1. Data Controller
The data controller responsible for your personal data is:
Rinseshoulder
Støtvigveien 52, 1560 Larkollen, Norway
Phone: +47 92 22 95 04
Email: cooperation@rinseshoulder.world
2. What Data We Collect
We may collect and process the following categories of personal data:
- Contact Information: Name, email address when you submit inquiries through our contact form.
- Communication Data: Content of messages you send to us.
- Technical Data: IP address, browser type, operating system, and browsing behavior collected through cookies (with your consent).
- Preference Data: Your cookie consent preferences stored in your browser.
We ask you not to submit special category data (for example health records, diagnosis details, or therapy history) through the contact form. If such information is submitted, it will only be processed to handle your request and protect your interests where required by law.
3. Purposes and Legal Basis
We process your personal data for the following purposes:
- To respond to inquiries: When you contact us, we use your data to respond to your questions. Legal basis: Performance of a contract or pre-contractual measures (Art. 6(1)(b) GDPR) or legitimate interests (Art. 6(1)(f) GDPR).
- To improve our website: We analyze aggregated, anonymized data to enhance user experience. Legal basis: Legitimate interests (Art. 6(1)(f) GDPR).
- Analytics and marketing (with consent): If you consent, we may use cookies to understand site usage and deliver relevant content. Legal basis: Consent (Art. 6(1)(a) GDPR).
Where processing is based on legitimate interests, we assess and balance our interests against your rights and freedoms.
4. Data Retention
We retain your personal data only as long as necessary for the purposes described:
- Contact form submissions: Up to 2 years from your last interaction, unless you request earlier deletion.
- Cookie data: As specified in our Cookie Policy.
- Legal obligations: Data may be retained longer if required by law.
5. Children and Age Requirement
This website is intended for adults. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact us and we will delete the data without undue delay.
6. Your Rights Under GDPR
As a data subject, you have the following rights:
- Right of Access: Request a copy of your personal data we hold.
- Right to Rectification: Request correction of inaccurate data.
- Right to Erasure: Request deletion of your data ("right to be forgotten").
- Right to Restriction: Request limitation of data processing.
- Right to Data Portability: Receive your data in a structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent at any time without affecting lawfulness of prior processing.
To exercise your rights, contact us at cooperation@rinseshoulder.world. We will respond within 30 days.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:
- SSL/TLS encryption for data transmission
- Secure storage systems with access controls
- Regular security assessments
- Staff training on data protection
8. Third-Party Sharing
We do not sell your personal data. We may share data with:
- Service providers: Third parties who assist with website hosting, analytics (with your consent), and technical support, bound by data processing agreements.
- Legal requirements: When required by law, court order, or government request.
9. International Transfers
If your data is transferred outside the European Economic Area (EEA), we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission.
You may request additional information about relevant safeguards by contacting us.
10. Cookies
We use cookies and similar technologies on our website. For detailed information, please see our Cookie Policy.
You can change or withdraw cookie consent at any time through the cookie settings panel available on the website.
11. Automated Decision-Making
We do not use your personal data for solely automated decision-making, including profiling, that produces legal or similarly significant effects.
12. Changes to This Policy
We may update this Privacy Policy periodically. Changes will be posted on this page with an updated revision date. We encourage you to review this policy regularly.
13. Complaints
If you believe your data protection rights have been violated, you have the right to lodge a complaint with a supervisory authority. In Norway, this is the Norwegian Data Protection Authority (Datatilsynet):
Datatilsynet
Postboks 458 Sentrum, 0105 Oslo
Website: www.datatilsynet.no