Data protection
Last updated: September 2026
How we look after the personal data we hold — security, processors, and what happens if something goes wrong.
1. How we protect your data
Footfolk ApS processes personal data under the GDPR. We use technical and organisational measures so unauthorised people cannot get at it.
- HTTPS/TLS across the webshop.
- Payments run with certified providers. We do not store full card numbers.
- Passwords are hashed — never stored in plain text.
- Only staff who need it can see orders and customer data.
- Systems are kept up to date, and we take backups.
2. Processors
We use suppliers to run the shop. They may only process data on our instructions and have a processor agreement where GDPR requires one.
- Hosting and shop platform (the site and orders).
- Payments: Visa, Mastercard, Apple Pay, MobilePay, Klarna, Vipps and similar.
- Carriers: GLS, DHL, PostNord and the equivalent in your country.
- Email and newsletter — only if you subscribed, or the email is needed for the order (receipt, tracking).
- Analytics — only with your cookie consent.
3. Transfers outside the EU/EEA
Most processing stays in the EU/EEA. If a supplier uses servers outside the EU/EEA, it is only with a valid transfer tool — typically the European Commission’s standard contractual clauses, plus extra safeguards where needed.
4. Payments and fraud
Card details are entered at the payment provider, not on our servers. We may keep payment status, the last four digits and a transaction id so we can help with refunds and disputes.
We may review orders for misuse. If an order looks unusual, we can ask for confirmation before we ship.
5. Personal-data breaches
If we discover a breach that is likely to risk your rights, we notify the relevant authority within 72 hours where the law requires it, and we tell you if the risk is high.
6. Your requests
To access, correct or delete data, email [email protected] from the address on the account or order so we can identify you. We may ask for extra confirmation if there is doubt.
We cannot delete data we are legally required to keep — for example bookkeeping records. Those stay until the deadline ends, and we do not use them for anything else.
Your GDPR rights are set out in the privacy policy.
7. Retention and deletion
When a purpose ends, we delete or anonymise the data — unless bookkeeping, a warranty claim or a dispute means we must keep it longer. Backups roll off on their normal cycle.
8. Contact
Footfolk ApS, Karen Jeppesgade 12, 8300 Odder, Denmark. Email: [email protected]. You can complain to your national data protection authority, or in Denmark to Datatilsynet.