Kongens Bodega

Personvernerklæring

Privacy Policy

Effective Date: 2 June 2026

This Privacy Policy explains how the brand you registered with ("we", "us", "our") collects, uses, and protects your personal data. We are committed to transparency and to complying with the General Data Protection Regulation (GDPR) and applicable local data protection laws.

1. Data Controller

1.1. The data controller responsible for your personal data is Kongens Bodega Oslo, company registration number 988559202, registered at Universitetsgata 26, 0162, Oslo, NO. You can contact us about anything relating to your personal data at [email protected].

1.2. Data Protection Officer. You can contact our Data Protection Officer about anything relating to how we handle your personal data at [email protected].

1.3. Each brand is an independent data controller for the personal data processed within its own services and decides why and how that data is processed.

1.4. Platform operator. Our services run on a shared platform operated on the brand's behalf. The platform operator acts as a data processor under a written data processing agreement and processes your data only on the brand's documented instructions.

1.5. Cross-brand analytics. Where several brands belong to the same parent organisation, the organisation may produce aggregated, statistical analytics across brands. For this limited purpose the organisation and the brands act as joint controllers (GDPR Art. 26). This uses a contact identifier (such as a hashed email address or phone number) only to link records for counting and trend analysis. Your profile, your contact details, and your raw guest data are never shared with another brand, and other brands cannot read your data. The lawful basis is our legitimate interest in understanding group-level performance (GDPR Art. 6(1)(f)), and you may object at any time (see Your Rights).

2. Personal Data We Collect

We collect the following categories of personal data:

2.1. Identity data: first name, last name, date of birth, gender.

2.2. Contact data: email address, phone number.

2.3. Account data: account credentials, registration date, account preferences, theme settings.

2.4. Transactional data: purchases, payments, wallet transactions, wardrobe usage records.

2.5. Visit data: venue check-ins, visit history, interaction records.

2.6. Membership data: programme enrolment, tier status, loyalty activity, perk usage.

2.7. Content data: photos taken via photobooth features, feedback submissions.

2.8. Technical data: IP address, browser type, device information, operating system.

2.9. Communication data: marketing preferences, consent records, communication history.

3. How We Collect Your Data

3.1. Directly from you: when you create an account, update your profile, use our services, or contact us.

3.2. Automatically: through your use of our digital services (for example, visit records and device information).

3.3. From third parties: social login providers (Google, Apple, Facebook) if you choose to authenticate via those services, limited to the data you authorise them to share.

4. Lawful Basis and Purposes

We process your personal data on the following lawful bases:

4.1. Contract (GDPR Art. 6(1)(b)): to provide and manage your account, process transactions, deliver membership benefits, manage wardrobe services, and fulfil our contractual obligations to you.

4.2. Consent (GDPR Art. 6(1)(a)): to send you marketing communications and to tailor that marketing to you. This consent is separate from these Terms and can be withdrawn at any time without affecting your access to our services.

4.3. Legitimate interest (GDPR Art. 6(1)(f)): to keep our services secure, prevent fraud, understand and improve our services using aggregated insights, and run group-level analytics. We carry out a balancing test for each such purpose to make sure our interests do not override your rights, and you may object at any time.

4.4. Legal obligation (GDPR Art. 6(1)(c)): to comply with applicable laws, including tax, accounting, and regulatory requirements.

5. Profiling, Segmentation and Personalisation

5.1. To keep our services and any marketing relevant to you, we group guests into segments and apply tags based on information such as your visit history, transactions, membership activity, and preferences.

5.2. We use this to tailor offers and recommendations and to choose when to send marketing messages. This is profiling for direct marketing purposes.

5.3. This profiling does not produce legal effects concerning you and does not similarly significantly affect you (see section 11).

5.4. You can object to profiling for direct marketing at any time, and we will stop profiling you for that purpose. Withdrawing your marketing consent also stops marketing personalisation.

6. Photos and Images

6.1. Some venues offer photo features such as a photobooth. Photos may show you and other people who are present at the time.

6.2. We do not use facial recognition, biometric matching, or any automated identification on these photos, and we do not create biometric profiles. We do not process special categories of data for this feature.

6.3. We store and display photos only to provide the feature you used. You can ask us to delete a specific photo at any time.

6.4. Please be considerate of other people in the frame and obtain their agreement before capturing or sharing a photo that features them.

7. Recipients and Data Sharing

We share your personal data only with the categories of recipients below, and only to the extent necessary. Each processor acts under a written data processing agreement.

7.1. Payment processors: to process payments and refunds securely. We use Nets (Nexi Group, based in the EU) and Stripe (based in the United States).

7.2. Communication providers: to deliver transactional messages and, where you have consented, marketing messages. We use Twilio for SMS, Twilio SendGrid for email, and push notification services for app notifications.

