This Privacy Policy has been prepared in accordance with Regulation (EU) 2016/679 (General Data Protection Regulation – GDPR), as well as Organic Law 3/2018 of December 5 on the Protection of Personal Data and Digital Rights (LOPDGDD), and other applicable legislation.
Its purpose is to inform users about how we collect, process, and protect personal data, and about the rights you can exercise in relation to your data.
Who is the Data Controller?
The entity responsible for processing your personal data is:
-
Name / Business name: Suzy Decor (independent artisan brand)
-
Address: Fisterra, A Coruña, Spain
-
Email: info@suzy-decor.com
What personal data do we collect?
Suzy Decor will only collect the data strictly necessary for providing our services. These may include:
-
Identification data (name, email, phone number)
-
Billing and shipping information (address, payment details)
-
Transaction data (orders, invoices, shipping records)
-
Marketing-related data (newsletter subscription, preferences)
How do we collect your data?
-
Directly from you (when placing an order, creating an account, contacting us)
-
When you subscribe to our newsletter
-
Automatically, via cookies and similar technologies (see our Cookies Policy)
For what purposes do we process your data?
We process personal data for the following purposes:
-
Order management: processing purchases, payments, invoices, and deliveries
-
Customer service: responding to inquiries and resolving incidents
-
Marketing: sending newsletters, promotions, and updates (with your consent)
-
Legal compliance: accounting and tax obligations
-
Profiling: tailoring offers to your preferences and purchase history (without automated decision-making)
What is the legal basis for processing?
-
Consent – for marketing communications and newsletters
-
Performance of a contract – for purchases, payments, and deliveries
-
Legal obligations – for tax, invoicing, and consumer protection laws
-
Legitimate interest – to maintain customer relationships and send information about products similar to those you have already purchased (unless you object). You may object to this processing at any time.
How long do we keep your data?
-
Purchase and billing data: for the legally required retention period (5–10 years)
-
Marketing data: until you unsubscribe or withdraw consent
-
Other data: only as long as necessary for the purposes described, after which they will be securely deleted
Who do we share your data with?
Personal data is only shared when strictly necessary and in accordance with the law:
-
Accounting and tax authorities
-
Shipping companies (delivery purposes)
-
Payment service providers (Stripe, PayPal, Revolut)
We do not sell or share your data with other third parties without your prior consent.
What rights do you have?
Under GDPR, you have the right to:
-
Access your personal data
-
Rectify inaccurate or incomplete data
-
Request the erasure of your data (“right to be forgotten”)
-
Restrict processing of your data
-
Object to processing
-
Request data portability
-
Lodge a complaint with the Spanish Data Protection Agency (AEPD) if you believe your rights have been violated
How can you exercise your rights?
You may exercise your rights by contacting us via:
-
Email: info@suzy-decor.com
-
Postal mail: Fisterra, A Coruña, Spain
Proof of identity may be required. We will respond within the deadlines set by data protection laws.
What happens if you do not provide your data?
If you do not provide the mandatory data required for processing an order, we cannot guarantee the provision of services, including order confirmation, invoicing, or delivery.
Profiling and Marketing
Suzy Decor may create a customer profile based on your purchase history and preferences to offer you personalized recommendations. This does not involve automated decision-making with legal effects. You may object to profiling at any time by emailing info@suzy-decor.com or using the unsubscribe/manage preferences link in our emails.
Security Measures
Suzy Decor applies appropriate technical and organizational measures to protect your data, including:
-
Data encryption for secure transactions
-
Secure servers and restricted access
-
Regular monitoring and evaluation of security measures
Changes to this Privacy Policy
This Privacy Policy may be updated periodically to reflect changes in regulations or business practices. Updates will be published on our Website, and the latest version will always apply.
Last Updated: January 2026