Privacy policy
PRIVACY POLICY
Last updated: 12 April 2026
1. Data controller and legal basis
FjordBites is the data controller for personal data processed through this online shop and associated services.
The processing is carried out in accordance with applicable data protection legislation, including:
– EU Regulation 2016/679 (General Data Protection Regulation – GDPR)
– The Personal Data Act (LOV-2018-06-15-38)
– the ePrivacy Directive (2002/58/EC), where applicable
– Other applicable national and international data protection regulations
By using the services, the user confirms that they have read and understood this statement.
2. Purposes of processing
Personal data is processed for the following lawful purposes:
a) Performance of a contract (GDPR Article 6(1)(b))
b) Compliance with a legal obligation (Article 6(1)(c))
c) Legitimate interests (Article 6(1)(f))
d) Consent, where required (Article 6(1)(a))
Purposes include:
– Delivery of goods and services
– Payment processing and logistics
– Customer service and communication
– Security, fraud prevention and risk management
– Marketing and personalisation (where consent has been given)
3. Categories of personal data
FjordBites may process the following categories:
– Identification and contact details
– Payment and transaction data
– Account information and preferences
– Technical information (IP address, device, browser)
– Behavioural data (use of the website)
– Communication data
Processing is limited to what is necessary, in accordance with the principle of data minimisation (GDPR Article 5(1)(c)).
4. Sources of information
Personal data is collected from:
a) The user themselves
b) Automatically via cookies and similar technologies
c) Service providers (e.g. payment and logistics partners)
d) Third parties and business partners
⸻
5. Disclosure of personal data
Personal data may be shared with:
– Shopify Inc. as the technical platform provider
– Payment providers and financial institutions
– Logistics and freight companies
– IT and analytics services
– Public authorities where required by law
All disclosure takes place in accordance with Articles 28 and 6 of the GDPR, and only where there is a valid legal basis for processing.
6. International data transfers
Personal data may be transferred to countries outside the EEA.
Such transfers take place in accordance with:
– Chapter V of the GDPR
– Standard Contractual Clauses (SCCs) adopted by the European Commission
– Any decisions on an adequate level of protection (Article 45)
The user accepts that such transfers may occur when using the services.
7. Storage and erasure
Personal data is stored only for as long as is necessary for the purpose, or to fulfil:
– Statutory requirements (e.g. the Accounting Act)
– Contractual obligations
– Dispute resolution and legal claims
The data is then deleted or anonymised in accordance with Article 5(1)(e) of the GDPR.
8. Security
FjordBites implements technical and organisational measures in accordance with Article 32 of the GDPR, including:
– Encryption and access control
– Secure payment solutions
– Monitoring of unauthorised access
However, absolute data security cannot be guaranteed.
9. The user’s rights
The user has the following rights under Chapter III of the GDPR:
– Right of access (Art. 15)
– Right to rectification (Art. 16)
– Right to erasure (Art. 17)
– Right to restriction of processing (Art. 18)
– Right to data portability (Art. 20)
– Right to object (Art. 21)
Where processing is based on consent, this may be withdrawn at any time.
10. Automated decision-making and profiling
FjordBites may use automated systems for analysis and personalisation.
This is carried out in accordance with Article 22 of the GDPR and does not affect the user’s rights.
11. Cookies
The services use cookies in accordance with the ePrivacy Regulation.
The user may manage or withdraw their consent via browser settings or the cookie banner.
12. Children’s privacy
The services are not directed at persons under the age of majority.
FjordBites does not knowingly collect data about children in breach of applicable legislation.
13. Limitation of liability
FjordBites is not liable for:
– Third-party processing of data
– Losses resulting from unauthorised access beyond our control
– Information shared by the user on external platforms
14. Changes to the policy
FjordBites reserves the right to update this policy to reflect:
– Legal requirements
– Technological changes
– Business needs
The updated version will be published on the website and will take effect immediately.
15. Complaints and supervisory authority
The user has the right to lodge a complaint with the relevant supervisory authority, including:
– The Norwegian Data Protection Authority (Norway)
or the equivalent authority in an EEA country.
16. Contact details
FjordBites
C/O Regus Flesland Airport
PO Box 9
5868 Blomsterdalen, Norway
Email: sale@fjordbites.com
FjordBites is the data controller in accordance with applicable data protection legislation.