7.3. Hosting and infrastructure providers: to store and run our services securely on cloud infrastructure located in the EU/EEA.

7.4. Error monitoring and security providers: to detect, diagnose, and prevent technical faults and abuse.

7.5. Analytics: we measure usage with aggregated, privacy-preserving methods. We do not share your data with advertising networks.

7.6. Law enforcement, regulators, and professional advisers: where required by law or to establish, exercise, or defend legal claims.

We do not sell your personal data, and we do not share it with other brands for their own marketing.

8. International Transfers

8.1. We store and process your personal data primarily within the EU/EEA.

8.2. Some processors (for example Stripe and Twilio, which are based in the United States) may process limited data outside the EU/EEA. Where this happens, we rely on an adequacy decision (such as the EU-US Data Privacy Framework) or on EU Standard Contractual Clauses together with additional safeguards.

8.3. You may ask us for a copy of the safeguards that apply to a specific transfer.

9. Data Retention

9.1. We keep your personal data only for as long as necessary for the purposes described in this policy. Our standard retention periods, and the criteria we use to set them, are:

- Account and profile data: for as long as your account is active. We delete it within 90 days after you close your account, unless a longer period below applies. - Transactional and payment records: retained to comply with bookkeeping law. The statutory minimum is 5 years after the end of the relevant financial year in Denmark and Norway, and 7 years in Sweden. - Visit, membership, and loyalty activity: up to 3 years after your last activity, after which it is deleted or anonymised. - Marketing engagement data (for example send and delivery records): up to 6 months, after which identifying fields are masked. - Consent and withdrawal records: retained for 5 years after the consent ends, to demonstrate compliance with our accountability obligations (GDPR Art. 5(2) and Art. 7(1)). - Support and dispute records: for the duration of the matter and up to 3 years afterwards, to establish, exercise, or defend legal claims. - Anonymised and aggregated data (which is no longer personal data) may be kept indefinitely for statistical purposes.

9.2. When a retention period ends, we delete the data or irreversibly anonymise it so that it can no longer be linked to you.

10. Your Rights

Under the GDPR you have the following rights, free of charge:

10.1. Right of access (Art. 15): obtain confirmation of whether we process your data and receive a copy of it.

10.2. Right to rectification (Art. 16): correct inaccurate or incomplete data via your account settings or by contacting us.

10.3. Right to erasure (Art. 17): have your data deleted, subject to legal retention requirements.

10.4. Right to restriction (Art. 18): limit how we process your data in certain circumstances.

10.5. Right to data portability (Art. 20): receive your data in a structured, commonly used, and machine-readable format, and have it sent to another controller where technically feasible.

10.6. Right to object (Art. 21): object to processing based on legitimate interests, and object at any time to processing for direct marketing, including profiling for direct marketing.

10.7. Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of processing before withdrawal.

How to exercise your rights

You can manage your profile and your marketing preferences directly in your account settings. To exercise your other rights, including access, portability, and erasure, contact the brand you registered with using the details in section 1, or contact our Data Protection Officer.

We respond without undue delay and within one month at the latest. We may extend this by two further months for complex or numerous requests, and we will tell you if we do. We may need to verify your identity before acting on a request. Exercising your rights is free, unless a request is manifestly unfounded or excessive.

Right to lodge a complaint

If you believe we have not handled your data lawfully, please contact us first so we can try to put it right. You also have the right to lodge a complaint with your data protection supervisory authority. In Norway this is Datatilsynet (datatilsynet.no).

11. Automated Decision-Making

11.1. We do not make decisions that produce legal effects concerning you, or that similarly significantly affect you, based solely on automated processing (GDPR Art. 22).

11.2. Membership tier promotions follow transparent rules and activity thresholds, which you can review in the membership programme details, and a person is available to review an outcome on request.

11.3. For marketing personalisation and segmentation, see section 5.

12. Children

12.1. Our services are intended for adults and are not directed at children under 18 years of age (or the applicable minimum age in your jurisdiction).

12.2. We do not knowingly collect personal data from children. If we learn that we have, we will delete it promptly.

13. Cookies and Similar Technologies

13.1. We use only strictly necessary cookies and similar technologies to operate our services. We do not use analytics, advertising, or tracking cookies, and we do not use tracking pixels in our emails.

13.2. For details, see our Cookie Policy.

14. Security and Data Breaches

14.1. We use appropriate technical and organisational measures to protect your personal data, including encryption in transit and at rest, access controls, and regular security reviews.

14.2. No method of transmission or storage over the internet is completely secure, but we work continuously to protect your data.

14.3. If a personal data breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, in line with GDPR Articles 33 and 34.

15. Changes to This Policy

15.1. We may update this Privacy Policy from time to time. We will make the current version available in our services and update the Effective Date shown at the top.

15.2. Where a change materially affects your rights, we will provide a prominent notice and, where required, ask for your renewed acceptance.