We may update this Privacy Policy from time to time. The "Last updated" date at the top will reflect any changes.
12. Contact
For privacy-related questions, email [email protected] or write to us at Hornsgatan 78, 118 21 Stockholm, Sweden.