Free shipping for all orders over 499.00 kr.

Cookie & Privacy Policy

This Privacy & Cookie Policy outlines how Cosmetican ApS, operating under the S4TIVA brand (“S4TIVA”, “we”, “us”, “our”), collects, processes, stores and protects personal data when users access the website www.s4tiva.dk (“the Website”), purchase products through our online store, or otherwise interact with our services. S4TIVA is committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR), the Danish Data Protection Act and all applicable European privacy laws. By using the Website, you acknowledge that you have read and understood the terms of this Policy.

Data Controller

The data controller responsible for processing your personal information is Cosmetican ApS, Refsnaesgade 46, 2200 Copenhagen N., Denmark, registered under CVR/VAT number DK 45515087. Any inquiries relating to this Policy or to the processing of your personal data can be addressed to info@cosmetican.dk. As the data controller, we determine the purposes and lawful foundations for collecting and processing your information and ensure that such processing is conducted in accordance with GDPR.

Personal Data We Collect

We collect personal data in several ways depending on how you interact with the Website. When you place an order or create an account, we collect information necessary to identify you, process your transactions and deliver products, such as your name, contact information, billing and shipping details and related communication. When you browse the Website, we automatically collect certain technical data, including your IP address, browser type, device information, time spent on pages and other statistics essential for website performance and security. When you sign up for newsletters or contact our support team, we collect the information you voluntarily provide, including email addresses, inquiries, feedback and communication records. Payment information is processed securely by approved third-party payment providers; S4TIVA does not have access to full credit card numbers or other sensitive payment credentials.

Legal Basis for Processing

We process personal data only when a lawful basis under GDPR applies. When you purchase a product or request support, processing is necessary for the performance of a contract. When we conduct analytics, improve our services or ensure security and fraud prevention, processing is based on our legitimate interests, provided those interests do not override your rights. When you sign up for newsletters, accept cookies that are not strictly necessary or engage in marketing communication, the lawful basis is your explicit consent. Some processing is required to fulfil legal obligations, including bookkeeping, accounting and regulatory compliance.

How We Use Personal Data

We use personal data primarily to process and deliver orders, provide customer service, manage customer accounts, authenticate users, communicate updates and maintain business operations. Additionally, personal data is used to improve website functionality, conduct performance analysis, ensure security, prevent fraud and develop our products and services. When you consent to marketing, we may send updates, promotions or news about our products. All processing is limited to the purposes described in this Policy and is not extended beyond what is necessary for the functioning of the Website and our business operations.

Sharing and Disclosure of Personal Data

We share personal data only with trusted service providers who support our business operations. This includes payment processors responsible for secure transaction handling, logistics partners who deliver products, email and communication platforms that send order confirmations and updates, analytics providers who help us analyse site usage and hosting and IT partners who maintain the Website. All third parties operate under GDPR-compliant agreements and are prohibited from using your data for their own purposes. We may also disclose personal data when required by law, regulatory authorities or court orders. We do not sell personal data to any third party under any circumstance.

Data Retention

We retain personal data for as long as it is necessary for the purposes for which it was collected or as required by law. Order records and financial data are retained for the period mandated by Danish bookkeeping regulations. Customer account information is kept for as long as the account remains active. Marketing information is retained until consent is withdrawn. Automatically collected technical data is stored for limited periods consistent with analytical and security protocols. Once personal data is no longer required, it is either securely deleted or irreversibly anonymised.

Your Rights Under GDPR

As an EU resident, you have several rights regarding the processing of your personal data. These include the right to request access to data we hold about you, the right to request correction of inaccurate information, the right to request deletion where legally permissible, the right to restrict processing, the right to object to processing based on legitimate interests and the right to request transfer of your data in a structured and machine-readable format. You also retain the right to withdraw consent for any processing activities that depend on your consent. To exercise any of these rights, you may contact us at info@cosmetican.dk. You may also file a complaint with the Danish Data Protection Agency (Datatilsynet) if you believe your rights have been violated.

Data Security

We implement technical and organisational measures designed to protect personal data from unauthorized access, alteration, loss or misuse. These measures include encrypted data transmission through HTTPS, secure payment processing handled by certified third parties, restricted access to customer information, internal security protocols and regular monitoring of the Website for vulnerabilities. Although we take all reasonable precautions to protect personal data, no online transmission can be guaranteed as entirely secure.

International Data Transfers

Certain service providers we work with may operate outside the EU/EEA. In such cases, personal data may be transferred internationally only when adequate safeguards exist, including the use of Standard Contractual Clauses approved by the European Commission or transfers to jurisdictions with an adequacy decision ensuring similar data protection standards. All international transfers are conducted in compliance with GDPR requirements.

Children’s Privacy

The Website and our services are not intended for individuals under the age of 18. We do not knowingly collect personal data from minors. If we become aware that such data has been inadvertently collected, we will delete it promptly.

Use of Cookies and Tracking Technologies

The Website uses cookies and similar technologies to ensure proper functionality, enhance user experience, analyse performance and, where applicable, display relevant marketing content. Cookies are small data files stored on your device when you visit a website. They may be used to maintain session information, remember preferences, enable shopping cart functionality, support secure authentication, enhance performance and measure engagement. Some cookies are essential for the core functions of the Website and cannot be disabled, while others are used only when you provide consent through the cookie banner displayed on your first visit.

Types of Cookies Used

The Website uses several categories of cookies. Essential cookies maintain security, enable checkout, allow items to remain in the shopping cart and ensure that the site functions correctly. Functional cookies help remember preferences such as language or login state. Analytical cookies provide insight into website traffic, user behaviour and performance metrics, allowing us to improve our services. Marketing cookies may be used, with your consent, to deliver personalised advertisements and measure the effectiveness of advertising campaigns conducted through platforms such as Google, Meta or other advertising partners. The specific duration and behaviour of each cookie may vary depending on the provider.

Cookie Consent and Management

Upon your first visit, you will be asked to consent to non-essential cookies. You may accept all cookies, reject them or customise your preferences. Consent can be withdrawn at any time by adjusting your browser settings or by re-opening the cookie banner where technically available. Most internet browsers allow users to block or delete cookies through their settings panel; however, disabling certain cookies may affect the functionality of the Website or restrict access to essential features such as checkout.

Changes to This Privacy & Cookie Policy

We reserve the right to amend or update this Policy at any time. When changes are made, the revised Policy will be posted on this page with an updated “Last Updated” date. Your continued use of the Website following any changes constitutes acceptance of those changes. We encourage users to review this Policy periodically to remain informed about how we process personal data.

Contact Information

If you have any questions about this Privacy & Cookie Policy, the processing of your personal data or your legal rights, you may contact:
Cosmetican ApS
Refsnaesgade 46
2200 Copenhagen N., Denmark
Email: info@s4tiva.dk