Privacy Policy
Effective date: 29 September 2026
Applies to: barbarazawadzki.com
1. Data controller
The controller is Barbara Zawadzki, Övre Husargatan 21A, 413 14 Göteborg, Sweden, email: info@barbarazawadzki.com, telephone: {{PHONE_NUMBER}}, identification/organisation number: {{ORGANISATION_NUMBER_OR_NOT_APPLICABLE}} (the “Controller”).
2. Data we collect
- identity and contact data: name, email, telephone, billing and delivery addresses;
- order data: products, amounts, currency, discounts, payment status, delivery history and consents required for digital content;
- payment information returned by Stripe, such as a transaction identifier and status, payment-method type and limited card details; full card data is submitted directly to Stripe;
- customer-account data, correspondence, complaints and support requests;
- technical and cookie data: IP address, device, browser, security logs, cookie identifiers and use of the website;
- where the affiliate programme is used: affiliate/coupon identifier, clicks and attributed orders, commissions, settlement data and anti-fraud information;
- where enabled: newsletter, analytics and marketing-campaign data.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Orders, payment, e-book or printed-book delivery, customer account and support | Contract or steps requested before entering into a contract — GDPR Article 6(1)(b) |
| Accounting, tax, consumer-law and record-keeping obligations | Legal obligation — Article 6(1)(c) |
| Security, fraud prevention, legal claims and basic service statistics | Legitimate interests — Article 6(1)(f) |
| Operating the affiliate programme and settling commissions | Affiliate contract, legal obligation or legitimate interest in correct sales attribution, as applicable |
| Newsletter, non-essential analytics, personalisation and marketing | Consent — Article 6(1)(a); consent can be withdrawn at any time |
4. Sources and required data
Data comes from the user, the user’s device, Stripe, the carrier and, for affiliate activity, a referral link, coupon or affiliate account. Fields marked as required are needed to perform a contract or comply with law. Without them, the order may not be fulfilled. Other information is voluntary.
5. Recipients and service providers
Data may be shared, as necessary, with hosting and WordPress/WooCommerce administration providers, Stripe, email and e-book delivery providers, carriers, the affiliate-system provider, accountants, IT support and legal advisers. Public authorities receive data where the law requires it.
Stripe may process some data as an independent controller under its Privacy Policy.
6. Transfers outside the EEA
Some technology providers may process data outside the European Economic Area. Where this occurs, the Controller relies on a GDPR-permitted mechanism, such as an adequacy decision or Standard Contractual Clauses, and applies required safeguards. Information about the relevant safeguard is available on request.
7. Retention
- orders and accounting records: for the period required by Swedish accounting and tax law;
- complaints and claims: until resolution and expiry of the relevant limitation periods;
- account data: while the account is maintained, then only as required for legal obligations and claims;
- newsletter data: until consent is withdrawn or an objection takes effect, with a minimal suppression record retained;
- cookies: for the duration shown in the cookie settings; security logs for a period proportionate to risk;
- affiliate data: for the contract, settlement and required accounting/tax periods.
8. Cookies
The Store uses cookies needed for the cart, payment, security, language selection and customer account. Non-essential analytics, affiliate or marketing cookies are set only after consent where legally required. Choices can be changed or withdrawn at {{COOKIE_SETTINGS_URL}}. Blocking essential cookies may prevent checkout.
9. Your rights
Subject to the GDPR, individuals may request access, correction, erasure, restriction, portability, object to processing based on legitimate interests, and withdraw consent without affecting earlier lawful processing. Requests can be sent to the Controller. Identity verification may be required.
A complaint may be lodged with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se, or the data-protection authority where the individual lives.
10. Automated decisions and children
The Controller does not make decisions based solely on automated processing that produce legal or similarly significant effects for customers. Stripe may independently use automated fraud-prevention measures under its own policy. The Store is not directed at children; a minor should act with a guardian’s consent.
11. Security, updates and contact
The Controller uses appropriate technical and organisational safeguards, including access control, updates and transmission security. This Policy may be updated when services or law change; a new version will be posted with its date. Questions and requests: info@barbarazawadzki.com.