Privacy Policy (Personvernerklæring) — Silkeon

Last Updated: June 2026 | Org. nr: [ORG-NUMBER] | GDPR & Personopplysningsloven (LOV-2018-06-15-38) compliant

1. Data Controller (Behandlingsansvarlig)

Silkeon (Org. nr: [ORG-NUMBER]), Lægdesvingen 5096 Bergen, Norway is the data controller. GDPR Art. 4(7) Contact: support@silkeon.com | +47 929 29 552. Silkeon does not have a mandatory obligation to appoint a DPO (not a public authority, no large-scale systematic monitoring). For all privacy matters: support@silkeon.com.

2. Data We Collect

  • Identity: Full name
  • Contact: Email, phone, postal address (delivery)
  • Transactional: Products ordered, amounts, order history, payment method type (not card numbers)
  • Account: Username, hashed password (never plain text)
  • Technical: IP address, browser, device, OS, session data
  • Usage: Pages viewed, products viewed, search terms, referral source
  • Communications: Content of support emails/messages
  • Marketing: Email consent status (opt-in/opt-out)

We do NOT collect: card numbers (payment provider processes directly), special category data (health, religion, ethnicity, biometrics), or data from children under 15 without parental consent.

3. Legal Basis for Processing GDPR Art. 6

Purpose Legal Basis Article
Order processing & fulfillment Contract performance Art. 6(1)(b)
Product delivery Contract performance Art. 6(1)(b)
Customer account management Contract performance Art. 6(1)(b)
Returns and refunds Contract / Legal obligation Art. 6(1)(b)/(c)
Accounting records (7 years) Legal obligation (Bokføringsloven §13) Art. 6(1)(c)
Consumer rights compliance Legal obligation (Angrerettloven) Art. 6(1)(c)
Fraud detection & prevention Legitimate interests Art. 6(1)(f)
Website analytics Legitimate interests / Consent Art. 6(1)(f)/(a)
Marketing emails Consent (Markedsføringsloven §15) Art. 6(1)(a)
Non-essential cookies Consent Art. 6(1)(a)

4. Data Retention

Data Type Retention Period Basis
Order & accounting records 7 years after transaction Bokføringsloven §13
Customer account — active Duration of account Contract
Customer account — inactive 3 years after last login Legitimate interest
Email consent & marketing records Until unsubscribed + 2 years GDPR Art. 7(1)
Analytics cookies Maximum 13 months Consent
Support communications 3 years Legitimate interest
Server/security logs 90 days Legitimate interest

5. Third-Party Processors GDPR Art. 28

  • Stripe Inc. (USA): Payments — EU Standard Contractual Clauses (SCC). PCI-DSS Level 1.
  • PayPal Holdings (USA): Payments — SCC. GDPR self-certified.
  • Vipps MobilePay AS (Norway): Payments — Norwegian entity, Norwegian data protection law.
  • Klarna AB (Sweden): Pay Later — EEA entity, GDPR compliant.
  • Google LLC (USA) — GA4: Analytics — IP anonymised, SCC. Used for website improvement.
  • Shipping carriers (Posten/Bring/DHL): Name + delivery address for fulfillment only.
  • WordPress/WooCommerce hosting: Server infrastructure — EEA or SCC.

We do not sell, rent, or exchange personal data with any third party for marketing purposes.

6. International Transfers GDPR Art. 44–49

Transfers outside EEA (Stripe, PayPal, Google — USA) are protected via European Commission Standard Contractual Clauses (SCC). Request copies of transfer safeguards: support@silkeon.com.

7. Your Rights GDPR Art. 15–22

  • Access (Art. 15): Copy of all personal data we hold
  • Rectification (Art. 16): Correct inaccurate data
  • Erasure (Art. 17): Deletion within 30 days (except legally required data)
  • Restriction (Art. 18): Pause processing during dispute
  • Portability (Art. 20): Data in machine-readable format (CSV/JSON)
  • Object (Art. 21): Object to legitimate-interest processing or direct marketing
  • Withdraw consent: At any time, without affecting prior lawful processing

To exercise: email support@silkeon.com — “Privacy Request — [request type]”. Response within 30 days (up to 90 for complex). Identity verification may be required.

Complaint authority: Datatilsynet — datatilsynet.no — Tel: 74 07 70 00 — Postboks 458 Sentrum, 0105 Oslo

8. Cookies

Category Purpose Consent Needed Examples
Strictly Necessary Cart, login session, security tokens No — always active woocommerce_cart_hash, PHPSESSID
Preferences Language, display settings Yes woocommerce_recently_viewed
Analytics (Statistics) Google Analytics 4 — anonymous traffic Yes _ga, _ga_XXXXXXXX
Marketing Targeted advertising, retargeting Yes _fbp, _fbc

Manage preferences via the cookie consent banner. Withdrawal of consent removes future cookies; already-set cookies cleared on next visit.

9. Data Security GDPR Art. 32

Measures: HTTPS/TLS encryption; bcrypt password hashing; 2FA for admin; access controls; regular security patching; processor vetting per GDPR Art. 28. Data breach procedure: Datatilsynet notified within 72h; individuals notified without undue delay. GDPR Art. 33–34

10. Children’s Privacy

We do not knowingly collect data from children under 15 without verifiable parental consent. GDPR Art. 8 / Personopplysningsloven §5 Report concerns: support@silkeon.com — deleted promptly.

11. Updates

Material changes communicated by email 14+ days in advance. Last updated date shown at top. Always current at silkeon.com/privacy-policy-gdpr/