Privacy policy
(Last updated at: 2024-09-27)
To begin with, cest normal AB ("c'est normal", "we", "us", "our") would like to say that your trust and privacy are extremely important to us and we are committed to protecting it through our compliance with the practices described in this notice.
This Privacy Notice explains how we collect, use, share and protect your personal information and data in connection with cestnormal.co (the "Website"), the mobile application, or the services that link to this Privacy Notice (collectively, we call these our "Services"). In order to better understand our policies and practices for processing and storing your personal data, please carefully read this notice.
This notice applies to the personal data collected through our Website, regardless of the country where you are located. However, for California Consumers, we have also prepared a Supplemental Privacy Notice under the California Consumer Privacy Act of 2018 ("CCPA") ("California Notice"). Please review our California Notice for more information.
By engaging with our Services, you accept and consent to the practices described in this Privacy Notice. This Privacy Notice may change from time to time. Your continued engagement with our Services after any such revisions indicates that you accept and consent to them, so please check the notice periodically for updates.
Who we are & how to contact us:
cest normal AB is a Swedish Aktiebolag (limited company) with its principal office located at Nybrogatan 85, 114 41 Stockholm, Sweden.
Any comments, concerns, complaints, or questions regarding our Privacy Notice may be addressed to privacy@cestnormal.co or you can write us as follows:
To the c'est normal’s Data Protection Officer in the EU:
Data Protection Officer
cest normal AB, Grev Turegatan 30, 114 38 Stockholm, Sweden.
However, if you have any comments, concerns, complaints, or questions regarding any website, application, product, software, service, or content that are offered by third parties or that link to their own privacy statement, privacy policy, or privacy notice, then you should contact them with any privacy-related issues or questions.
Information we collect
The type of personal information and data we collect depends on how you are specifically interacting with us and which Services you are using. Generally, we collect the following categories of personal information:
- Contact Information, such as name, alias, address, phone number, social media user ID, email address, and similar contact data.
- Account Information, such as security-related information (including usernames and passwords, authentication methods, and roles), service-related information (including purchase history and account profiles), billing-related information (including payment, shipping, and billing information), and similar data.
- User Content, such as content of communications, suggestions, questions, comments, feedback, and other information you send to us, that you provide to us when you contact us, or that you post on our Services (including information in alerts, folders, notes, and shares of content), and similar data.
- Device & Browser Information, such as network and connection information (including Internet Service Provider (ISP) and Internet Protocol (IP) addresses), device and browser identifiers and information (including device, application, or browser type, version, plug-in type and version, operating system, user agent, language and time zone settings, and other technical information), advertising identifiers, cookie identifiers and information, and similar data.
- Usage Information and Browsing History, such as usage metrics (including usage rates, occurrences of technical errors, diagnostic reports, settings preferences, backup information, API calls, and other logs), content interactions (including searches, views, downloads, prints, shares, streams, and display or playback details), and user journey history (including clickstreams and page navigation, URLs, timestamps, content viewed or searched for, page response times, page interaction information (such as scrolling, clicks, and mouse-overs), and download errors), advertising interactions (including when and how you interact with marketing and advertising materials, click rates, purchases or next steps you may make after seeing an advertisement, and marketing preferences), and similar data.
- Location Data, such as the location of your device, your household, and similar location data.
- Demographic Information, such as country, preferred language, age and date of birth, marriage status, gender, physical characteristics, personal or household/familial financial status and metrics, military status, and similar data.
- Your Image, such as still pictures, video, voice, and other similar data.
- Identity Information, such as government-issued identification information, tax identifiers, social security numbers, other government-issued identifiers, and similar data.
- Financial Information, such as billing address, credit card information, billing contact details, and similar data.
- Social Media and Online Content, such as information in social media and online profiles, online posts, and similar data.
- For our Employees and Candidates for Employment: Career, Education, and Employment Related Information, such as job preferences or interests, work performance and history, salary history, status as a veteran, nationality and immigration status, demographic data, disability-related information, application information, professional licensure information and related compliance activities, accreditations and other accolades, education history (including schools attended, academic degrees or areas of study, academic performance, and rankings), and similar data.
