This Privacy Policy ("Policy") outlines how NordXSwiss GmbH ("We," "Our," or "Us") collects, uses, discloses, and manages personal information provided by users ("You" or "Your") who visit and use our shop (Fresh Ideas Lab) on the Etsy platform.
This Privacy Policy does not apply to the practices of third parties that we do not own or control, including Etsy or any third party services you access through Etsy.
1. Legal Basis for Processing
We will only process your personal data when we have a valid legal basis for doing so under Article 6 of the GDPR:
• Contract Performance (Art. 6(1)(b)): Processing necessary to fulfill our contract with you, including order processing, delivery, and customer support.
• Legal Obligation (Art. 6(1)(c)): Processing required to comply with legal obligations, such as tax reporting, accounting requirements, and regulatory compliance.
• Legitimate Interest (Art. 6(1)(f)): Processing for our legitimate business interests, including improving our services, fraud prevention, and security measures, provided these interests do not override your fundamental rights and freedoms.
• Consent (Art. 6(1)(a)): For marketing communications and optional services, we will seek your explicit consent.
2. Information We Collect
We may collect and process the following information:
• Personal Information: This may include your name, email address, postal address, phone number, and other relevant contact details.
• Order Information: Information about the products you purchase, including product details, pricing, shipping information, and order history.
• Payment Information: Information related to your payment methods, such as credit card details or other financial information (processed securely through third-party payment processors).
• Communication Data: Correspondence between you and us, including emails, messages on the Etsy platform, and customer support interactions.
• Usage Data: Information about how you use our shop, including pages visited, time spent on each page, referral source, and browsing behavior.
• Technical Data: IP address, browser type, device information, and operating system.
3. How We Use Your Information
We use the information we collect for the following purposes:
• To process and fulfill your orders.
• To communicate with you regarding your orders, inquiries, and to provide customer support.
• To improve and optimize our shop, products, and user experience.
• To comply with legal obligations, such as tax reporting requirements and regulatory compliance.
• To send marketing materials and updates (only with your explicit consent).
• To prevent fraud and ensure the security of our services.
• To analyze usage patterns and improve our business operations.
4. Information Sharing and Disclosure
We may share your personal information in the following circumstances:
• Etsy Platform: We share information with Etsy as necessary to provide you our services and comply with our obligations under both the Etsy Seller Policy and Etsy Terms of Use.
• Service Providers: We engage certain trusted third parties to perform functions and provide services to our shop, such as:
Payment processors
Shipping and delivery companies
Print-on-demand suppliers
Customer support platforms
Analytics providers
We will share your personal information with these third parties only to the extent necessary to perform these services and under appropriate data protection agreements.
• Business Transfers: If we sell, merge, or transfer our business, we may disclose your information as part of that transaction, only to the extent permitted by law and with appropriate safeguards.
• Legal Compliance: We may collect, use, retain, and share your information if we have a good faith belief that it is reasonably necessary to:
(a) respond to legal process or government requests
(b) enforce our agreements, terms, and policies
(c) prevent, investigate, and address fraud and other illegal activity, security, or technical issues
(d) protect the rights, property, and safety of our customers or others
5. Data Retention
We retain your personal information only for as long as necessary to provide you with our services and fulfill the purposes outlined in this policy. Specific retention periods include:
• Order Data: 10 years for accounting and tax purposes
• Marketing Data: Until you withdraw consent or request deletion
• Customer Support Data: 1 years after the last interaction
• Usage and Technical Data: 1 years for analytics and improvement purposes
We may also retain information to comply with legal and regulatory obligations, resolve disputes, and enforce our agreements.
6. International Data Transfers
We may store and process your information through third-party hosting services in the US and other jurisdictions. As a result, we may transfer your personal information to a jurisdiction with different data protection and government surveillance laws than your jurisdiction.
If we transfer personal data outside the EU, United Kingdom, or Switzerland, we will rely on appropriate safeguards such as Data Privacy Framework (DPF).
For more information on the DPF, visit the Data Privacy Framework website (https://www.dataprivacyframework.gov/).
7. Your Rights Under GDPR
You have the following rights regarding your personal data:
• Right of Access: Request access to your personal data and information about how we process it.
• Right to Rectification: Request correction of inaccurate or incomplete personal data.
• Right to Erasure: Request deletion of your personal data in certain circumstances.
• Right to Restrict Processing: Request limitation of processing in certain circumstances.
• Right to Data Portability: Request to receive your personal data in a structured, commonly used format.
• Right to Object: Object to processing based on legitimate interests or for direct marketing purposes. •
Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
• Right to Lodge a Complaint: File a complaint with your local data protection authority.
To exercise these rights, please contact us using the details provided in Section 9.
8. Data Security
We implement and maintain appropriate technical and organizational measures to ensure a level of security appropriate to the risk, including protection against unauthorized or unlawful processing and against accidental loss, destruction, or damage.
9. Minors
Our services are not intended for individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete such information promptly.
10. Cookies and Tracking Technologies
We may use cookies and similar tracking technologies to enhance your experience on our Etsy shop. These may include:
• Essential cookies for shop functionality
• Analytics cookies to understand usage patterns
• Marketing cookies (with your consent)
You can manage your cookie preferences through your browser settings or Etsy's cookie preferences.
11. Contact Information
For the purposes of European data protection law, NordXSwiss GmbH, Sperrstr. 83, Basel, Switzerland, is the data controller for your personal data.
For any questions or concerns regarding this Privacy Policy or our data practices, or to exercise your rights, please contact us at support@freshidealab.com or through Etsy's messaging service.
12. Additional Information by Jurisdiction
• European Union (EU) Countries: For detailed information regarding GDPR compliance, visit the official GDPR website: https://commission.europa.eu/law/law-topic/data-protection_en
• United Kingdom: Refer to the Information Commissioner's Office (ICO) website for UK GDPR guidance: https://ico.org.uk/
• United States: Visit the Federal Trade Commission (FTC) website for general guidance on U.S. privacy laws: https://www.ftc.gov/
• Canada: Find more information about PIPEDA on the Office of the Privacy Commissioner of Canada's website: https://www.priv.gc.ca/en/
• Australia: Access details about Australia's privacy laws from the Office of the Australian Information Commissioner (OAIC) website: https://www.oaic.gov.au/