Privacy Policy

Contact information can be found at the end of this document.

This Privacy Policy applies when Epoxit AS provides services and products in conjunction with purchases, customer service, and all other forms of contact, such as visiting the website, and in order to fulfill our obligations to you as customer.

1. What is personal data?

Personal data is information that can be linked to an individual directly or indirectly. Examples include names, addresses, phone numbers, ID numbers, email and IP addresses, or a combination of these which makes it possible to identify an individual.

All use of personal data is considered processing of personal data, including collection, registration, compilation, storage and transfer, or a combination of these.

Epoxit AS, hereafter Epoxit is the controller of personal data that is processed in conjunction with the use of our services and products, as well as personal data that we collect and process for the purposes described in this document. That Epoxit is the personal data controller means that Epoxit assumes responsibilities and obligations pursuant to the EU’s General Data Protection Regulation (GDPR).

All processing of personal data is carried out in accordance with applicable data protection laws.

2. How do we collect information about you and how is it used?

Epoxit only collects personal data that is necessary for the purposes described in the specific terms and conditions for the relevant service and in the Privacy Policy.

The only information we have about you is information that you provide when creating an account with Epoxit or data that is generated when you use our services. This includes page views and information about your device. In addition, we occasionally receive data from other sources and partners. The personal data to which we have access is primarily used to formulate agreements with you, but also to understand and improve our services, optimize our range, create personalized page views, store statistics, understand market trends, and personalize advertisements.

Pursuant to applicable data protection laws, personal data may only be collected for “specific, explicitly stated, and justified purposes”. Personal data may not be processed in way that does not conform to these purposes. Furthermore, pursuant to data protection laws, there must be grounds for processing personal data, i.e. a lawful basis.

In order for us to lawfully process your personal data, one or more of the following grounds must exist:

  1. processing is necessary for us to fulfill our contract with you,
  2. processing is necessary for us to fulfil our lawful duties (i.e. if we have a legal obligation to do something according to the law),
  3. processing is necessary for Epoxit’s legitimate interests provided that your interests for protection do not override these, or
  4. in specific cases, after you have consented to the processing in question.

In order for us to provide our services and products to you, we need to handle and process your personal data. The purposes for which we process your personal data and the lawful basis for doing so are described in examples below.

Certain personal data processing may require consent as a lawful basis. In such cases, we will request your consent for the processing in question before any processing commences.

Information is collected in several different ways:

Information that you provide to us and information that is collected through the use of services as follows

Creating an account

When you create an account with us, you provide information such as your name, postal code, email address and phone number. We will also record your purchases so as to provide you with an electronic receipt and to analyze purchasing histories and trends in order to present you with relevant special offers and shopping lists containing frequently purchased products. The information is stored in our database, primarily to provide the service you have ordered but also to improve our services.

You can log in to our website via your Facebook account if you have one. The only information we collect about you from your Facebook account is your email address and your name. We will never post anything to your Facebook account.

Newsletter subscription

When you subscribe to our newsletter, we save your name and email address in order to send out the newsletter to you. The information is stored in our databases mainly in order to provide the services ordered, as well as to provide you with relevant offers and information about special offers and promotions. Personal data is only processed in order to distribute the newsletter. We utilize a third party to distribute our newsletter.

Contact with Customer Service

We save information when you contact us, such as when you send an email, contact us by telephone or through one of the features on our website or via social media. We do this to save your enquiry.

Returns and claims

When making a return or claim in our stores, we will ask you for your name, phone number, and ID number, as well as your email address if making a damage claim. We request this information so as to be able to contact you if you have returned a product for repair, or for documentation requirements from authorities in conjunction with monetary compensation, and to be able to process your damage claim. The information is stored locally in the store and in our databases in order to combat fraud. The data is not shared with any other companies.

Information collected through the use of our services

When you make a purchase and use our services, we record information pertaining to which products you have purchased, and which products are of interest to you. This makes it possible for us to improve our services, combat fraud, and personalize content and advertisements according to your interests and patterns of use.

