Privacy Policy

10 May 2018 (updated 31 August 2022)

This is the Maya Delorez AB Privacy Policy. The company is identified herein as ‘Maya Delorez,’ ‘we,’ ‘our,’ and ‘us.’ This privacy policy presents company compliance activities relating to the General Data Protection Regulation (GDPR).
We are concerned about your privacy and want you to feel confident in our processing of your personal data. This privacy policy under the GDPR covers the personal data we collect through our operations. This refers to data collected in relation to our products or services, and from other interactions you have with us where we link to or otherwise appropriately refer to incorporating this policy. The policy is designed to help you understand the type of personal data we collect and how we process and use that information. The policy also describes your rights and how you can assert these.

What is personal data?

Personal data is any information that directly or indirectly can relate to a living, identifiable person. The GDPR also applies to digital information such as IP address, Geolocation, certain metadata, images, registration numbers, and more. The law is defined broadly to protect you and your data.

Data quality and retention

Maya Delorez has implemented measures to keep the personal data we hold correct and current. We also implement measures to delete outdated, or otherwise incorrect or unnecessary personal data. Some of our products and services enable you to manage your profile and data in that profile. We encourage you to keep your profile updated to ensure that your personal data is correct and current. Remember that in the types of digital services for which you can manage your profile, you are responsible to provide us correct information and to keep the personal data you have submitted to us current. We store your personal data only as long as necessary for the current purpose or as long as required to comply with applicable regulation.

Sharing your data

'Maya Delorez,’ referencing Maya Delorez AB, is the data controller. We may collect and share your information within our group when necessary to complete our contractual obligations with you or when it is within the correct field. When we provide information about you to a third party (as with any of our partners, transport businesses, customer service providers, accountants or similar) they are our personal data processors. Their processing of your personal data is contractually regulated to protect you. In accordance with this policy, you shall understand and consent to having your personal data collected and processed by and for one or more Maya Delorez group companies. We do not use collected data for any purpose or in any field other than that originally stated. Therefore, we collect information when you contact us and that data is used solely within our company and group.

Sharing your information outside the EU/EEA

We share your data with third-party businesses outside the EU/EEA and have ensured security levels compliant with GDPR regulatory requirements. The data is shared in software we need to use in providing our services to customers and visitors.

Mergers and acquisitions

If we determine to sell, acquire, merge, or otherwise restructure our company in certain countries, this may result in our disclosing personal data to potential or actual buyers and their advisers, or that we receive personal data from sellers or their advisors in relation to such transaction.

When do we process your personal data
  • When you visit our website and when developing our website.

  • When you make a purchase.

  • When we conduct marketing or advertising activities.

  • When we send newsletters or text-based marketing.

  • When you contact customer service.

  • When you register for our loyalty program MD VIP Community. 

  • When you interact with us on social media or share your posts on social media.

  • When you post a product review.

  • When you participate in a contest.

  • When we develop our products and services.

  • In order to comply with accounting and reporting legislation.

  • When you are in contact with company representatives.

  • When you are in contact with us at any event.

When we process your personal data, we may ask you for other information about you or to use in identifying you or verify users and their documents, or information as may be needed to provide the products and services you have requested or to communicate with you. We may also process and use your personal data to ensure the functionality and safety of our products and services, and to prevent or detect fraud and other irregularities.

We may also collect other information that you provide, such as your consent, preferences, and feedback. This may also include information about your devices and such other information you provide. Note that some non-identifiable data that is collected from you may be personally identifiable when you submit your personal data to us. Some of our services may also allow you to send information about other individuals, such as when you order a product you want us to send directly to someone else.

Legal grounds - Consent

Any legally mandatory consent you provide to us for processing your personal data as described herein will be obtained using an appropriate method. This can be a checkbox that indicates your consent when filled in, selecting technical settings for a service or website, or other statement or behavior that clearly indicates that you accept data processing depending on the product, website, service, or software you use.

Legal grounds - Legitimate interest

In certain circumstances Maya Delorez will process your personal data based on our legitimate interest. This means we conduct a balancing of interests to determine that our legitimate interests for processing your personal data are greater than your basic right to not have your personal data processed.

Data obtained from a third party

In addition to personal data that we obtain from you, we may obtain certain personal data from list rental companies and other publicly available sources. This may include personal data such as credit information and updated addresses.

The purpose of processing

Maya Delorez processes your personal data for the purposes described in this policy and/or other service-specific confidential data. Note that one or more purposes may apply simultaneously.

