PRIVACY

UPDATED 22nd May 2024

PRIVACY POLICY

1. WE CARE ABOUT YOUR PRIVACY

This notice describes how we, Urbanista AB, Reg. No. 556797-3267, Mäster Samuelsgatan 10, 111 44 Stockholm, Sweden ("Urbanista", "we", “our” or "us"), process your personal data that you provide to us when using our website (the "Website") and the Urbanista Audio app (the “App”). We are the data controller for the processing of personal data carried out within our business including on this website, which is described in more detail in this notice. Should you have any questions regarding our processing of your personal data, please contact us by using the contact details in section 8.

We care about your privacy and it is important to us that you feel comfortable with how we process your personal data. Therefore please read the information in this notice carefully before you interact with us.

Please note that our website or App may contain links to websites managed by third parties. These websites have (or should have) their own privacy policies, and we have no control, nor can we take any responsibility, for their business or policies. Thus, prior to submitting information to or through these third-party websites, you should review the privacy policies of such third parties.

In order to collect visitor statistics, we use cookies and similar technologies. By enabling cookies in your web browser and our cookie banner you consent to our use of cookies.

2. WHICH CATEGORIES OF PERSONAL DATA DO WE COLLECT, WHY, WITH WHICH LEGAL BASIS, AND FOR HOW LONG?

Urbanista may process your personal data for the purposes and legal bases set out below, and for the time period specified below.

2.1 Process Orders Made via our Website

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for the purpose of administering your order, including communicating with you regarding the order (e.g. for support purposes in the event of any issues with the delivery of the items).

What personal data we process and where we have collected them

From you:

●  name (first name and last name),

●  e-mail address,

●  telephone number,

●  address,

●  delivery address, and

●  information regarding your order and transaction (including any support email relating to the order should any issues arise with the delivered products).

What is our legal basis for the processing?

To fulfil our contractual obligations in relation to you. There is no way of being a customer of Urbanista if you do not accept the handling of the necessary personal data.

For how long do we process your personal data, for each purpose?

Until the purchase is fulfilled and fully completed (including delivery and payment) and for another 36 months to handle potential complaints and/or guarantee matters.

Please note that personal data will also be saved in accordance with certain law requirements, for example, for seven (7) years in accordance with the Swedish Bookkeeping Act. After this time has passed the personal data will be deleted.

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data to manage payments.

We use third-party payment providers in order to process payments via the Website. Your personal data may be shared with them for this purpose, for more information on our sharing, please see section 3.1.1.

What personal data we process and where we have collected them

From you:
Payment details (such as debit or credit card information).

What is our legal basis for the processing?

To fulfil our contractual obligations in relation to you.
If you do not accept the handling of the necessary personal data, the purchase will be denied. For how long do we process your personal data, for each purpose?
Until the purchase is fulfilled and fully completed (including delivery and payment).

Please note that personal data will also be saved in accordance with certain law requirements, for example, for seven (7) years in accordance with the Swedish Bookkeeping Act. After this time has passed the personal data will be deleted.

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for the purpose of handling potential complaints and/or guarantee matters.

What personal data we process and where we have collected them

From you:

●  name (first name and last name),

●  e-mail address,

●  telephone number,

●  address,

●  information regarding your order (e.g. type of product, time of purchase), and

●  information about possible complaints.

What is our legal basis for the processing?

To comply with our legal obligations in relevant consumer protection laws and our legitimate interest in handling complaints and/or defending ourselves against legal claims.

For how long do we process your personal data, for each purpose?

Until the complaint and/or guarantee matter has been completed.

2.2 Customer Support Matters or Other Communication

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for the purpose of managing customer support matters.

What personal data we process and where we have collected them

From you:

●  name (first name and last name),

●  e-mail address,

●  telephone number,

●  address, and

●  other information that you may provide in your correspondence with us.

What is our legal basis for the processing?

Our legitimate interest in being able to provide you with customer support.

For how long do we process your personal data, for each purpose?

Until the customer support matter has been completed.

2.3 Use of the Website and Newsletters

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for the purpose of providing you with our newsletter.

What personal data we process and where we have collected them

From you:

●  name, and

●  e-mail address.

What is our legal basis for the processing?

Your consent to receive newsletters.

You have the right to at any time oppose to our processing of your personal data for newsletters and de-register from future communications from us, please see section 6.7 for details on how to withdraw your consent.

For how long do we process your personal data, for each purpose?

Until you de-register from future communications from us.

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for the purpose of providing customer reviews on our Website.

What personal data we process and where we have collected them

From you:

●  name, and

●  e-mail address.

What is our legal basis for the processing?

