Privacy Policy (Personvernerklæring) — Silkeon
Last Updated: June 2026 | Org. nr: [ORG-NUMBER] | GDPR & Personopplysningsloven (LOV-2018-06-15-38) compliant
1. Data Controller (Behandlingsansvarlig)
Silkeon (Org. nr: [ORG-NUMBER]), Lægdesvingen 5096 Bergen, Norway is the data controller. GDPR Art. 4(7) Contact: support@silkeon.com | +47 929 29 552. Silkeon does not have a mandatory obligation to appoint a DPO (not a public authority, no large-scale systematic monitoring). For all privacy matters: support@silkeon.com.
2. Data We Collect
- Identity: Full name
- Contact: Email, phone, postal address (delivery)
- Transactional: Products ordered, amounts, order history, payment method type (not card numbers)
- Account: Username, hashed password (never plain text)
- Technical: IP address, browser, device, OS, session data
- Usage: Pages viewed, products viewed, search terms, referral source
- Communications: Content of support emails/messages
- Marketing: Email consent status (opt-in/opt-out)
We do NOT collect: card numbers (payment provider processes directly), special category data (health, religion, ethnicity, biometrics), or data from children under 15 without parental consent.
3. Legal Basis for Processing GDPR Art. 6
| Purpose | Legal Basis | Article |
|---|---|---|
| Order processing & fulfillment | Contract performance | Art. 6(1)(b) |
| Product delivery | Contract performance | Art. 6(1)(b) |
| Customer account management | Contract performance | Art. 6(1)(b) |
| Returns and refunds | Contract / Legal obligation | Art. 6(1)(b)/(c) |
| Accounting records (7 years) | Legal obligation (Bokføringsloven §13) | Art. 6(1)(c) |
| Consumer rights compliance | Legal obligation (Angrerettloven) | Art. 6(1)(c) |
| Fraud detection & prevention | Legitimate interests | Art. 6(1)(f) |
| Website analytics | Legitimate interests / Consent | Art. 6(1)(f)/(a) |
| Marketing emails | Consent (Markedsføringsloven §15) | Art. 6(1)(a) |
| Non-essential cookies | Consent | Art. 6(1)(a) |
4. Data Retention
| Data Type | Retention Period | Basis |
|---|---|---|
| Order & accounting records | 7 years after transaction | Bokføringsloven §13 |
| Customer account — active | Duration of account | Contract |
| Customer account — inactive | 3 years after last login | Legitimate interest |
| Email consent & marketing records | Until unsubscribed + 2 years | GDPR Art. 7(1) |
| Analytics cookies | Maximum 13 months | Consent |
| Support communications | 3 years | Legitimate interest |
| Server/security logs | 90 days | Legitimate interest |
5. Third-Party Processors GDPR Art. 28
- Stripe Inc. (USA): Payments — EU Standard Contractual Clauses (SCC). PCI-DSS Level 1.
- PayPal Holdings (USA): Payments — SCC. GDPR self-certified.
- Vipps MobilePay AS (Norway): Payments — Norwegian entity, Norwegian data protection law.
- Klarna AB (Sweden): Pay Later — EEA entity, GDPR compliant.
- Google LLC (USA) — GA4: Analytics — IP anonymised, SCC. Used for website improvement.
- Shipping carriers (Posten/Bring/DHL): Name + delivery address for fulfillment only.
- WordPress/WooCommerce hosting: Server infrastructure — EEA or SCC.
We do not sell, rent, or exchange personal data with any third party for marketing purposes.
6. International Transfers GDPR Art. 44–49
Transfers outside EEA (Stripe, PayPal, Google — USA) are protected via European Commission Standard Contractual Clauses (SCC). Request copies of transfer safeguards: support@silkeon.com.
7. Your Rights GDPR Art. 15–22
- Access (Art. 15): Copy of all personal data we hold
- Rectification (Art. 16): Correct inaccurate data
- Erasure (Art. 17): Deletion within 30 days (except legally required data)
- Restriction (Art. 18): Pause processing during dispute
- Portability (Art. 20): Data in machine-readable format (CSV/JSON)
- Object (Art. 21): Object to legitimate-interest processing or direct marketing
- Withdraw consent: At any time, without affecting prior lawful processing
To exercise: email support@silkeon.com — “Privacy Request — [request type]”. Response within 30 days (up to 90 for complex). Identity verification may be required.
Complaint authority: Datatilsynet — datatilsynet.no — Tel: 74 07 70 00 — Postboks 458 Sentrum, 0105 Oslo
8. Cookies
| Category | Purpose | Consent Needed | Examples |
|---|---|---|---|
| Strictly Necessary | Cart, login session, security tokens | No — always active | woocommerce_cart_hash, PHPSESSID |
| Preferences | Language, display settings | Yes | woocommerce_recently_viewed |
| Analytics (Statistics) | Google Analytics 4 — anonymous traffic | Yes | _ga, _ga_XXXXXXXX |
| Marketing | Targeted advertising, retargeting | Yes | _fbp, _fbc |
Manage preferences via the cookie consent banner. Withdrawal of consent removes future cookies; already-set cookies cleared on next visit.
9. Data Security GDPR Art. 32
Measures: HTTPS/TLS encryption; bcrypt password hashing; 2FA for admin; access controls; regular security patching; processor vetting per GDPR Art. 28. Data breach procedure: Datatilsynet notified within 72h; individuals notified without undue delay. GDPR Art. 33–34
10. Children’s Privacy
We do not knowingly collect data from children under 15 without verifiable parental consent. GDPR Art. 8 / Personopplysningsloven §5 Report concerns: support@silkeon.com — deleted promptly.
11. Updates
Material changes communicated by email 14+ days in advance. Last updated date shown at top. Always current at silkeon.com/privacy-policy-gdpr/
