Privacy Policy

Welcome to Strawbees Webshop Privacy Policy

Last updated 2024-07-09

This Privacy Notice tells you what Personal Information we collect on shop.strawbees.com, what we do with it, who can access it, and your rights in relation to your Personal Information. This is for our online shop only. For the Strawbees Service Privacy Notice, please click here.

  

Who we are

Strawbees AB is a company incorporated and registered in Sweden. Our registered office is Strawbees AB, Polhemsplatsen 5, 411 11 Göteborg, Sweden.

Strawbees AB processes Personal Information as a Business or Controller, as defined in the CPRA and EU/UK GDPR respectively.

Information you give us

Strawbees AB only collects information on our shop in limited circumstances. When you purchase from our shop, we will collect any information you provide such as:

  • First & last name
  • Email address
  • Job title
  • Country of residence

 

Information we collect from you

When you use our shop’s website, we will collect information about you automatically through cookies. You can reject analytics cookies by clicking ‘Do not sell my personal information’ on the banner when you enter the website. To find out more about the cookies we enable on this website, please find the cookie button on the left hand side of this website then expand the categories to read more. You can adjust your cookie preferences at any time by clicking this button.

How We Share Your Personal Information

We may use your Personal Information for the purposes and on the legal bases below. We may process your Personal Information for more than one lawful ground depending on the specific purpose for using your information.

  • Purchase and payment. 
  • We need to use your Personal Information to process your order. This is to fulfil our contract with you. It may also be necessary for our legitimate interests (to recover debts due to us).
  • Provide your account. We may use your Personal Information to set up your account. This can be used to track your orders. This is to fulfil our contract with you.
  • Support you. If you contact us, we may use your Personal Information to respond to your request and help with your query. This is to fulfil our contract with you. It may also be necessary for our legitimate interests (to gather feedback on our support systems).
  • Analytics. We may use data analytics to improve our website, marketing, and visitor experiences. This is in line with your explicit consent. You can change your cookie settings at any time on the cookies button on our website.
  • Comply with legal obligations. Please note we may process your Personal Information without your knowledge or consent where it is required or permitted by law.

How long we keep your Personal Information

Except as otherwise stated below, we store your Personal Information until we fulfil your purchase or close your support ticket.

We keep support ticket information for 12 months after your ticket is closed so that we can improve our support.

We will keep aggregated analytics data until we deem it no longer necessary for informing our marketing strategy. Your analytics data will not be re-identified.

Please refer to the cookie policy in the ‘Privacy & Cookies Policy’ button for how long your Personal Information is kept for each cookie.

We may need to keep your Personal Information for longer to comply with our legal, regulatory, or reporting obligations, or to resolve complaints and disputes. For example, if you have opted out of marketing communications, we will store your request indefinitely so that we can respect the request in future.

Disclosures of your Personal Information

We will share your Personal Information with Third Party Service Providers where required by law, where you have given explicit permission or where we have another legitimate interest in doing so.

We may use Third Party Service Providers in keeping with the purposes set out in the section How we use your Personal Information and, in particular, to help in the following circumstances:

  • Purchase and payment (including Shopify)
  • Warehouse fulfilment
  • Professional advisory services (including lawyers, bankers, insurers, auditors and accountants who provide legal, banking, insurance, audit and accounting services)

We may share your Personal Information with other entities in our eEducation Albert group as part of our regular reporting activities on company performance, in the context of a business reorganisation or group restructuring exercise, or for system administration. Please see the Strawbees Service privacy notice for more.

Sharing in the Last Twelve (12) Months

In the preceding twelve (12) months, Strawbees has disclosed the following categories of personal information for a business purpose to the following categories of third parties:

  • We have disclosed your personal identifiers to service providers that assist us in providing the Services. These service providers assist us with the following: information technology (“IT”) support; data hosting; customer relationship management; mailing; email delivery; professional services (lawyers, bankers, insurers, auditors, accountants); purchase and payment; error reporting; video/phone system; web analytics; and similar services.
  • We have disclosed your internet or other electronic network activity information collected by cookies to our service providers to detect security incidents, protect against malicious, deceptive, fraudulent, or illegal activity, and to identify and repair the Websites and platform errors.
  • We have disclosed your internet or other electronic network activity information collected by cookies to our cookie management provider.