Our legitimate interest in asking for feedback to facilitate buying decisions and to improve our products. For how long do we process your personal data, for each purpose?

Any posted review will be kept until further notice.

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for the purposes of personalizing the online user and shopping experience, and developing, testing and continuously improving our Website.

What personal data we process and where we have collected them

From other sources:

visitor statistics, including content and pages visited, referring website, and searches made on our Website.

What is our legal basis for the processing?

Our legitimate interest in being able to provide our website.

Your consent in relation to our use of non-essential cookies. Please see our Cookie policy for more information regarding cookies.

For how long do we process your personal data, for each purpose?

During your visit of the Website, or for a period not longer than 12 months.

2.4 Direct Marketing and Surveys

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for the purpose of sending you relevant and tailored offers via e-mail and other similar ways of electronic communication.

What personal data we process and where we have collected them

From you:
email address.

From other sources:

●  order history,

●  order value,

●  payment method used, and

●  from which country you accessed our Website.

What is our legal basis for the processing?

Based on your consent to receive direct marketing.

You have the right to at any time oppose to our processing of your personal data for direct marketing purposes and de-register from future communications from us, please see section 6.7 for details on how to withdraw your consent.

For how long do we process your personal data, for each purpose?

Until you de-register from future communications from us.

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data to carry out customer surveys and interviews.

What personal data we process and where we have collected them

From you:

●  name,

●  e-mail address,

●  telephone number, and

●  order history.

From other sources:

●  telephone number.

What is our legal basis for the processing?

Our legitimate interest in obtaining further knowledge of how our customers view us and our products and services.

For how long do we process your personal data, for each purpose?

The individual results of the surveys and interviews are only retained during such period that it takes for us to compile the result on an aggregated level and is thereafter deleted.

The aggregated information (which then no longer constitutes personal data) is retained until further notice.

2.5 Statistics and Business Development

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data for statistical purposes, e.g. in order to see how many individuals in a certain age range have purchased our certain product. This statistical information may be used for business development purposes.

What personal data we process and where we have collected them

From you:

●  location,

●  purchased product categories, and

●  information regarding payment method.

What is our legal basis for the processing?

Our legitimate interest of continuously improving our business and providing new products and services.

For how long do we process your personal data, for each purpose?

The personal data are retained during such period that it takes for us to compile the result on an aggregated level and is thereafter deleted.

The aggregated information (which then no longer constitutes personal data) is retained until further notice.

2.6 Products and Services

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data relating to the use of your Urbanista product for the purpose of providing the App and services relating thereto, e.g. to enable you to see the charging of your device and/or to change the audio settings on your device by using the Urbanista app.

What personal data we process and where we have collected them

From you:

●  location (on a general level such as that the product is being used in a city),

●  device ID, and

●  unique identifier for your Urbanista product.

What is our legal basis for the processing?

To fulfil our contractual obligations relating to you.

For how long do we process your personal data, for each purpose?

We process your personal data for as long as is necessary to fulfil our contractual obligations in relation to you.

For which purposes do we process your personal data, i.e. what we do and why

We process your personal data relating to the use of your Urbanista product and the App and services relating thereto for statistical purposes, e.g. to see how our products and services are working and are being used, and to improve our products and services.

What personal data we process and where we have collected them

From you:

●  data regarding your usage of the App and services relating thereto,

●  data regarding your usage of the Urbanista product,

●  device ID, and

●  unique identifier for your Urbanista product.

What is our legal basis for the processing?

Our legitimate interest of continuously evaluating and improving our business, products and services, and providing new products and services.

For how long do we process your personal data, for each purpose?

The personal data are retained during such period that it takes for us to compile the result on an aggregated level and is thereafter deleted.

The aggregated information (which then no longer constitutes personal data) is retained until further notice.

2.7 How have we performed the assessment of the balance of interests when the legal basis for processing your personal data is our legitimate interest?

For certain purposes, we process your personal data based on our legitimate interest as the legal basis. When determining that we have a legitimate interest, we rely on a balancing of interests test by which we have determined that our legitimate interests of the processing override your interest and your fundamental right not to have your personal data processed for this purpose. We have stated our legitimate interest in the tables above. Please contact us if you want to know more about how the balancing of interest test has been performed. Our contact details can be found in section 8.

3. WHO HAS ACCESS TO YOUR PERSONAL DATA?

Urbanista only shares personal data as described below. When we share your personal data, we ensure that the recipient processes them in accordance with this privacy policy by e.g. entering into data transfer agreements or data processing agreements with the recipients. The agreements ensure that your personal data are processed with an adequate level of protection and in accordance with the GDPR.

