ScandiNaturePass

Privacy policy

This policy explains what personal data ScandiNaturePass ("we") collects when you buy or take a course, why, and what your rights are. The data controller is Näshultakök, Ollonborrstigen 7, SE971124765101. Contact for all privacy questions: (contact email).

What we collect and why

We do not collect payment card details — payment is handled entirely by Stripe. We do not use advertising or analytics trackers, and we do not make decisions about you by automated means.

Who receives your data

We do not sell your data.

How long we keep it

Cookies

We only use strictly necessary cookies: one that remembers your chosen language, and (for administrators only) a secure login session cookie. No consent banner is needed because nothing is used for tracking or marketing. Fonts are served from our own server.

Your rights

You can ask us for access to your data, to correct it, to erase it, to restrict or object to its processing, and to receive it in a portable format. Write to (contact email) and we will answer within one month. You also have the right to lodge a complaint with your national data protection authority (in Sweden: Integritetsskyddsmyndigheten, imy.se).

Security

Data is transmitted over HTTPS. Administrator access requires individual accounts with two-factor authentication, access is limited by role, and administrative actions are logged. Secrets such as payment keys are stored encrypted. Course access links are long random codes — keep them private.

Changes

We will update this policy when our processing changes. Current version: 1.0.