0
Your Cart
0
Your Cart

Privacy policy

This privacy policy explains which personal data Atheaa collects, why we do so, and which rights you have. We only collect data that is necessary to deliver your order and run the online shop.

Data controller

The data controller is the company that runs Atheaa:

Company
This detail will be filled in before the shop opens.
Organisation number
This detail will be filled in before the shop opens.
Address
This detail will be filled in before the shop opens.
Email
This detail will be filled in before the shop opens.
Phone
This detail will be filled in before the shop opens.

What data we collect

  • Orders: name, delivery address, email address and, optionally, phone number, as well as what you bought.
  • Customer account (optional): email address and password. The password is only stored in encrypted form.
  • Payment: payments are handled by our payment provider. We do not store your card number.
  • Enquiries: information you give us yourself when you contact us.
  • Technical operation: IP address and technical server logs, for security and troubleshooting.

We do not collect data for advertising, and we use no third-party analytics or tracking tools.

Purposes and legal basis

  • To complete the purchase and deliver the goods: performance of a contract (GDPR Article 6(1)(b)).
  • To keep accounting records: legal obligation under the Norwegian Bookkeeping Act (GDPR Article 6(1)(c)).
  • To protect the online shop against misuse and attacks: legitimate interest (GDPR Article 6(1)(f)).

We do not send newsletters or other marketing unless you have consented. You can withdraw your consent at any time.

How long we keep the data

  • Order and accounting data: for five years after the end of the financial year, as required by the Bookkeeping Act. After that they are anonymised.
  • Customer account: until you delete it or ask us to delete it.
  • Orders that are not completed or paid: deleted after 30 days.
  • Technical logs: up to 30 days. Backups: 7 days.

Who we share data with

We never sell personal data. We only share what is necessary, with these recipients:

  • The payment provider, to process the payment.
  • The carrier, to deliver the parcel.
  • The providers of server hosting and email, who process data on our behalf.

If a provider processes data outside the EEA, this is done with a valid transfer mechanism, such as the EU standard contractual clauses.

Your rights

You have the right to access, rectification, erasure, restriction and data portability, and the right to object to the processing. Contact us and we will reply within 30 days.

You can also complain to the Norwegian Data Protection Authority (datatilsynet.no) if you believe we process your data in breach of the rules.

Cookies

We only use necessary cookies. Read more on the Cookies page.

Changes

We update this policy when needed. Last updated: 5 October 2026.