Third parties are contractually prohibited from using the Personal Information for any other purpose than to provide the service requested by us, for the purposes described in this Privacy Policy. This ensures Third Party Service Providers will provide the same or higher level of protection for your Personal Information. We only permit Third Party Service Providers to process Personal Information for specified purposes and in accordance with our instructions.

Sale of Personal Information

Where targeted advertising is defined as a sale, in the preceding twelve (12) months (assuming you have opted-in), Strawbees has shared your internet or other electronic network activity information collected via cookies and other tracking technologies on both our Educational Content Provision and our Company Website(s) with our data analytics/advertising providers as described in PERSONAL INFORMATION WE COLLECT, WHY AND FOR HOW LONG. To adjust your privacy preferences (opt-in or out), please click the cookie button on the bottom left of our Company Website(s). Please note that advertising and analytics cookies are not deployed behind login walls on our Educational Content Provision.

International Transfers

Your information is stored and processed on the servers of our Service Providers. This will include a transfer of your data to the EU and the UK.

To ensure your Personal Information receives an adequate level of protection, we require our Service Providers to protect it in a way that respects the EU GDPR and the UK GDPR. 

How we keep your Personal Information safe

Our security measures include, but are not limited to, the use of access-controlled data centers, data encryption in transit, brute force controls, firewalls, multi factor authentication for systems, regular staff training and physical access controls.

In addition, we limit access to your personal information to those employees, agents, contractors and other Third Parties who have a business need to know. They will only process your Personal Information on our instructions and they are subject to a duty of confidentiality.

We have put in place procedures to deal with any suspected data security breach and will notify you and any applicable regulator of a suspected breach where we are legally required to do so..

We do not process children’s data on the Strawbees shop website. This website is not intended for children.

Your Rights - United States

CALIFORNIA

The California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act (collectively, “CPRA”) entitles California residents to certain rights. To the extent the CPRA applies to our processing of your personal information, you are entitled to the following rights:

  • Right to Access/Know. You have the right to request what personal information we have collected, used, disclosed, and sold about you, unless doing so proves impossible or would involve disproportionate effort. You may only make a request for access twice within a 12-month period.
  • Right to Deletion. You have the right to request the deletion of your personal information that we collect or maintain, subject to certain exceptions. For example, if we are required by law to retain the information that you are asking to be deleted, we would not be able to delete the information until we are legally permitted to delete it.
  • Right to Correct. You have the right to correct inaccurate personal information that we collect or maintain.
  • Right to Opt Out of Sale/Sharing. You have the right to opt out of the sale or sharing of your personal information to third parties.
  • Right to Non-Discrimination. You have the right to not receive discriminatory treatment if and when you exercise your privacy rights under the CPRA.
  • Right to Limit Use of Sensitive Personal Information. You have the right to limit the use of your sensitive personal information when such use goes beyond that which is necessary for providing the Services or certain other permissible purposes like fraud, customer service or quality control. Sensitive information includes Social Security number, driver’s license number, biometric information, precise geolocation, and racial and ethnic origin. However, Strawbees does not process sensitive personal information in a manner which gives rise to this right.

If you are a California resident and wish to exercise your privacy rights, you may submit a request to our Data Protection Officer via email at privacy@strawbees.com. Please indicate your state of residence upon submission of your request. You may opt in or out of non-essential cookies at any time by using the toggles in Your Privacy Rights.

For requests submitted via telephone, you must provide us with sufficient information that allows us to reasonably verify you are the person about whom we collected the personal information and describe your request with sufficient detail to allow us to properly evaluate and respond to it. In doing so, we will take steps to verify your request by matching information provided by you with the information we have in our records. If we are not able to verify your identity for access and deletion requests with the information provided, we may ask you for additional pieces of information. We will ask you for your school name, school zip code, and your role.

Only you, or a person that you authorize to act on your behalf may make a request related to your personal information. If you are an authorized agent making a request on behalf of another individual, you must provide us with signed documentation that you are authorized to act on behalf of that individual.

We will try to act on your request within one month or quicker if local law requires. You will be notified of receipt of your request within 10 days. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

COLORADO, CONNECTICUT, DELAWARE, INDIANA, IOWA, KENTUCKY, MARYLAND, MINNESTOTA, MONTANA, NEBRASKA, NEW HAMPSHIRE, NEW JERSEY, OREGON, RHODE ISLAND, TENNESSEE, TEXAS, VIRGINIA

If you are a resident in one of the States above, you may have the same rights as those listed for California. Please refer to the section above and include “Privacy Request Under [your State here] Law” in the subject line and body of your message.