3.1 Categories of recipients with whom we may share your personal data

3.1.1 Third-Party Payment Providers

Categories of persons whose personal data may be shared with the recipient: Customers.

Personal data shared with the recipient: Name, address, order information, and debit or credit card information and device used for purchase to the third-party payment provider.

Recipient: We may share your personal data with third-party payment providers when they provide services to you and Urbanista to complete and administer payments. Please note that the payment providers are data controllers for their own processing of your personal data in order to process payments.

Purpose and legal basis: We use third-party payments providers to handle payments via our Website. In order to administer the order and for the performance of the agreement between you and us, we will disclose your personal data.

3.1.2 Delivery and Storage Partners and other Third-Party Service Providers

Categories of persons whose personal data may be shared with the recipient: Customers.
Personal data shared with the recipient: Name, address, delivery address, telephone number, order information, order history, IP-address.

Recipient: Our third-party service providers may process your personal data in connection with providing services on our behalf, e.g. delivery, storage and marketing services. The third-party service providers that we engage are contractually obligated to only process your personal data in accordance with our strict instructions and may not use your data for their own purposes. Additionally, they are obligated to implement technical and organizational security measures to protect and safeguard your personal data.

Purpose and legal basis: In order to handle orders, we use third-party delivery services and storage partners. As such, for the purposes of administering the order and to fulfill our contractual obligations in relation to you, we will share your personal data with our delivery and storage partners. Moreover, we may for the purposes outlined above in section 2 engage additional third-party service providers not mentioned in this section, e.g. to carry out customer surveys and to send tailored offers.

 

3.1.3 Third party in corporate transaction

Categories of persons whose personal data may be shared with the recipient: Customers, website visitors, App users and others who are in contact with us or interact with us.

Personal data shared with the recipient: What personal data we share with third parties depends on what personal data is requested by such third parties (our advisor, potential buyer and their advisor).

Recipients: If we, or a significant part of our business, were to be sold to or integrated with a third party, your personal data may be shared with our advisor, potential buyer and their advisor and then passed on to the new owner of the business.

Purpose and legal basis: We may disclose your personal data to third parties in case of a merger or a transfer of assets in order to fulfill our legitimate interest of carrying out such merger or transfer of assets.

3.1.4 Authorities

Categories of persons whose personal data may be shared with the recipient: Customers, website visitors, App users and others who are in contact with us or interact with us.

Personal data shared with the recipient: What personal data we share with authorities depends on what personal data is requested by the specific authority in each case.

Recipients: We may share personal data with authorities such as e.g. the police, the Swedish Tax Agency or another authority.

Purpose and legal basis: We may process and disclose the personal data that you have provided in order to comply with applicable law and regulations and lawful regulatory requests or relevant orders from competent courts and public authorities and to establish, exercise and defend legal claims.

3.1.5 Third Party Processors

Our carefully selected partners and service providers may process personal information about you on our behalf as described below:

Digital Marketing Service Providers

We periodically appoint digital marketing agents to conduct marketing activity on our behalf, such activity may result in the compliant processing of personal information. Our appointed data processors include:

(i)Prospect Global Ltd (trading as Sopro) Reg. UK Co. 09648733. You can contact Sopro and view their privacy policy here: http://sopro.io. Sopro are registered with the ICO Reg: ZA346877 their Data Protection Officer can be emailed at: dpo@sopro.io

4. TRANSFER OF PERSONAL DATA OUTSIDE THE EU/EEA

We use third-party delivery and storage partners which are based in China, Japan, and the U.S. As such, your personal data may in connection with a purchase be transferred outside the EU/EEA to countries that do not have the same level of protection for personal data as countries within the EU/EEA. In relation to such transfers, we will ensure that appropriate safeguards are put in place, e.g. by entering into a data transfer agreement including the standard model clauses for data transfers adopted by the EU Commission and available at the EU Commission’s website. If you wish to read them, you may download them via the EU Commission’s website (under the title Standard contractual clauses for international transfers (Word)).

5. WHAT ARE YOUR RIGHTS?

The right to data portability covers such personal data that you have provided to us and which we process either based on your consent or in order to fulfil our contractual obligations in relation to you. This typically includes your name, e-mail address, telephone number, address, order information, order history. It may also include any products reviews that you have made on the Website and survey results.

Applicable law grants you certain rights against us who process your personal data. We explain each of these rights below and what they mean for you with respect to the personal data that we process. If you wish to read more about what the Swedish Authority for Privacy Protection (Sw. Integritetsskyddsmyndigheten) (the “SAPP”) writes about these rights, please see the links to the SAPP below each of the relevant rights.