The information can be categorized as follows:

Technical data about your device and internet connection

By means of service logs and other tools, we record information about your device and connection to our services, e.g. operating system, web browser, IP address, network operator, cookies, and unique identification files.

If advertising ID is activated on your Android or Apple device, this information is sent from our app for personalized advertisements. Example of use: customization of our services for the device you are using so that you, for example, access the mobile version of our website when using your mobile phone.

Information about the use of services

When you visit one of our websites, your activity is automatically recorded in our measurement tool. We use this information to, for example, improve our services and provide you with personalized marketing according to your patterns of use.

Example of use: we collect traffic history in order to see which pages you have visited and for how long you stayed on the page so as to present products that are relevant to you.If you are logged in, we link the search history to your profile so that we can present products and content relevant to you.

Information about position

We record your geographic position based on your IP address or other forms of geolocation. If you consent to sharing your location in our app, your GPS position will be collected when using the app.

Examples of use: display offers in stores near you or provide relevant advertisements based on a position in which you have been.

Cookies and local storage

When you use Epoxit’s services, cookies and other data are stored locally (hereafter referred to as local storage of data) on your device. These are text files that are stored in your web browser which can be read by our services.

Locally stored data is used to simplify the use of our services and to provide you with relevant information when you visit our website, which improves your user experience. This is also used to gauge traffic on our website, collect statistics, track behavior to formulate target audiences for marketing, simplify advertisement management, and to improve our services.

Examples of use: we use cookies in order to recognize your device, which means you do not have to log in each time you use our services, or to provide personalized product displays so that you do not have to search. Cookies are also used to record the advertisements you have seen and clicked on.

Information from other sources

We receive information from other sources, such as measurement tools or other third-party tools, which help us or the other party to understand user activity and preferences, or to improve the service we offer in general.

Sending out marketing materials

In certain cases, we have a legitimate interest to process personal data in order to send out addressed marketing materials to you. We do so to afford you an opportunity to find out about special offers and products in our range.

When we send out addressed marketing materials, we purchase address registers from third parties. The information we purchase constitutes names and addresses. The information is only used so that it can be printed on catalogues, and the address register is deleted afterwards.

3. Storage duration periods

Epoxit does not store personal data longer than is necessary to fulfil the purpose of the processing and our legal obligations, e.g. as relates to the Norwegian Bookkeeping Act and other regulations concerning statutory limitations.

4. With whom is personal data shared?

Epoxit AS

We may share information with other companies within the group to be used for purposes of the same nature as those for which the information was collected, and as described in this Privacy Policy.

External companies

In certain cases, we use a personal data assistant for the processing of personal data, e.g. in order to enter into contracts or provide services.

Epoxit implements the requisite measures to ensure that the personal data assistant processes the personal data pursuant to our stipulations and in accordance with applicable laws, and we require adequate security measures to be in place.

Personal data may also be shared with various authorities as required by law.

Transfer to a third country

In general, we do not transfer customer information to countries outside of the EU/EES (so-called “third countries”). In the event that this is necessary, we implement appropriate security measures and ensure that the transferred personal data is processed pursuant to applicable data protection regulations. We ensure that the provider enters into a legal agreement with us in which they undertake to adhere to decisions approved by the EU Commission concerning the protection of personal privacy.

Other

If suspicions arise that a crime has been committed in conjunction with the use of Epoxit’s products or services, the information may be shared with authorities upon request.

We never forward, sell, or disseminate your personal data in any way other than that described in this Privacy Policy.

5. Security

We implement appropriate technical and organizational security measures, conforming to industry standards, to ensure that all the information we process is protected from being accessed by unauthorized parties. Only a limited number of employees has access to the information about you, and the way in which they process the information is strictly controlled.

We have implemented technical and organizational measures to protect your information from loss, manipulation, and unauthorized access. We regularly adapt our security measures in line with technological progress and development.

6. Your rights as a registered data subject

Pursuant to the EU’s General Data Protection Regulation, you have the right to know what we do with your personal data, such as when, how and why your personal data is processed. Furthermore, you have the right, in certain cases, to access your personal data or have it moved, rectified, erased, or restricted. If, for any reason, we cannot fulfil your wishes, we will provide justification for our failure to do so. Note that we can only provide information that we indubitably know belongs to you.