Importantly, the Services may include links to third-party websites, plug-ins, services, social networks, or applications. Clicking on those links or enabling those connections may allow the third party to collect or share data about you. We do not control these third-party websites, and we encourage you to read the privacy notice of every website you visit.
Information that we may collect about you
We collect and use different types of data from and about you including:
- Personal data that we could reasonably use to directly or indirectly identify you, such as your name, postal address, email address, telephone number, username or other similar identifier, or any other identifier we may use to contact you online or offline ("personal data").
- Non-personal data that does not directly or indirectly reveal your identity or directly relate to an identified individual, such as demographic information, statistics, or aggregated information. Statistical or aggregated data does not directly identify a specific person, but we may derive non-personal statistical or aggregated data from personal data. For example, we may aggregate personal data to calculate the percentage of users accessing a specific Website feature.
- Technical information, including the Internet protocol (IP) address used to connect your computer to the Internet, your login information, browser type and version, time zone setting, browser plug-in types and versions, or operating system and platform.
- Non-personal details about your Website interactions, including the full Uniform Resource Locators (URLs), clickstream to, through, and from our Website (including date and time), products you viewed or searched for; page response times, download errors, length of visits to certain pages, page interaction information (such as scrolling, clicks, and mouse-overs), methods used to browse away from the page, or any phone number used to call our customer service number.
If we combine or connect non-personal, technical, or demographic data with personal data so that it directly or indirectly identifies an individual, we treat the combined information as personal data.
How we collect data about you
We use different methods to collect data from and about you including through:
-
Direct interactions
You may give us information about you by filling in forms or by corresponding with us by phone, e-mail or otherwise. This includes information you provide when you create an account, subscribe to our service, search for a product, place an order, or other social media functions on our Website, and when you report a problem with our Website.
-
Automated technologies or interactions
As you interact with our Website, we may automatically collect technical data about your equipment, browsing actions and patterns as specified above. We collect this information by using cookies, server logs, and other similar technologies (see Cookies and Automatic Data Collection Technologies).
-
Third parties or publicly available sources
We may receive information about you from third parties including, for example, business partners, sub-contractors in technical, payment and delivery services, advertising networks, analytics providers, search information providers, credit reference agencies, data brokers, or aggregators.
-
User contributions.
You also may provide information for us to publish or display ("post") on public Website areas, social media accounts, or transmit to other Website users or third parties (collectively, "User Contributions"). You submit User Contributions for posting and transmission to others at your own risk.
Cookies and automatic data collection technologies
Our Website uses cookies (small files placed on your device) or other automatic data collection technologies to distinguish you from other Website users. This helps us deliver a better and more personalized service when you browse our Website. It also allows us to improve our Website by enabling us to:
- Estimate our audience size and usage patterns.
- Store your preferences so we may customize our Website according to your individual interests.
- Speed up your searches.
- Recognize you when you return to our Website.
For detailed information on the cookies we use and the purposes for which we use them, see our cookie policy.
In addition to cookies, our Services may contain web beacons (small transparent embedded images or objects, also known as clear gifs, pixel tags, and single-pixel gifs) that permit us, for example, to count website page visitors or email readers, or to compile other similar statistics such as recording Website content popularity or verifying system and server integrity.
Third-party use of cookies and other tracking technologies
Some content or applications on the Services are served by third parties, including content providers and application providers. These third parties may use cookies alone or in conjunction with web beacons or other tracking technologies to collect information about you when you use our Services. They may associate the information collected with your personal data or they may collect information, including personal data, about your online activities over time and across different websites or other online services. They may use this information to provide you with interest-based (behavioral) advertising or other targeted content.
We do not control how these third-party tracking technologies operate or how they may use the collected data. If you have any questions about an advertisement or other targeted content, you should contact the responsible provider directly. For information about how you can opt out of receiving targeted advertising from many providers, search for Your Personal Data Use Choices.
How we use your personal data
To begin with, some laws require us to explain the lawful basis upon which we process your personal information. With respect to these laws, we process personal information about you for one or more of the following basis:
- To Perform a Contract. Where the processing is necessary for the performance of contract.
- Legitimate Interests. Where the processing is necessary for legitimate interests pursued by us or by a third party, except where such interests are overridden by your interests or fundamental rights and freedoms which require protection of personal information.
- Your Consent. Where you have given us consent to process your personal information for specified purposes, such as to provide our Service and other items requested by you.
