Your personal data
LightAir International AB (“LightAir”, “we”, “us”) knows the importance of the privacy of our customers and website visitors and our aim with this policy is to describe to you, clearly and transparently, how we collect, use, display, transfer and store your data so that you feel confident that your personal data is stored securely. All LightAir’s processing of personal data is carried out in accordance with EU privacy legislation, the GDPR.
Responsibility for personal data
LightAir is the data controller for the processing of personal data on this and other websites operated by LightAir. LightAir International AB is part of the LightAir Group and the company LightAir AB (publ) has overall responsibility for the operations of the Group and therefore also of LightAir. LightAir AB (publ) is the company that exercises a controlling influence over other companies in the Group. LightAir therefore has a legitimate interest in transferring personal data to LightAir AB (publ) and other companies within the Group for internal administrative purposes and for the analysis of customers’ personal data. LightAir and LightAir AB (publ) therefore have a shared responsibility for personal data. Your main contact is LightAir, however.
Personal data collected by LightAir may therefore also be processed by LightAir AB (publ) or another company within the LightAir Group for the purposes specified below.
Collection of personal data
What is personal data?
Personal data is any information that can be used directly or indirectly to identify a living natural person. This includes, for example, name, personal identity number, address, e-mail address and telephone number. It also includes, for example, order numbers and encrypted data and various types of electronic identities, such as IP addresses, if these can be linked to natural persons.
How we collect personal data and what information we collect
LightAir collects personal data in a number of ways, but primarily directly from you.
Data collected in connection with the ordering and purchase of a product
When you order a product at lightair.com or from one of our vendors, we collect personal data from you in order to fulfil your order. This is usually your name, address and contact details. Our payment service providers also collect payment data from you when you make a payment.
When you place an order with us, we also collect information about your order. This includes, in addition to the above, your order number, shipment and tracking number, product selected and which other services you added to your order, for example.
Data collected through personal contact
We collect personal data from you when you contact us, for example, via customer service, by e-mail, by telephone, or by other means. In the first instance, we collect the personal data we need in order to answer your question or deal with your case. This information is your name and order number. Depending on how you choose to contact us, we may also collect contact details such as your e-mail address or telephone number.
In the case of contact in person, we also collect the other personal data that you choose to give us.
Data collected through My Pages
If you register a user ID at lightair.com (My Pages), we ask for your e-mail address so we can create a login for you. We also collect information about your username. Once on My Pages, you can choose to provide your name, address and contact details.
When you place an order with us, you can choose to create a user ID on My Pages if you don’t have one already. In this case, the user ID includes the personal data that you give us in connection with the order.
Data collected when you subscribe to our newsletter
If you choose to subscribe to LightAir’s newsletter, we collect your name and e-mail address so that we can send you the newsletter. We also collect information about your postcode and country of residence if you choose to provide this.
Data collected when you use our digital services
When you use one of our websites or any of our other digital services, we collect data about your use of the service. Some of this may be personal data, such as your IP address, for example. We also collect information about how you navigate the service, what searches you perform and which products you are interested in. If you are logged in to My Pages or provide information that allows us to identify you, we may link the information about your usage to the other data we have collected about you.
When you visit our website, we also use your IP address to determine your geographical position at the country level. We do this to better align the content of our website with relevant information for the country you are in.
Processing and storage of personal data
LightAir’s legal basis for processing your personal data
LightAir processes your personal data lawfully. It may be the case that the same personal data is processed on the basis of fulfilment of the terms and conditions of purchase and because the information is necessary in order to fulfil other legal obligations. This means that even if a basis for processing disappears and the processing that is based on that basis ends, we may still retain your personal data for other purposes. In the main, we process your data in order to fulfil a contract to which you are a party, such as the terms and conditions of purchase.
Administration of your order
We use your personal data in a number of ways in order to deliver the products and services you have ordered from us. The data is used to issue delivery notes and shipping documents, to book the shipment of your order and to enable our payment service providers to process payment for the products and services you have ordered. If you have ordered additional services or similar, your data will be used in a corresponding manner to deliver these services.
Administration of your order also includes use of your data for the purposes of accounting, billing and auditing, credit or other payment card verification and customs checks.
