Privacy policy
This Privacy Policy describes how we collect, use, and protect your personal data when you visit our website or interact with us through purchases, account creation, or customer support. We are committed to protecting your privacy in accordance with applicable data protection laws, including the EU General Data Protection Regulation (GDPR).
1. Who we are
This website is operated by Studio Schalling AB, a company registered in Sweden with registered address at Skrittgatan 9, 213 77 Malmö, Sweden. If you have any questions about this Privacy Policy or how we handle your data, you can contact us at info@schalling.se.
We assume full responsibility that the objects are in their described condition when they reach you. This responsibility holds until the object is either collected by the buyer or delivered by the shipping company. If the object(s) have been damaged during transport, we urge the customer to point this out directly to the shipping firm and also notify us immediately.
2. What data we collect
We may collect the following personal data from you:
- Name and contact details (email, phone number, address)
- Payment and billing information (processed via third-party providers)
- Purchase history and order details
- Login credentials (for registered users)
- Preferences and interaction with the site (through cookies and analytics)
- IP address and device/browser information
- Information related to participation in loyalty programs such as our Trade Program
3. How we use your data
We use your data for the following purposes:
- To process and deliver your orders
- To provide customer support
- To manage your account and loyalty status
- To analyze site usage and improve performance
- To detect and prevent fraud and misuse
- To comply with legal obligations (including anti-money laundering laws)
- For marketing and promotional purposes, if you have given consent
4. Legal Basis for Processing
We process your personal data under the following legal bases:
- Contractual necessity – to fulfill orders and provide services
- Legal obligation – for tax, accounting, and anti-money laundering compliance
- Legitimate interest – to improve our services and prevent fraud
- Consent – for marketing or optional cookies, where required
5. Sharing Your Data
We may share your data with:
- Payment providers (e.g., Stripe)
- Shipping and logistics partners
- IT and cloud service providers
- Analytics and marketing platforms (e.g., Google, Meta)
- Government authorities when legally required (e.g., tax or AML investigations)
We never sell your data to third parties.
6. Anti-Money Laundering (AML) compliance
As a business subject to financial transaction laws, we comply with all applicable anti-money laundering (AML) regulations under EU and national legislation, including the 6th EU Anti-Money Laundering Directive (6AMLD).
This may include:
- Verifying customer identity in high-value transactions
- Monitoring unusual or suspicious payment activity
- Retaining transaction records for a legally mandated period
- Reporting suspicious activities to competent authorities (e.g., the Swedish Financial Intelligence Unit)
- By making a purchase or creating an account, you acknowledge that your data may be processed for AML compliance purposes.
7. Data retention
We retain your personal data only as long as necessary to fulfill the purposes described in this policy, or as required by law. For example, order and billing data may be retained for 7 years to comply with accounting and tax requirements.
8. Your rights
Under GDPR and relevant laws, you have the right to:
- Access the personal data we hold about you
- Request correction of incorrect or incomplete data
- Request deletion of your data (“right to be forgotten”)
- Object to or restrict certain types of processing
- Withdraw your consent at any time (where processing is based on consent)
- Lodge a complaint with a supervisory authority
To exercise any of your rights, contact us at info@schalling.se.
9. Data security
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, disclosure, alteration, or destruction. This includes encrypted connections (SSL), secure payment processing, and access restrictions.
10. International transfers
If we transfer personal data outside the EU/EEA, we ensure that adequate safeguards are in place, such as Standard Contractual Clauses (SCCs) or data transfer agreements in accordance with GDPR.
11. Updates to this policy
We reserve the right to update this Privacy Policy at any time. Any significant changes will be communicated through our website. The most current version will always be available on this page.