Xlaxyronghel

Privacy Policy

Last Updated: January 2025

Understanding our cookie usage. This policy provides detailed information about how we use cookies and similar tracking technologies on our website. We believe in giving you control over your data, which is why we offer granular cookie preferences and explain exactly what each type of cookie does. Your privacy choices matter to us.

Welcome to our comprehensive privacy policy. At Xlaxyronghel, we take your privacy seriously and are committed to protecting your personal information. This detailed policy explains exactly how we collect, use, store, and protect your data in full compliance with GDPR and Norwegian data protection laws. We believe in transparency and want you to understand your rights and how your information is handled. Please take the time to read through this policy carefully.

1. Introduction

Xlaxyronghel ("we," "our," or "us") is committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, store, and protect your personal information when you visit our website at https://xlaxyronghel.world or use our services.

We are the data controller responsible for your personal data. Our registered business address is Nydalsveien 33, 0484 Oslo, Norway. You can contact us at customer@xlaxyronghel.world or by phone at +47 22 89 50 00.

This Privacy Policy complies with the General Data Protection Regulation (GDPR) and applicable Norwegian data protection laws. By using our website and services, you acknowledge that you have read and understood this Privacy Policy.

2. Data We Collect

2.1 Information You Provide Directly

When you place an order or contact us through our website, we collect the following personal information:

  • Contact Information: Full name, email address, phone number, and delivery address
  • Order Information: Product selections, quantities, and any special instructions or messages you provide
  • Communication Data: Any correspondence you send to us via email, phone, or contact forms
  • Payment Information: Payment details necessary to process your order (processed securely through third-party payment processors)

2.2 Information Collected Automatically

When you visit our website, we automatically collect certain technical information:

  • Device Information: IP address, browser type and version, operating system, device type
  • Usage Data: Pages visited, time spent on pages, links clicked, referring website addresses
  • Cookies and Tracking Technologies: Information collected through cookies and similar technologies (see our Cookies Policy for details)
  • Location Data: General geographic location based on IP address

2.3 Information from Third Parties

We may receive information about you from third-party services such as payment processors, delivery services, and analytics providers. This information is used solely to fulfill our contractual obligations and improve our services.

3. Legal Basis for Processing

Under GDPR, we process your personal data based on the following legal grounds:

  • Contractual Necessity: Processing is necessary to fulfill our contract with you when you place an order
  • Consent: You have given explicit consent for specific processing activities, such as marketing communications
  • Legitimate Interests: Processing is necessary for our legitimate business interests, such as fraud prevention, website security, and business analytics, provided these interests do not override your fundamental rights
  • Legal Obligations: Processing is required to comply with legal obligations, such as tax and accounting requirements

4. How We Use Your Data

We use your personal information for the following purposes:

4.1 Order Processing and Fulfillment

  • Processing and fulfilling your orders
  • Communicating with you about your order status
  • Arranging delivery and shipping
  • Processing payments and preventing fraud
  • Handling returns and refunds

4.2 Customer Service

  • Responding to your inquiries and support requests
  • Providing product information and assistance
  • Resolving complaints and disputes
  • Improving our customer service quality

4.3 Website Improvement and Analytics

  • Analyzing website usage patterns and user behavior
  • Improving website functionality and user experience
  • Testing new features and services
  • Conducting market research and statistical analysis

4.4 Marketing and Communications

  • Sending promotional emails about new products and special offers (only with your consent)
  • Personalizing your experience on our website
  • Conducting customer satisfaction surveys

4.5 Legal and Security

  • Complying with legal obligations and regulatory requirements
  • Protecting against fraud, unauthorized access, and security threats
  • Enforcing our terms and conditions
  • Defending legal claims and protecting our rights

5. Data Sharing and Disclosure

We do not sell your personal data to third parties. We may share your information with the following categories of recipients:

5.1 Service Providers

We work with trusted third-party service providers who process data on our behalf:

  • Payment Processors: To securely process your payments
  • Shipping and Delivery Services: To deliver your orders
  • Email Service Providers: To send transactional and marketing emails
  • Web Hosting Providers: To host our website and databases
  • Analytics Providers: To analyze website usage and performance
  • Customer Support Tools: To manage customer inquiries and support tickets

All service providers are contractually obligated to protect your data and use it only for the specified purposes.

5.2 Legal Requirements

We may disclose your personal data if required by law, court order, or governmental authority, or to protect our legal rights, prevent fraud, or ensure the safety of our users.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of assets, your personal data may be transferred to the acquiring entity, subject to the same privacy protections.