What personal data do we collect and how do we process these?
When you visit our website and when developing our website

When you visit our website, we collect data from you such as metadata and IP address, and we profile you against information you have presented in your social media. Normally, you can visit our websites without needing to identify yourself. However, we collect certain technical data as standard procedure since we use cookies. Read more in the section on ‘Use of cookies and web beacons.’ We collect data from your device when you use our services in order to analyze how our website is used and thereby improve the site, our products, and our services. All for the purpose of improving user friendliness. We also display personalized marketing for you based on this analysis.

The personal data processing we perform

We use analysis software and pixels to improve our website and our products. Read more in the section ‘Use of cookies and web beacons.’ The data collected includes the personal data listed below along with technical data your browser provides us, or that may be collected in relation to certain products and services. The collected personal data is used to optimize our website so we can provide you and other visitors a positive user experience.

Personal data that is processed
  • IP address. *

  • Access time

  • The website you were linked from.

  • Pages you visited.

  • Links you use.

  • Advertisements and other content you interacted with.

  • Information regarding your devices.

  • Location settings

  • Demographic information such as age, gender, language preferences.

*We have taken measures to protect your privacy that prevent identifying you when you visit our website. We therefore store only an encrypted version of your IP address.

Legal grounds for processing personal data

We process your personal data based solely on your consent. You can revoke your consent at any time and you can also prevent Google Analytics from using your personal data by downloading and installing the following browser add-on. https://tools.google.com

Storage period

We maintain your personal data for a period of 26 months.

When you make a purchase
The personal data processing we perform

When you complete a purchase from us, we collect or request personal data relating to your purchase. Such personal data processing is necessary for us to administer your purchase as we need the information to send your order and delivery confirmations, deliver the product you purchased, process payment, and when necessary, process any claims or warranty issues. We also collect data when you contact our customer service regarding the purchase.

Personal data that is processed
  • First and last names.

  • Address.

  • E-mail address.

  • Phone number.

  • Payment information.

  • Purchase information, such as products ordered or whether the product shall be delivered to a different address.

  • Purchasing history.

  • Order number.

  • Membership number.

  • IP address. *

  • User data for ‘My account.’

  • Details regarding the agreement between you and Maya Delorez.

  • Other information about your purchase.

*We have taken measures to protect your privacy that prevent identifying you when you visit our website. We therefore store only an encrypted version of your IP address.

Legal grounds for processing personal data

This personal data processing is necessary so we can fulfill our obligations under the purchase agreement.

Storage period

After your purchase, we store your data for seven (7) years to comply with applicable accounting law in Sweden.

When we conduct marketing or advertising activities

We may process and use your personal data for marketing purposes when presenting offers and personalized marketing which we believe may be interesting for you. Marketing purposes may involve our using your personal data for direct and targeted marketing or to conduct market research. We may also communicate our products, services, or campaigns, either through our own or third-party digital services or otherwise. Some of our products and services may also be used in marketing for products and services of other companies. However, Maya Delorez will not provide your personal data to these companies for marketing purposes without your prior consent.

Profiling and personalization

We may also process and use your personal data for profiling and personalization for such purposes as targeted marketing and improving our products or services. We may also create aggregated and statistical information based on your personal data. Profiling and personalization involve automatic processing of your personal data to assess, analyze or predict your personal preferences or interests in order to send marketing announcements on products and services that are most appropriate for you.

The personal data processing we perform
  • Personalization of product recommendations.

  • Personalized advertising from third-party services. Google, Google Search Partners, Facebook, Instagram, Snapchat, Tiktok, Youtube, Pinterest, Bing.

  • Personalized retargeted advertising from third-party services. Google, Google Search Partners, Facebook, Instagram, Snapchat, Tiktok, Youtube, Pinterest, Bing.

  • Reminders of a forgotten digital shopping cart.

  • Direct or targeted marketing by email, text, or social media.

Personal data that is processed
  • First and last names.

  • IP address. *

  • Address.

  • E-mail address.

  • Phone number.

  • Demographic information.

  • Transaction data.

  • Storing and retrieving information using cookies.

*We have taken measures to protect your privacy that prevent identifying you when you visit our website. We therefore store only an encrypted version of your IP address.

Legal grounds for processing personal data

Legitimate interest. Processing is necessary to enable us to offer relevant marketing of our products and services.

Storage period

We maintain your personal data for a period of 18 months. At any time, you may change your settings for what marketing you see. You do this at the appropriate third-party service. You can update your preferences at each of our third-party providers using the links below.