Your rights are listed below along with how you may exercise them.

Pursuant to the General Data Protection Regulation, as a private person you have a host of rights. Your rights are as follows:

  • You have the right to be informed of the personal data Epoxit processes about you.
  • You have the right to have the personal data Epoxit processes about you rectified and updated.
  • • You have the right to request the personal data Epoxit processes about you be erased. If you wish for your personal data to be erased, Epoxit will delete all personal data that Epoxit is not required by law to save.
  • If the processing of personal data is based on consent provided by you, you have the right to withdraw your consent, which means that processing will then cease, except in cases where Epoxit has a legal obligation to process the personal data.
  • It is important for us that the information we have about you is accurate and up-to-date. If you discover any discrepancies in your personal data, we request that you contact us in order for this to be rectified.

All communication pertaining to your rights will be in writing.

Deleting cookies

You can select whether to accept local storage of data through your browser settings. Here you can normally specify whether you accept cookies from the websites you visit, from third parties linked to the websites, and whether you wish to be notified each time a cookie is saved.

The exact procedure will depend on your device and the web browser you use. More information about cookies can be found here.

If you choose to deactivate local storage of data from Epoxit, it may prevent our websites from functioning optimally, e.g. you may be required to log in each time.

Complaints

If you feel that our processing of your personal data contravenes the General Data Protection Regulation, you should report this to us as soon as possible. You are also able lodge a complaint directly with the Norwegian Data Protection Authority.

All communication pertaining to your rights will be in writing.

7. Our analysis tools

We utilize analysis tools to collect information on how our services are used. For example, we calculate the number of visitors, which pages are visited, the duration of each visit, and similar.

We utilize analysis tools to collect information on how our services are used. For example, we calculate the number of visitors, which pages are visited, the duration of each visit, and similar.

Statistics about users and traffic are chiefly used in an aggregated form, which is why the statistics do not contain any type of information that can be linked directly to you as an identifiable person.

However, information on products purchased is linked to personal information in certain contexts in order for us to provide better customer service and targeted communication, such as in our customer management system and analysis system for sales pages. IP addresses and geodata are used to create statistics based on geographic criteria.

Google Anaytics: We use Google Anaytics to improve the customer experience on our websites. Google Anaytics collects anonymized information about behavior on our websites, including the pages visited. Hotjar does not collect data that is sent via forms or any personal information. Learn more about Google Anaytics ‘s privacy policy here.

8. Personal data of children

Epoxit does not collect or process the personal data of children under 16 years of age. If a child under the age of 16 provides us with personal information, we will delete this information as soon as we become aware of its existence. Parents/guardians can contact us as indicated below.

9. Changes to terms and conditions and the Privacy Policy

Epoxit reserves the right to change terms and conditions for consent and in the Privacy Policy in order to fulfil new legal requirements and in line with our own practices for the collection and processing of personal data.For changes that require consent, you will be requested to give your consent to the new terms and conditions when you log in to the site/service to which the change pertains.

Information about changes is communicated on our website www.epoxit.com.

10. Contact information

Epoxit has elected to appoint a data protection officer (DPO) who will be involved in all questions concerning the protection of personal data. It is the responsibility of the DPO to inform and offer advice in actual cases, as well as to assess whether the business complies with the GDPR in general.

Epoxit has also elected to make the DPO the contact person for all internal and external communication concerning the processing of personal data.

If you have questions regarding our Privacy Policy or data protection, kindly contact us on: customerservice@epoxit.com

Epoxit AS (org. nr. 912 448 363)
ATT: Behandlingsansvarlig/Personvern
Dalsrudåsen 82,
3073 Sande i Vestfold,
Norge

All communication must be in writing.

All communication concerning data subject rights, i.e. requests pertaining to your personal data such as access, rectification, erasure, portability, processing restriction, must be carried out by writing email to: customersevice@epoxit.com