- Comply with the Law. Where the processing is necessary for compliance with a legal obligation.
Specifically, we use your personal data to provide you with products, offer you services, communicate with you, deliver advertising and marketing, or to conduct other business operations, such as using data to improve and personalize your experiences. Examples of how we may use the personal data we collect include to:
- Present our Website and provide you with the information, products, services, and support that you request from us.
- Meet our obligations and enforce our rights arising from any contracts with you, including for billing or collections, or comply with legal requirements.
- Fulfil the purposes for which you provided the data or that were described when it was collected.
- Notify you about changes to our Services, products, or services.
- Ensure that we present our Website content in the most effective manner for you and for your computer.
- Administer our Services and conduct internal operations, including for troubleshooting, data analysis, testing, research, statistical, and survey purposes.
- Improve our Services, products, marketing, or customer relationships and experiences.
- Enable your participation in our Services' interactive, social media, or other similar features.
- Protect our Website, employees, or operations.
- Detect and prevent fraud and abuse to ensure the security and protection of all customers and others, as well as to identify and authenticate your access to our Service or to identify and authenticate you before we provide you with certain information.
- Measure or understand the effectiveness of the advertising we serve to you and others, and to deliver relevant advertising to you;
- Make suggestions and recommendations to you and other users of our Services about goods or services that may interest you or them.
Any other uses
We may also use personal data to contact you about our own goods and services that may be of interest to you. If you do not want us to use your data in this way, please [check the relevant box located on the form where we collect your data (the [order form/registration form])/adjust your user preferences in your account profile.] For more information, see Your Personal Data Use Choices.
We may use non-personal data for any business purpose.
Disclosure of your personal data
We may share your personal data with:
- Business partners, suppliers, service providers, sub-contractors, and other third parties we use to support our business (such as analytics and search engine providers that assist us with Website improvement and optimization). For example.
- Third-Party Content Providers. We may share your personal information with our third-party content providers to perform tasks on our behalf and to assist us in providing, delivering, analyzing, administering, improving, and personalizing content that are delivered as part of our Services. We may also pass certain requests from you or your organization to these content providers.
- Third-Party Service Providers. We may share your personal information with our third-party service providers to perform tasks on our behalf and to assist us in offering, providing, delivering, analyzing, administering, improving, and personalizing our Services. For example, service providers who assist us in performing, delivering, or enhancing certain products and services related to our delivery and operation of our Services, who provide technical and/or customer support on our behalf, who provide application or software development and quality assurance, who provide tracking and reporting functions, research on user demographics, interests, and behavior, and other products or services. These third-party service providers may also collect personal information about or from you in performing their services and/or functions on our Services. We may also pass certain requests from you or your organization to these third-party service providers.
- Advertisers. We may share your personal information with advertisers, advertising exchanges, and marketing agencies that we engage for advertising services, to deliver advertising on some of our Services, and to assist us in advertising our brand and products and services. Those advertising services may also target advertisements on third-party websites based on cookies or other information indicating previous interaction with us and/or our Services.
- Credit reference agencies when required to assess your credit score before entering into a contract with you.
- Social Media Services. We may work with certain third party social media providers to offer you their social networking services through our Services. These social networking services may be able to collect information about you, including your activity on our Services in accordance with applicable law and their own privacy policies.
- To fulfil the purpose for which you provide it. For example, if you give us an email address to use the "email a friend" feature of our Website, we will transmit the contents of that email and your email address to the recipients.
- For any other purposes that we disclose in writing when you provide the data.
- With your consent.
Any other types of third-party disclosures
We may also disclose your personal data to other third parties:
- In the event that we sell or buy any business or assets, in which case we may disclose your personal data to the prospective seller or buyer of such business or assets.
- To a buyer or other successor in the event of merger, divestiture, restructuring, reorganization, dissolution, or other sale or transfer of some or all of our assets, whether as a going concern or as part of bankruptcy, liquidation, or similar proceeding, where one of the transferred assets is the personal data we hold.
- To comply with any court order, law, or legal process, including responding to any government or regulatory request.
- To enforce or apply our terms of use or terms and conditions of supply [WEBSITE'S TERMS AND CONDITIONS OF SUPPLY OF GOODS OR SERVICES URL] and other agreements.
