Privacy Policy

Privacy Policy

Last updated: July 24, 2026

This Privacy Policy explains how MARVELLO collects and processes personal data when you visit marvello.eu, place an order, create or use an account, subscribe to communications, contact Client Services or otherwise interact with us.

MARVELLO processes personal data in accordance with the General Data Protection Regulation (EU) 2016/679 (“GDPR”), applicable Swedish data-protection legislation and other applicable law.

Principle

Necessary And Proportionate

Control

Your GDPR Rights

Contact

Client Services

Privacy Information

Clear information about what we collect, why we process it, how long it is retained and the choices available to you.

1. Data Controller

MARVELLO is the trading name used for the business operating marvello.eu.

Data controller: [FULL LEGAL NAME]
Organisation number: [ORGANISATION NUMBER]
Registered address: [REGISTERED BUSINESS ADDRESS]
Email: clientservices@marvello.eu

The data controller determines the purposes and means of the personal-data processing described in this Policy.

2. Scope

This Policy applies to personal data processed through our website, online store, customer accounts, order and return processes, newsletters, Client Services and related digital services.

It does not govern independent third-party websites or services reached through external links. Those providers are responsible for their own processing and privacy information.

3. Personal Data We Collect

Depending on how you interact with MARVELLO, we may process:

  • Identity and contact data, including name, email address, telephone number, delivery address and billing address.
  • Order and transaction data, including products ordered, order value, payment status, delivery method, returns, refunds and correspondence relating to a purchase.
  • Account data, including account identifiers, authentication information, saved preferences and account activity.
  • Payment-related data, including payment method, transaction reference and payment confirmation. Complete card details are normally handled directly by authorised payment providers and are not stored by MARVELLO.
  • Communications, including messages, enquiries, complaints, return requests and other information you provide to Client Services.
  • Technical and usage data, including IP address, device and browser information, cookie identifiers, website interactions, security logs and approximate location derived from technical data.
  • Marketing data, including subscription status, consent records and interaction with our communications.

Please do not send sensitive personal data unless it is strictly necessary for us to handle your request.

4. How Data Is Collected

We collect personal data:

  • directly from you when you place an order, create an account, subscribe, contact us or submit information;
  • automatically when you use the website, subject to your cookie choices and applicable law;
  • from service providers involved in payments, fraud prevention, fulfilment, delivery, website operation, customer support and analytics; and
  • from publicly available sources or business partners where lawful and relevant.

Where data is required to enter into or perform a contract, failure to provide it may prevent us from processing an order, delivering a product or responding fully to a request.

5. Purposes And Legal Bases

  • Orders, payments, delivery, returns and refunds: necessary to enter into or perform a contract with you.
  • Customer accounts and requested services: necessary to perform a contract or take requested pre-contractual steps.
  • Client Services: contract, legitimate interests in providing support and managing our customer relationship, or legal obligation, depending on the matter.
  • Accounting, tax, consumer-law and regulatory requirements: compliance with legal obligations.
  • Security, fraud prevention and misuse detection: our legitimate interests in protecting customers, transactions, systems and legal rights.
  • Website operation, troubleshooting and service improvement: our legitimate interests, provided those interests are not overridden by your rights and freedoms.
  • Email marketing and non-essential cookies: consent where consent is required by law.
  • Legal claims and dispute management: our legitimate interests in establishing, exercising or defending legal claims, and compliance with legal obligations.

Where we rely on legitimate interests, we assess the necessity and proportionality of the processing and its effect on your rights.

6. Cookies And Similar Technologies

We use strictly necessary technologies to operate essential website functions such as security, checkout, authentication and preference storage.

Analytics, personalisation or advertising technologies are used only where permitted by applicable law and, where required, after you have given consent. You may accept, reject or adjust non-essential technologies through the cookie settings available on the website.

Withdrawing consent does not affect processing that occurred before withdrawal. Further details about individual technologies, providers, purposes and durations should be presented in MARVELLO’s cookie settings or separate Cookie Policy.

7. Marketing Communications

We may send marketing communications where you have consented or where another lawful basis is available under applicable law.

You may unsubscribe at any time through the link included in a marketing email or by contacting Client Services. We may retain limited suppression information to ensure that your opt-out is respected.