We use your personal data so that we can provide you with service if you contact us with any questions, comments, or complaints, for example. We use your name and order number to help us identify you and your order. We use your contact details, such as your e-mail address and telephone number, to contact you in connection with any questions or cases. We may also use all the other personal data we have collected about you in order to deal with your question or case, depending on what is relevant in each particular instance.
Sending information to you
Once you have placed an order with us, we use your personal data to send you an order confirmation, important information concerning your order and offers related to your order. These communications will be sent to the e-mail address you provided when you placed your order.
Once your order has been delivered, we may send you a survey asking you to answer some questions about your order to help us to improve our services.
As your order is being processed, we may send important information to the contact details provided when you placed your order. This may include, for example, information about order picking, dispatch, delivery information or events relating to your order.
We also send information about issues such as delays to delivery or if the product is out of stock. This information may be sent by e-mail, letter, text message or telephone, depending on the nature of the issues and the contact details we have for you.
We send payment reminders by e-mail.
Marketing and personalisation
Customer data may be used by LightAir in a marketing context in connection with orders to contact you by post, e-mail and text message.
If you have subscribed to our newsletter, we use your personal data in order to send you the newsletter and to personalise the content of the newsletter for you. This includes both your e-mail address and information about your order history. We use this information to provide you with the offers we believe will be of greatest interest and benefit to you.
On our websites, we use information about our users to provide personalisation. This means that we use the data we have collected about you and your use of our services to determine how the site content is displayed when you visit us. Customisation can mean, for example, that we store and display details of products you have searched for during previous visits to our website, products you have added to your shopping basket and language preferences and that we display advertisements and offers we believe are relevant to you and your preferences.
We also use personalisation in our communication via social media and web advertising on websites other than lightair.com.
In some cases, we share data with our business partners to help us customise our offers and marketing for you. We enter into agreements to ensure that such partners process data in accordance with relevant personal data legislation.
Development of products and services
We use the data we collect about our customers to develop and improve our products and services. This applies to our digital services, where we analyse user behaviour to develop our presentation of information and our offers and to design new features. It also applies to the development of our products in line with the wishes and behaviour of customers and to enable us to address shortcomings or improve security, for example.
We primarily use anonymous or anonymised data on an aggregated basis to perform this type of analysis. There may be instances, however, where we also use personal data that we have collected, where this is relevant.
Finally, your personal data may also be processed to enable us to fulfil the obligations we have under laws and regulations, such as with regard to security and reporting.
LightAir stores your personal data for as long as it is required for the purpose of the processing.
We store all the personal data we collect in our customer database. The customer database stores personal data relating to order history and accounting for at least seven (7) years, unless you have agreed that we can store your data for longer.
If you make a complaint within three (3) years of your last order, we store all your data for at least seven (7) years from the date of the order.
The data you have registered on My Pages is stored for as long as the user ID is active, for at least three (3) years from the last login.
If you subscribe to our newsletter, your contact details are stored for as long as you choose to continue receiving the newsletter.
The same personal data may be stored in several different places for different purposes. This may mean that data that has been deleted from one system because it is no longer required may remain in another system where it is stored on the basis of consent or for another purpose for which the personal data is still required.
LightAir’s technical and organisational measures for the secure processing of your personal data
We continuously implement measures to fulfil the principles of “data protection by design and by default”. We continuously evaluate the risks of the personal data processing that is carried out and implement the security measures necessary to mitigate the risks.
We continuously train our staff on data protection issues. If you have any specific questions about how we work with the Swedish Personal Data Act and the General Data Protection Regulation (GDPR), please e-mail [email protected].
Disclosure of personal data
Contractual partners and IT suppliers
We use a number of different IT services and IT systems in our operations. Some of these store and process personal data. We safeguard your privacy and the security of your data in all such processing. Some systems are installed locally at our offices and only our staff have access to the data. In these cases, no data is transferred to third parties. Some systems use cloud solutions, however, or are installed at the supplier’s offices, which means that we transfer personal data to the supplier. In such cases, the supplier is our personal data processor and processes the data on our behalf and in accordance with our instructions. Personal data may be transferred to a third country (i.e. a country outside the EU/EEA) in the event of a major IT incident. This transfer takes place solely for the purpose of protecting the data.
Cloud-based IT systems
Internally, we process personal data in our customer database, in our order and sales support systems and in our customer service system. These systems enable us to deliver the products and services you have ordered from us and to handle questions and provide customer care in connection with the performance of these deliveries and services. All the personal data we collect may be processed in these systems.