- To protect the rights, property, or safety of our business, our employees, our customers, or others. This includes exchanging information with other companies and organizations for the purposes of cybersecurity, fraud protection, and credit risk reduction.
- We may share non-personal data without restriction.
Consent to personal data transfer
We are based in Cyprus. We may process, store, and transfer the personal data we collect, in and to a country outside your own, with different privacy laws that may or may not be as comprehensive as your own. Whenever we transfer personal information to other jurisdictions, we will ensure that the information is transferred in accordance with this Privacy Statement and as permitted by applicable data protection laws.
By submitting your personal data or engaging with our Services, you consent to this transfer, storing, or processing.
Your personal data use choices
We strive to provide you with choices regarding certain personal data uses, particularly around marketing and advertising. We have established a privacy center where you can view and make certain decisions about your personal data use/the following personal data control mechanisms:
-
Promotional Offers from the Company
If you do not want us to use your [email address/contact information] to promote our own products and services you can opt-out by [checking the relevant box located on the form where we collect your data or by sending us an email with your request to privacy@cestnormal.co. You may also opt-out of further marketing communications by following the opt-out links on that message. This opt out does not apply to information provided to the Company as a result of a product purchase, warranty registration, product service experience, or other transactions.
-
Third-Party Advertising
If you do not want us to share your personal data with unaffiliated or non-agent third parties for promotional purposes, you can [opt-in/opt-out] by [checking the relevant box located on the form where we collect your data (the [order form/registration form])/[OTHER OPT-IN OR OPT-OUT METHOD]]. You can also always opt-out by sending us an email stating your request to privacy@cestnormal.co
-
Tracking Technologies and Advertising
You can set your browser to refuse all or some browser cookies, or to alert you when websites set or access cookies. If you disable or refuse cookies, please note that some parts of this Website may become inaccessible or not function properly. For more information about tracking technologies, please see Cookies and Automatic Data Collection Technologies.
-
Targeted Advertising
If you do not want us to use information that we collect or that you provide to us to deliver advertisements according to our advertisers' target-audience preferences, you can opt-out by [checking the relevant box located on the form where we collect your data (the [order form/registration form])/[OTHER OPT-OUT METHOD]]. You can also always adjust your settings by sending us an email stating your request to privacy@cestnormal.co For this opt-out to function, you must have your browser set to accept browser cookies.
Our Website may, from time to time, contain links to and from the websites of our partner networks, advertisers, and affiliates, or include plug-ins enabling third-party features. If you follow a link to any third-party website or engage a third-party plug-in, please note that these third parties have their own privacy policies and that we do not accept any responsibility or liability for these policies. Please check these policies before you submit any personal data to these third parties.
Accessing and correcting your personal data
You can access, review, and change your personal data by sending us an email at privacy@cestnormal.co to request access to, correct, or delete personal data that you have provided to us. We may not accommodate a request to change or delete information if we believe the change or deletion would violate any law or legal requirement or negatively impact the information's accuracy.
If you delete your User Contributions from the Services, copies of your User Contributions may remain viewable in cached and archived pages or because other Website users may have copied or stored them. Our Terms & Conditions govern proper access and use of information provided on the Website, including User Contributions.
Data security
The security of your personal data is very important to us. We use physical, electronic, and administrative safeguards designed to protect your personal data from loss, misuse, and unauthorized access, use, alteration, or disclosure. We store all personal data you provide to us behind firewalls on servers employing security protections. We encrypt any payment transactions using SSL technology.
The safety and security of your information also depends on you. Where we have given you (or where you have chosen) a password for access to certain parts of our Website, you are responsible for keeping this password confidential. We ask you not to share your password with anyone.
Unfortunately, the transmission of information via the internet is not completely secure. Although we do our best to protect your personal data, we cannot guarantee the security of your personal data transmitted to our Website. Any transmission of personal data is at your own risk. We are not responsible for the circumvention of any privacy settings or security measures contained on the Website.
Retention of information
We retain personal information in accordance with our records retention schedule, which varies by Service, business function, record classes, and record types.