Google: https://support.google.com

Facebook: https://www.facebook.com/help

Instagram: https://help.instagram.com

Snapchat: https://support.snapchat.com

TikTok: https://support.tiktok.com

Youtube: https://support.google.com/youtube

Pinterest: https://help.pinterest.com

Bing: https://privacy.microsoft.com

When we send newsletters or text-based marketing
The personal data processing we perform

When you subscribe to our newsletter and text-based marketing services, you will receive email notices and text messages with inspiration, offers, and personal recommendations. We use your purchasing and surfing history with information on the products you are interested in to personalize our offerings to you. To enable improving and developing our newsletter, we also analyze your use of our newsletter and collect data about how you opened the newsletters and the links in the newsletters that you clicked on.

Personal data that is processed
  • First and last names.

  • Address.

  • E-mail address.

  • Phone number.

  • Information relating to your use of newsletters.

Legal grounds for processing personal data

Processing is necessary to enable us to offer relevant marketing of our products and services. Personal data processing is done with your consent and you can revoke that consent at any time.

Storage period

You can terminate your subscription to our newsletter by following the instructions in the email message. This normally means using the ‘Cancel subscription’ link at the end of the message. Click the link to cancel your subscription, or contact the appropriate brand or group company specified in the email message or on their website. If you deregister in this way, we may still send email messages that are not marketing, such as service notifications or business related information to business customers.

You can deregister from receiving text-based marketing messages from us by using the link at the end of the message. By clicking the link, you can remove your phone number and opt out of receiving future text messages from us.

When you contact customer service
The personal data processing we perform

When you contact customer service, we collect your personal data so we can provide customer service, and to allow us to identify you as a customer, answer your questions, and investigate your claims. We also collect information to allow us to track your order and process any claims issues.

Personal data that is processed
  • First and last names.

  • E-mail address.

  • Address.

  • Phone number.

  • Data regarding purchases and purchase history.

  • Technical data such as language settings and IP address.

Legal grounds for processing personal data

Processing your personal data is necessary to ensure your legitimate interests by providing customer service.

Storage period

We save your personal data until you ask us to delete it.

When you register for our loyalty program MD VIP Community 
What personal data do we collect and how do we process these? 

When you register as a member in the MD VIP Community, we collect or request personal data related to your membership. This personal data processing is necessary for us to manage your membership and, based on your personal data and purchase and order history, to customize your membership level, benefits and personal offers sent to you. 

When you register as a member in the MD VIP Community, you will receive a personal login where you will be able to view:  

  • Your purchase and order history  

  • Your account information  

  • Your membership level and benefits  

  • Your personal offers and vouchers  

The personal data processing we perform 

We process your personal data in order to analyze and combine information from your order and purchase history, as well as other information you have provided, in order to customize your membership level, benefits and personal offers to you.

Personal data that is processed 
  • First and last name 

  • E-Mail address 

  • Phone number 

  • Address 

  • Date of birth 

  • Membership number 

  • Details of the contract between you and Maya Delorez 

Legal grounds for processing personal data 

This processing of personal data is necessary to enable you to register your membership in the MD VIP Community. The processing of personal data is done with your consent and you can withdraw your consent at any time. 

Storage period 

Your personal data is stored until you choose to terminate your membership. Maya Delorez reserves the right to terminate your membership if it has been inactive or if your last registered purchase took place more than 24 months ago. Maya Delorez also reserves the right to terminate your membership if you do not comply with the agreed conditions. 

When you interact with us on social media or share your posts on social media
The personal data processing we perform

We communicate with you and we share the posts and images you have tagged us in or that you have sent to us on our social media.

Personal data that is processed

Information from your profile and your posts.

Legal grounds for processing personal data

Personal data processing is done with consent and you can revoke that consent at any time.

Storage period

Your posts and comments will be displayed on our social media until we choose to delete them or you ask us to do so.

When you post a product review
The personal data processing we perform

After you complete a purchase, we send an email notification to you asking for a review of the product or products you bought. We then publish your review on our website. You can also volunteer a review on any of our other channels.

Personal data that is processed
  • First and last names.

  • E-mail address.

  • Information relating to your review.

  • Profile on social media.

Legal grounds for processing personal data

We publish your review based solely on your consent. You provide consent by submitting the product review and you can revoke that consent at any time by asking us to delete that review.

Storage period

Information relating to your review will be displayed until we choose to delete it or you ask us to do so.

When you participate in a contest
The personal data processing we perform

We use your personal data to administer participation in any contest following the rules for that specific contest. We may also use information to identify contest participants and to communicate with these participants before and after the contest, and to award winners and deliver their prize.

Personal data that is processed
  • Contact data that you use to participate in the contest. This includes social media profiles, first and last names, email address, and phone number.

  • Information about your contest entry.

  • Contact data to enable contacting the contest winner and to send the prize to them. This includes first and last names, address, and phone number.