6. International Data Transfers

Your personal data is primarily stored and processed within the European Economic Area (EEA). If we transfer data outside the EEA, we ensure appropriate safeguards are in place, such as:

  • Standard Contractual Clauses approved by the European Commission
  • Adequacy decisions confirming the recipient country provides adequate data protection
  • Binding Corporate Rules for transfers within multinational organizations

You have the right to request information about the safeguards we use for international data transfers.

7. Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy:

  • Order and Transaction Data: Retained for 7 years to comply with accounting and tax obligations
  • Customer Account Data: Retained until you request deletion or close your account
  • Marketing Data: Retained until you withdraw consent or unsubscribe
  • Website Analytics Data: Typically retained for 26 months
  • Communication Records: Retained for 3 years for customer service quality and dispute resolution

After the retention period expires, we securely delete or anonymize your personal data. In some cases, we may retain data longer if required by law or to defend legal claims.

8. Your Rights Under GDPR

As a data subject under GDPR, you have the following rights regarding your personal data:

8.1 Right of Access

You have the right to request a copy of the personal data we hold about you, along with information about how we process it.

8.2 Right to Rectification

You can request that we correct any inaccurate or incomplete personal data we hold about you.

8.3 Right to Erasure (Right to be Forgotten)

You can request that we delete your personal data in certain circumstances, such as when it is no longer necessary for the purposes for which it was collected, or if you withdraw consent.

8.4 Right to Restriction of Processing

You can request that we restrict the processing of your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.

8.5 Right to Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format, and to transmit it to another controller.

8.6 Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we have compelling legitimate grounds.

8.7 Right to Withdraw Consent

Where processing is based on consent, you have the right to withdraw your consent at any time. This does not affect the lawfulness of processing before withdrawal.

8.8 Right to Lodge a Complaint

You have the right to lodge a complaint with the Norwegian Data Protection Authority (Datatilsynet) if you believe we have violated your data protection rights. Contact details: Datatilsynet, P.O. Box 458 Sentrum, 0105 Oslo, Norway, or visit www.datatilsynet.no.

8.9 Exercising Your Rights

To exercise any of these rights, please contact us at customer@xlaxyronghel.world or write to us at Nydalsveien 33, 0484 Oslo, Norway. We will respond to your request within 30 days. We may request additional information to verify your identity before processing your request.

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction:

  • Encryption: All data transmitted between your browser and our servers is encrypted using SSL/TLS protocols (HTTPS)
  • Access Controls: Access to personal data is restricted to authorized personnel only, based on the principle of least privilege
  • Secure Storage: Personal data is stored on secure servers with regular security updates and patches
  • Regular Audits: We conduct regular security audits and vulnerability assessments
  • Employee Training: Our staff receives regular training on data protection and security best practices
  • Incident Response: We have procedures in place to detect, respond to, and report data breaches

While we strive to protect your personal data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security but continuously work to improve our security measures.

10. Children's Privacy

Our website and services are not intended for children under the age of 16. We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately, and we will delete such information from our systems.

11. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to enhance your browsing experience and analyze website usage. For detailed information about the cookies we use and how to manage your preferences, please refer to our Cookies Policy.

12. Third-Party Links

Our website may contain links to third-party websites, services, or applications. We are not responsible for the privacy practices of these third parties. We encourage you to review the privacy policies of any third-party sites you visit.

13. Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you. Any automated processing we conduct is limited to basic analytics and does not involve decisions that impact your rights.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or business operations. When we make significant changes, we will notify you by:

  • Posting the updated policy on our website with a new "Last Updated" date
  • Sending an email notification to registered users (for material changes)
  • Displaying a prominent notice on our website

We encourage you to review this Privacy Policy periodically. Your continued use of our website after changes are posted constitutes your acceptance of the updated policy.

15. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or our data processing practices, please contact us:

Xlaxyronghel
Nydalsveien 33
0484 Oslo, Norway
Email: customer@xlaxyronghel.world
Phone: +47 22 89 50 00
Business Hours: Monday to Friday, 9:00-17:00 CET

We are committed to resolving any privacy concerns you may have and will respond to your inquiries as promptly as possible.

16. Data Protection Officer

For matters specifically related to data protection and privacy compliance, you may contact our Data Protection Officer at customer@xlaxyronghel.world with "DPO" in the subject line.

17. Consent and Acknowledgment

By using our website and services, you acknowledge that you have read, understood, and agree to the collection, use, and disclosure of your personal data as described in this Privacy Policy. Where required by law, we will obtain your explicit consent before processing your personal data for specific purposes such as marketing communications.