We calculate retention periods based upon and reserve the right to retain personal information for the periods that the personal information is needed to: (a) fulfill the purposes described in this Privacy Statement, (b) meet the timelines determined or recommended by regulators, professional bodies, or associations, (c) comply with applicable laws, legal holds, and other legal obligations (including contractual obligations), and (d) comply with your requests.
Children's Online Privacy
We do not direct our Website to minors and we do not knowingly collect personal data from children under 16 years of age or as defined by local legal requirements. When a user discloses personal information on our Services, that user is representing to us that he or she is at least sixteen (16) years of age. If we learn we have mistakenly or unintentionally collected or received personal data from a child without appropriate consent, we will delete it. If you believe we mistakenly or unintentionally collected any information from or about a child, please contact us at privacy@cestnormal.co
Jurisdiction Specific Rights
In certain circumstances, local data protection laws (such as Regulation (EU) 2016/679, General Data Protection Regulation (“GDPR”)) may give you rights with respect to personal information if you are located in or are a resident of that country, state, or territory (including if you are located in the European Union or the European Economic Area). As discussed above, we have also prepared a Supplemental Privacy Statement for California Consumers under CCPA (“California Statement”) in compliance with the California Consumer Privacy Act of 2018 (“CCPA”). When reviewing these rights, it is important for you to understand that we are only required to honor rights to the extent that those rights apply to you under your applicable data protection laws.
What rights may be available to me?
Depending on the local data protection laws in your country, state, or territory, you may possess one or more of the following rights:
- Access to Personal Information. You may have the right to obtain confirmation from us that we process your personal information; and, in the event that we do so, you may have the right to request access to that personal information that we process. See Article 15 and Recital 63 of the GDPR.
- Erasure/Deletion. You may have the right to require us to erase some or all of the personal information concerning you. See Article 17 and Recitals 65, 66 of the GDPR.
- Rectification. You may have the right to request that we rectify inaccurate or incomplete personal information concerning by having that personal information amended or completed. See Article 16 of the GDPR.
- Restriction of Processing. You may have the right to require us to restrict the further processing your personal information. In such cases, we will mark the respective information as restricted, and may only be processed by us for certain purposes. See Article 18 of the GDPR.
- Data Portability. You may have the right to receive a copy of the personal information which you have provided to us and you may have the right to have that personal information transmitted to another entity without hindrance from us. See Article 20 and Recital 68 of the GDPR.
- Objection. You may have the right to object to the processing of your personal information by us and request that we no longer process some or all of your personal information. See Article 21 of the GDPR.
- Withdraw Consent. You may have the right to withdraw the consent that you have provided to us where we rely solely on your consent to process your personal information. If you withdraw your consent, we would like you to know that you can always provide your consent to us again in the future. See Article 7 of the GDPR.
- Right to Complain. You may have the right to lodge a complaint to a regulator or other supervisory authority if you are not satisfied with our responses to your requests or how we manage your personal information. For example, if you are located in the European Union or the European Economic Area, a list of and more information about the Data Protection Authorities can be found here: http://ec.europa.eu/justice/data-protection/bodies/authorities/index_en.htm. Prior to filing a complaint, we would encourage you to first reach out to us at privacy@cestnormal.co so we may have an opportunity to address your concerns directly.
Specific Rights to the United States:
If you are a California resident, California Civil Code Section 1798.83, if applicable, permits you the right to request information regarding the disclosure of your personal information to third parties for the third parties’ direct marketing purposes.
If you are a Nevada resident, Nevada residents may opt out of the future sale of their personal information to a third party by clicking the following link “Do Not Sell My Personal Information” or by emailing us at:privacy@cestnormal.co
When reviewing theses rights, it is important that you understand that these rights are not absolutely guaranteed and there are several exceptions to these rights were we may not have an obligation to fulfill your request.
How do I submit a request?
To make a request or exercise your rights, please visit our Data Subject Rights Portal.
Changes to Our Privacy Notice
We will post any changes we may make to our privacy notice on this page and indicate on the Website home page that we updated this privacy notice. If the changes materially alter how we use or treat your personal data we will notify you by email to the primary email address specified in your account and/or through a notice on the Website home page. Please check back frequently to see any updates or changes to our privacy notice.
Contact Information
Please address questions, comments, and requests regarding this privacy notice and our privacy practices to privacy@cestnormal.co
Our data protection office is Warner Nickerson.