For the protection of your privacy and your personal data, we may require that you identify yourself in connection with your exercise of your rights.

Should you have any issues or questions regarding our processing of your personal data, please do not hesitate to contact us by using the contact details set out in section 8 below.

5.1 Right to information and access

In this privacy policy, we provide a general description of the personal data that we process in various situations, however, if you would like to know more about whether or not we process your personal data and, if so, to which extent we process your personal data, you can contact us on the below contact details and request information about which personal data we process about you.

If you wish to read more about the right to information, read here (or, in Swedish, here).

We can also provide you with a copy of the personal data that we process. In such copy, we provide information about e.g. the categories of personal data that are processed, what the personal data are used for, for how long the personal data are stored, with whom the personal data have been shared and from where the personal data have been collected.

If you wish to read more about the right to access, read here (or, in Swedish, here).

6.2 Right to rectification

We always aim towards ensuring that the personal data we process are correct and updated when needed. If you identify that we process incorrect or ambiguous personal data about you, you have the right to request that these are corrected. You also have the right to request that we update incomplete personal data if it is relevant based on the purpose of our processing, by providing us additional information. Please contact us on the below contact details for such requests.

If you wish to read more about the right to rectification, read here (or, in Swedish, here).

6.3 Right to erasure (right to be forgotten)

You have the right to request that your personal data are erased or that the processing is restricted. However, this right is not absolute. In order for us to erase your personal data, certain circumstances must apply. For example, you may have the right to have personal data erased if the data are no longer necessary for the purposes for which they were collected, if you withdraw your consent or if you object towards us using your personal data for direct marketing purposes.

The right to erasure is also limited in the event that there is an applicable exemption for the personal data in question. For example, we have the right to store your personal data if it is needed in order to determine, make claims or defend ourselves against legal claims.

If you wish to read more about the right to erasure, read here (or, in Swedish, here).

6.4 Right to object

You have the right to object against our processing, if the legal basis for the processing (as specified above) is that it is necessary for purposes regarding our legitimate interest. If you object to our processing, we no longer have the right to process your personal data, unless we can provide a legitimate reason that outweighs your interests, rights and freedoms, or if we process the data in order to determine or exercise, or defend ourselves against, a legal claim. If we consider that we have such legitimate rights, or if the personal data are needed for the purpose of determining, exercising or defence against legal claims, we will communicate this to you, including the grounds for the assessment.

You can also object against your personal data being used for marketing purposes (including profiling, if applicable). If you object against marketing, we will no longer process your personal data for this purpose.

If you wish to read more about the right to object, read here (or, in Swedish, here).

6.5 Right to limitation of processing                

You can request that the processing of your personal data is limited, for example if you do not consider that the personal data we process about you are correct, if you consider that the processing is unlawful, or while we review whether or not our legitimate interest outweighs your privacy interest when you have objected against the processing.

If you wish to read more about the right to limitation of processing, read here (or, in Swedish, here).

6.6 Right to data portability

You have the right to request that the personal data that we process about you and which you have provided to us (provided that our legal basis for the processing is consent or performance of a contract) be transmitted in a structured, generally used and electronic format. This presupposes that the processing is automatic (i.e. not in physical form on a paper). Of it is technically possible and if you request it, we can transfer your personal data to another controller.

If you wish to read more about the right to data portability, read here (or, in Swedish, here).

6.7 Right to withdraw your consent

You may, at any time, withdraw all or part of the consent you have given us, with effect from the time of withdrawal (i.e. the processing that has taken place prior to your withdrawal will not be affected).

The easiest way to stop getting direct marketing is to unregister from mailing by clicking the unsubscribe-button in the send-out or contact us by using the contact details in section 8].

6.8 Right to complain to supervisory authority

You may file a complaint with the SAPP (or another supervisory authority) if you believe that Urbanista’s processing of your personal data is not carried out in accordance with applicable laws.

If you wish to read more about the right to complain, read here (or, in Swedish, here).

7. HOW WILL WE NOTIFY YOU OF CHANGES TO THIS NOTICE?

Please note that we may change or amend the information contained in this privacy policy if needed in order for us to adequately describe how we process personal data.We advise you to keep yourself up to date with our Privacy Policy when visiting our Website or App.

If we make any changes to this information, we will notify you on the Privacy Policy section on our site. We advise you to keep yourself up to date with our Privacy Policy when visiting our site.

8. QUESTIONS?

If you have any questions or concerns about our processing of personal data, please contact us at support@urbanista.com or by using the following contact details.

Urbanista AB (556797-3267)
Mäster Samuelsgatan 10
111 44 Stockholm
Sweden