Your rights under the General Data Protection Regulation.
Last updated: August 2026
Nord Blommor is committed to complying with the General Data Protection Regulation (GDPR) and protecting the personal data of all individuals who interact with our website and services. This page outlines how we fulfil our obligations under GDPR and explains your rights as a data subject.
Nord Blommor acts as the data controller for personal data collected through this website. Our contact details are:
Under GDPR, you have the following rights regarding your personal data:
You have the right to request a copy of the personal data we hold about you. We will provide this information free of charge within one month of receiving your request.
If you believe any personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will respond to your request within one month.
Also known as the "right to be forgotten," you can request that we delete your personal data in certain circumstances, such as when the data is no longer necessary for the purpose it was collected.
You have the right to request that we limit how we use your personal data in certain situations, such as when you contest the accuracy of the data or object to our processing.
Where processing is based on consent or contract, you have the right to receive your personal data in a structured, commonly used, machine-readable format and to transmit it to another controller.
You have the right to object to processing of your personal data based on legitimate interests. We will cease processing unless we can demonstrate compelling legitimate grounds.
You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. We do not currently use automated decision-making on this website.
To exercise any of your rights, please contact us at [email protected] with your request. We may need to verify your identity before processing your request. We will respond within one month, though this period may be extended by two months for complex requests.
We implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk, including:
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours. If the breach is likely to result in a high risk, we will also inform affected individuals directly.
If you are not satisfied with how we handle your personal data or respond to your requests, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY):
We may update this GDPR information from time to time. Any changes will be posted on this page with an updated revision date.