Service messages relating to an order, account, security matter, return or legal notice are not marketing communications and may still be sent where necessary.

8. Recipients And Service Providers

We disclose personal data only where necessary and lawful. Recipients may include:

  • website, hosting, infrastructure and security providers;
  • payment processors and fraud-prevention providers;
  • warehousing, fulfilment, delivery and return partners;
  • email, customer-support, analytics and consent-management providers;
  • professional advisers, insurers, auditors and authorities; and
  • a purchaser, investor or adviser in connection with a genuine corporate transaction, subject to appropriate safeguards.

Service providers acting on our behalf may process data only under documented instructions, subject to confidentiality, security and data-processing obligations. Some providers act as independent controllers for specific processing and must provide their own privacy information.

9. International Transfers

Some recipients may process personal data outside Sweden or the European Economic Area (“EEA”). Where personal data is transferred outside the EEA, we use a lawful transfer mechanism, such as an adequacy decision adopted by the European Commission or the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required.

You may contact us for further information about the safeguards relevant to a transfer involving your personal data.

10. Retention

We retain personal data only for as long as necessary for the relevant purpose, including:

  • Order and accounting records: for the period required by Swedish accounting, tax and consumer-law obligations.
  • Customer account data: while the account remains active and thereafter for a limited period needed for security, dispute handling or legal compliance.
  • Client Services communications: for as long as needed to resolve the matter and manage related legal or contractual obligations.
  • Marketing data: until consent is withdrawn, you object, the purpose expires or continued retention is no longer justified.
  • Security and technical logs: for a limited period proportionate to security, troubleshooting and fraud-prevention needs.

When data is no longer required, it is deleted, anonymised or securely restricted unless continued retention is required by law or necessary for legal claims.

11. Security

We apply appropriate technical and organisational measures designed to protect personal data against unauthorised access, loss, alteration, disclosure or destruction. Measures are selected with regard to the nature, scope, context and risks of the processing.

No method of transmission or storage is completely secure. You should protect account credentials and avoid sending confidential information through unsecured channels.

12. Your Rights

Subject to the conditions and limitations in the GDPR, you may have the right to:

  • receive information about our processing and request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • receive data you provided in a structured, commonly used and machine-readable format and, where technically feasible, have it transmitted to another controller;
  • object to processing based on legitimate interests;
  • object at any time to processing for direct marketing;
  • withdraw consent at any time, without affecting earlier lawful processing; and
  • lodge a complaint with a competent supervisory authority.

These rights are not absolute. Legal obligations, the rights of others and the establishment, exercise or defence of legal claims may limit a request.

13. Exercising Your Rights

To exercise a data-protection right, contact clientservices@marvello.eu and describe your request.

We may request information reasonably necessary to confirm your identity and protect your data. We will respond without undue delay and within the time required by applicable law. Requests are generally free of charge, although a reasonable fee may be permitted for manifestly unfounded or excessive requests.

14. Automated Decisions

MARVELLO does not currently make decisions based solely on automated processing that produce legal effects or similarly significant effects on you.

Automated tools may be used to support security or fraud screening. Where a decision falls within Article 22 GDPR, we will provide the information and safeguards required by law, including the ability to request human intervention where applicable.

15. Children

Our online store is intended for persons who may lawfully enter into a purchase agreement or who act with the involvement of a parent or legal guardian where required.

We do not knowingly collect personal data from children for profiling or targeted marketing. If you believe that a child has provided personal data unlawfully, please contact us so that the matter can be investigated and appropriate action taken.

16. Complaints

Please contact us first so that we have an opportunity to address your concern.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, “IMY”) or another competent supervisory authority in the EU or EEA.

IMY: Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, Sweden.

17. Changes To This Policy

We may update this Privacy Policy to reflect changes in our operations, technology or legal obligations. The revised version will be published on this page with an updated revision date.

Where required by law, we will provide additional notice or obtain renewed consent before materially changing processing based on consent.

18. Contact

Questions about this Privacy Policy or MARVELLO’s processing of personal data may be directed to:

MARVELLO / [FULL LEGAL NAME]
[REGISTERED BUSINESS ADDRESS]
[POSTCODE AND CITY], Sweden
clientservices@marvello.eu