Legal grounds for processing personal data

We process your personal data to ensure your and our legitimate interests in participating in our contest.

Storage period

Information relating to your contest participation will be displayed until we choose to delete it or you ask us to do so.

When we develop our products and services

We may process and use your personal data to develop our products and/or services. But we mostly use aggregated and statistical data in developing our products and services, not data that is directly identifiable to you. We can combine personal data collected during your use of a specific Maya Delorez product and/or service with other personal data we may have about you, except when such personal data was collected for other purposes.

In order to comply with accounting and reporting legislation
The personal data processing we perform

We collect and save personal data for accounting and reporting purposes.

Personal data that is processed
  • First and last names.

  • Payment history

  • Information providing a basis for reporting.

Legal grounds for processing personal data

Processing your personal data is necessary to enable us to follow the obligations we operate under for accounting and reporting legislations.

Storage period

Accounting and reporting documentation and related personal data are stored for a period of seven (7) years to comply with applicable Swedish accounting legislation.

Who will we share your personal data with?
Transferring personal data

We may submit your personal data to third parties exclusively as stated in this policy or applicable mandatory legislation.

Service providers and other authorized third-party providers

We may transfer personal data to third parties who are authorized to process personal data on assignment from Maya Delorez for the purposes described in this policy. This includes technology, logistics, e-commerce, marketing, and other services. These parties do not have the right to use your personal data for other purposes than those for which your personal data was first collected. We require that they act consistently to comply with applicable laws and this policy, and that they use suitable security measures to protect your data.

Our products or services may also include links to other companies’ websites, and to other third-party services that have their own privacy policies. We are not responsible for confidentiality practice and content at these third-party services and we therefore recommend that you closely consider their privacy policies.

The list below identifies third-party providers with which our database and its contents are shared.

Google: https://policies.google.com/privacy

Facebook: https://www.facebook.com/privacy/policy

Instagram: https://privacycenter.instagram.com/policy

Youtube: https://policies.google.com/privacy

Snapchat: https://snap.com/privacy/privacy-policy

Bing: https://privacy.microsoft.com/privacystatement

TikTok: https://www.tiktok.com/legal/privacy-policy

Klarna: https://klarna.com/privacy

Adyen: https://www.adyen.com/policies-and-disclaimer/privacy-policy

Yotpo: https://www.yotpo.com/privacy-policy/

Ingrid: https://www.ingrid.com/privacy-policy

Voyado: https://voyado.com/privacy-policy/

International transfers

Our products and services may be provided using resources and servers located in various countries around the world. Therefore, your personal data may be transferred outside the country where you use our services, including countries beyond the European Economic Area (EEA) where the level of protection may not be seen as appropriate according to the European Commission. In such cases, we take measures to ensure adequate protection of your personal data in accordance with current legal requirements. In executing international personal data transfers, we generally rely on terms based on the standard contractual clauses issued by the European Commission.

Other information

We may transfer or otherwise process your personal data in accordance with applicable legal regulations to defend legitimate interests of Maya Delorez, as with civil or criminal litigation.

Data regarding minors

Regarding legal minors (according to laws in each country), Maya Delorez attempts to refrain from collecting any data or involving them in transactions. Our databases may, however, contain personal data for children since it is not always possible to determine a user's age. We retain the right to block the service from anyone who we reasonably suspect is or is a minor. Our policy is to request that minors do not initiate purchases of our products or services or engage in other legal acts relating thereto without the consent of their legal guardian unless otherwise permitted by applicable law. If you are a minor and have your guardian's consent, you must be able to provide evidence thereof on request.

Data security

Maya Delorez conducts appropriate technical and organizational security measures to prevent and minimize the risks related to providing and processing personal data. These security measures include, as necessary, the use of firewalls, secure server facilities, encryption, implementing correct systems and processes for managing access rights, careful selection of processors, training staff who conduct the processing, and other necessary measures to provide appropriate protection for your personal data against unauthorized use or disclosure. We also maintain backup copies as necessary and use other means to prevent unintentional harm to or destruction of your personal data. Where any part of a Maya Delorez website supports online transactions, we use industry-standard security measures, such as those available through Secure Sockets Layer (SSL) to protect confidentiality and security in online transactions.

Use of cookies and web beacons

Maya Delorez uses cookies, web beacons (pixel tags) and other tracking technology with our websites for the following purposes: web statistics, sales and advertisement, user experience, and functionality. Through this policy, you confirm you approve the storage of cookies, and other local storage technologies, web beacons, and other information about your devices, and to accessing such cookies, and local storage technologies, web beacons, and other information by us and our partners.

