The General Data Protection Regulation (GDPR) is a comprehensive data protection law that governs how organizations collect, process, and store personal data of individuals within the European Union and European Economic Area. At Nordisk Gardindesign, we are committed to full compliance with GDPR requirements.
Nordisk Gardindesign acts as the data controller for personal information collected through our website and services. As the data controller, we are responsible for determining the purposes and means of processing your personal data.
Contact details:
Nordisk Gardindesign
Storgata 42
0182 Oslo, Norway
Email: [email protected]
The GDPR provides you with specific rights regarding your personal data:
You have the right to request confirmation of whether we process your personal data and, if so, to receive a copy of that data along with information about how it is being processed.
You may request correction of inaccurate personal data or completion of incomplete data we hold about you.
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when the data is no longer necessary for its original purpose.
You may request that we limit the processing of your personal data in specific situations, such as when you contest the accuracy of the data.
You have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You may object to processing of your personal data based on legitimate interests or for direct marketing purposes.
Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing based on consent before its withdrawal.
To exercise any of these rights, please contact us using the details provided above. We will respond to your request within one month. In complex cases, this period may be extended by two additional months, and we will inform you of any such extension.
We process personal data for the following purposes:
Our processing activities are based on:
We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, where feasible. If the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly.
If you believe that your data protection rights have been infringed, you have the right to lodge a complaint with the Norwegian Data Protection Authority:
Datatilsynet
Postboks 458 Sentrum
0105 Oslo
Website: www.datatilsynet.no
We may update this GDPR information page from time to time to reflect changes in our practices or legal requirements. We encourage you to review this page periodically.