Privacy Policy

DRAFT — replaces the old generic WordPress privacy policy, which never described our actual data handling (orders, payments, accounts). This draft follows the required GDPR sections but needs your review before publishing: fill in the [TODO] items with real decisions.

  1. Data controller: Mira Plus AB, Org.Nr. 559392-0944, Gamla Norrtäljevägen 103A, 187 47 Täby, Sweden. Contact: info@miraplus.nu.

  2. What we collect: account data (name, email); order data (services purchased, shipping/contact address if applicable); payment data (handled by Stripe - we never see or store full card numbers); technical data (IP address, essential cookies).

  3. Legal basis: contractual necessity (to deliver a booked service), consent (marketing emails, opt-in only), legal obligation (bookkeeping).

  4. How we use data: process bookings/orders, respond to enquiries, meet Swedish accounting/tax obligations, and - only with explicit consent - send marketing updates.

  5. Data sharing: Stripe (payment processing, see https://stripe.com/privacy); Hostup AB (website hosting, servers in Stockholm, Sweden); Loopia AB (our email provider). These process data on our behalf under data processing agreements. We do not sell data to third parties.

  6. Data retention: orders and payment records are kept 7 years after the end of the financial year (Swedish bookkeeping law); your account is kept until you delete it (order records survive deletion but are disconnected from any account); contact form messages are deleted within 12 months of being handled; cart reservations that never become orders are deleted within a day.

  7. Your rights and how to contact us: you have the right to access, rectification, erasure, restriction, data portability, and to object to processing. For any of these - or any question about your personal data - email our data-protection contact at info@miraplus.nu; we reply within one month. Note that data we are legally required to keep (see section 6, e.g. accounting records) cannot be erased on request until its retention period ends. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY - imy.se).

  8. Security: passwords are hashed, payment details never touch our servers, and the site is served over HTTPS.

[TODO] Review and approve before go-live: the retention periods in section 6 are proposed operating policy - confirm they match how you actually want to work, then remove this note and the DRAFT header.