Web analytics companies
We use external suppliers for personalisation and analysis of user behaviour on our websites and for user feedback. These companies process personal data on our behalf as personal data processors. The data concerned is primarily data collected through cookies and it is processed at an anonymous and aggregated level.
We use external suppliers to process payments. These suppliers have access to personal data in the form of names, addresses and payment information. This processing is necessary in order for us to be able to deliver the products and services you have ordered from us.
We use external suppliers to provide information by text message and e-mail during the order delivery process. These suppliers have access to personal data in the form of telephone numbers and e-mail addresses.
Suppliers of products and services
We use subcontractors and contractual partners to provide some of the products and services you have ordered from us. It is often necessary for us to disclose personal data to these parties to enable the product to be delivered or the service to be performed.
When you place an order with LightAir through a website (digital partner) with which we collaborate in order to market our products, you may need to provide personal data to that website. This personal data is the responsibility of and is processed by the operator in question in accordance with their personal data policy.
When an order is processed through a digital partner, we send certain personal data to the operator in question to confirm that the order has been placed. The data we send to digital partners is pseudonymised data and order numbers. The operators are unable to use this data to identify you directly as a customer.
Shipping and transport
We contract shipping suppliers, both through long-term arrangements and for individual deliveries at the customer’s request. Shipping suppliers are given access to the personal data they need in order to carry out each delivery. Where relevant, this data comprises the name, address and contact details of the recipient. Where delivery is made using a shipping supplier outside the EU/EEA, the personal data is transferred to a third country (i.e. a country outside the EU/EEA). This transfer takes place solely for the purpose of carrying out the delivery.
We make deliveries from the most appropriate warehouse in relation to the destination. We contract third-party logistics suppliers (3PL) for our warehouse management. The warehouse that is handling the delivery is given access to the personal data of the recipient. This comprises the name, address and contact details of the recipient. Where delivery is made from our 3PL warehouse in the USA, the personal data is transferred to a third country (i.e. the USA, which is a country outside the EU/EEA). This transfer takes place solely for the purpose of issuing the delivery.
If you order other products or services from us, the personal data necessary to deliver the product or service you have ordered may, where applicable, be disclosed to the party delivering the product or performing the service. This may include, for example, your name, address and contact details.
Delivery to third countries
We supply products all over the world, which means that some of our partners (e.g. shipping companies) are located outside the EU/EEA. As a result, personal data may be transferred to business partners in these countries for the same purposes as are described above. Irrespective of the country to which LightAir transfers your personal data, LightAir has an obligation to ensure that your personal data enjoys a good level of protection, which LightAir naturally does.
Necessary processing of personal data
Processing of personal data that is necessary in order for us to be able to fulfil a contract with you or comply with a legal obligation is permitted without consent. Your consent to processing is required, however, to enable us to collect and process your personal data for any other purpose. We process your personal data when you use our services at lightair.com and when you have contact with our sales staff, our customer service staff or an agent or subcontractor.
Withdrawal of consent
You can withdraw your consent at any time by contacting us using the contact details above. If you withdraw your consent, we will erase your personal data and cease the processing for which the consent was given.
It may be the case that the same personal data is processed on the basis of consent and on the basis that the data is necessary or on the basis of other rules. This means that even if you withdraw your consent and the processing that is based on consent ends, we may still retain your personal data for other purposes.
Right to information about the personal data we store about you
If you would like to receive information about what data we have registered relating to you, you can apply in writing to the address above. A register extract is provided on request, with one extract free of charge per year. How do I request a register extract?
Write to LightAir requesting a register extract. Please note: You must submit your request in writing as it must contain your signature, which means you cannot just send an e-mail. Mark your letter “Personal data extract – LightAir”.
You can write the following, for example:
Personal data extract – LightAir
I hereby apply for information concerning the data stored about me in accordance with the GDPR.
(Place and date)
(Name in block capitals, personal identity number and address.)
(e-mail address/telephone number)
Right to control over your personal data
You have the right to request that the data stored about you be erased, completed or rectified. You also have the right to request that the processing of your personal data be restricted to specific purposes and not used for direct marketing or profiling, for example.
If you want to make a complaint
If you believe that a company is in breach of the GDPR or other privacy legislation, you can contact the Swedish Data Protection Authority. You can read more on the Swedish Data Protection Authority’s website