UTAH

If you are a resident in the State of Utah, you have the right to opt out of the processing of sensitive personal information. We do not currently process sensitive personal information, nor do we plan to do so in the future. Please contact us at privacy@strawbees.com if you have any questions.

NEVADA

If you are a consumer in the State of Nevada, you may request to opt-out of the current or future sale of certain of your personal information. We do not currently sell any of your personal information under Nevada law, nor do we plan to do so in the future. However, you can submit a request to opt-out of future sales, as defined by Nevada law, by contacting us at privacy@strawbees.com. Please include “Opt-Out Request Under Nevada Law” in the subject line and body of your message.

Your rights - UK and EU

It is important that the Personal Information we hold about you is accurate and current. Please keep us informed if your Personal Information changes during your relationship with us.

Where the UK GDPR or the EU GDPR applies, by law you have the right to:

  • Request access to your Personal Information. This enables you to receive a copy of the Personal Information we hold about you and to check that we are lawfully processing it.
  • Request correction of the Personal Information that we hold about you. This enables you to have any incomplete or inaccurate information we hold about you corrected, though we may need to verify the accuracy of the new data you provide to us.
  • Request erasure of your Personal Information. This enables you to ask us to delete or remove Personal Information where there is no good reason for us continuing to process it. You also have the right to ask us to delete or remove your Personal Information where you have successfully exercised your right to object to processing (see below), where we have processed your information unlawfully or where we are required to erase your Personal Information to comply with law. Note, however, that we may not always be able to comply with your request for erasure for specific legal reasons which will be notified to you, if applicable, at the time of your request.
  • Object to processing of your Personal Information where we are relying on a legitimate interest (or those of a Third Party) and there is something about your particular situation which makes you want to object to processing on this ground. You also have the right to object where we are processing your Personal Information for direct marketing purposes. In some cases, we may demonstrate that we have compelling legitimate grounds to process your information which override your rights and freedoms.
  • Request the restriction of your Personal Information. This enables you to ask us to suspend the processing of Personal Information about you, (i) if you want us to establish its accuracy or (ii) where our use of the data is unlawful but you do not want us to erase it, (iii) where you need us to hold the data even if we no longer require it as you need to establish, exercise or defend legal claims or (iv) you have objected to our use of your data but we need to verify whether we have overriding legitimate grounds to use it.
  • Request the transfer of your Personal Information to you or another party. Note that this right only applies to automated information which you initially provided consent for us to use or where we used the information to perform a contract with you.
  • In the limited circumstances where you may have provided your consent to the collection, processing and transfer of your Personal Information for a specific purpose (such as electronic marketing or photographs), you have the right to withdraw your consent for that specific processing at any time. We will then no longer process your information for the purpose(s) you originally agreed to, unless we have another legitimate basis for doing so.
  • Right to lodge a complaint about how we handle your Personal Information with IMY (Sweden EU) or the ICO (UK).

If you want to exercise any of these rights, please contact the Strawbees Data Protection Officer in writing, see ‘How to Contact Us’ below. We will try to act on your request within one month. Occasionally it could take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

We may need to request specific information from you to help us confirm your identity and ensure your right to access the information (or to exercise any of your other rights). This is another appropriate security measure to ensure that Personal Information is not disclosed unlawfully.

We will only require a fee if your request is clearly unfounded, repetitive or excessive. Strawbees AB reserves the right to refuse to comply with your request in these circumstances.

Do Not Track

Please note, we do not respond to Do Not Track requests. Do Not Track is a preference you can set in your web browser to inform websites and mobile applications that you do not want to be tracked. You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.

Updating this Privacy Notice

We may change this Privacy Policy from time to time. We will use reasonable means to notify you about the processing of your Personal Information if there are substantial changes.

How to contact us

If you have any query regarding this Privacy Notice or your Personal Information, please e-mail our Data Protection Officer at privacy@strawbees.com. Alternatively, please write to C/O Data Protection Officer, Strawbees AB, Polhemsplatsen 5, 411 11 Göteborg, Sweden.