What are cookies?

Cookies are small data files placed on your computer hard disc which contain information about the parts of our website you visit. The term ‘cookies’ may also include other technical solutions. Cookies are reliable files and may not consist of software code, transfer viruses, or be used to collect information about what you use your computer for. Some of our business partners whose content is linked to or by our website may also use cookies. However, we do not have access to or control of these.

What are web beacons?

Web beacons (pixel tags/ pixels) are typically graphic images located on a website. They are used to count the visitors to a site and/or to access certain cookies. Web beacons normally do not collect any other information than what your browser provides to us as is standard in any Internet communication and we do not use web beacons to identify individual users. If you opt out of using cookies, the web beacon will no longer be able to track your specific activity. The web beacon may, however, continue to collect information on visits from your IP address, but that information will no longer be personally identifiable.

How can I opt out of using cookies?

If you want to inactivate cookies or to be informed before these are installed, you can specify this in your browser settings. Read more information on how to manage cookies here. https://www.aboutcookies.org/. Note that we may not be able to provide certain services or you may not be able to display some sections of the website after having deactivated cookies. Read more information about how you managed cookies in each browser at the links below.

Google Chrome: https://google.com/chrome

Safari (Iphone): https://support.apple.com

Safari (Mac): https://support.apple.com

Mozilla Firefox: https://support.mozilla.org

Samsung Internet (Mobile): https://samsung.com

Microsoft Edge: https://support.microsoft.com

Internet Explorer: https://support.microsoft.com

Opera: https://help.opera.com

Your rights
Right to information

In this policy, we provide you with information about how we function under the provisions of the GDPR.

Right to access

You have the right to request your information and access the personal data that we have collected from and about you. You also have the right to request and receive personal data that we have collected about you, which we will provide in a commonly used electronic format.

Right to rectification

You have the right to request that we supplement or rectify incomplete or incorrect personal data.

Right to delete and restrict processing

You have the right to request that we anonymize or delete incomplete, incorrect, unnecessary, or out-of-date personal data we have about you. However, we cannot delete personal data that is necessary to comply with mandatory legal obligations or if the personal data shall be kept under applicable law.

If you believe a) your personal data that we collected is incorrect; b) you do not want your personal data to be deleted where processing of these is deemed illegal or they are no longer necessary; or c) if you have objected to the processing and presence of legitimate grounds for the processing is still under consideration, you may request that processing your personal data be restricted. You may, at any time, also object to your personal data being used for direct marketing, distribution of advertising material, profiling, or for market surveys. Additionally, where your personal data is processed based on your consent, you have the right to revoke your consent to such processing at any time.

If you want to exercise your rights as presented above you may, under applicable law, do so by contacting us using the points of contact specified in the marketing material or as below in this policy. In certain cases, especially if you want us to delete or block processing of your personal data, this may also mean that we may not be able to continue providing our services to you. We encourage you to use the tools available for managing profiles for the above purpose since these tools often allow you immediate access to your personal data and enable efficient management.

Note that we may need to identify you and ask for additional information to be able to comply with your requests as above. Also note that applicable law may include limitations and other provisions that apply to your rights outlined above.

Right to raise objections

You have the right to object to processing of your personal data. You may, at any time, object to our processing and we must then inform you that there are legitimate reasons for our processing.

Right to data portability

You have the right to obtain and use your personal data for a different data controller of personal data, as for example to transfer your data between social media services. For this, we are obligated to facilitate such a transfer of your personal data.

Complaints to supervisory authorities

If you believe that the processing Maya Delorez performs regarding your personal data is inconsistent with applicable data protection legislation or that Maya Delorez has not sufficiently secured your rights, you may complain to the local supervisory authority responsible for data protection.

Controller of your personal data and contractual clauses

The controller(s) responsible for processing your personal data are:

Maya Delorez AB

Corporate registration number: 559141-7620

Sidenvävargatan 11

753 19 Uppsala

and/or,

Maya Delorez group companies whose websites, software, products or services you use. Name and registered address are available during the purchasing or registration process.

and/or,

Maya Delorez group companies that use your personal data for direct marketing or similar purposes. Name and registered address are available in the marketing material you received.

Contact details

If you have questions regarding our processing of your personal data or want to exercise any of your rights as provided in applicable personal data protection legislation, contact us at privacy@mayadelorez.com or use our postal address below.

Maya Delorez AB

Att: Privacy

Sidenvävargatan 11

753 19 Uppsala

Changes to this privacy policy

We will update this privacy policy whenever we change our personal data processing procedures. We will also publish the latest version of this policy on our website.