Eagle DR AB logo

Eagle DR AB

Org.nr 559515-3122 · Stockholm

Contact
Back to Home
LegalGDPR Compliant

Privacy Policy

Eagle DR AB is committed to protecting your personal data and respecting your privacy rights under the GDPR and Swedish data protection law.

Last updated: 4 June 2026
GDPR & Swedish law
10 sections
01GDPR Art. 4(7)

Data Controller

Eagle DR AB (organisation number 559515-3122), with its registered address at Sotingeplan 28 LGH 1001, 163 61 Spånga, Stockholm, Sweden, is the data controller responsible for processing your personal data in accordance with the EU General Data Protection Regulation (GDPR) and the Swedish Data Protection Act (Dataskyddslag 2018:218).

Contact

eagledrab@gmail.com

02GDPR Art. 5

Personal Data We Collect

We collect and process the following categories of personal data:

Contact form

Full name, email address, phone number (optional), message content, and subject line.

Newsletter

Email address and preferred language.

Analytics

IP address (anonymised), browser type, device type, pages visited, and session duration via privacy-respecting tools.

B2B enquiries

Company name, job title, and order specifications when relevant to business correspondence.

We do not collect sensitive personal data (special category data) as defined under GDPR Article 9.

04Purpose limitation

How We Use Your Data

Your personal data is used exclusively for the following purposes:

  • Responding to contact form enquiries and business correspondence
  • Processing and fulfilling product orders and wholesale requests
  • Sending newsletters and product updates (with your consent)
  • Improving our website performance and user experience
  • Complying with legal and regulatory obligations
  • Protecting against fraudulent or abusive use of our services

We do not sell, rent, or trade your personal data to third parties for commercial purposes.

05Storage limitation

Data Retention

We retain personal data only for as long as necessary for the purpose for which it was collected:

Contact form data

24 months from last interaction, unless an ongoing business relationship requires longer retention.

Newsletter data

Until you unsubscribe, after which we delete your data within 30 days.

Order & invoice data

7 years in accordance with the Swedish Bookkeeping Act (Bokföringslag 1999:1078).

Analytics data

Aggregated and anonymised within 26 months.

06Third parties

Data Sharing and Transfers

We may share your personal data with the following categories of recipients:

Email service providers

For sending transactional emails and newsletters (processors under GDPR).

Hosting & infrastructure

Vercel Inc. (United States) — transfers covered by Standard Contractual Clauses per GDPR Art. 46.

Legal authorities

Where required by law, court order, or regulatory obligation in Sweden or the EU.

All third-party processors are bound by data processing agreements and are prohibited from using your data for their own purposes.

07Arts. 15–21

Your Rights Under GDPR

You have the following rights regarding your personal data:

Art. 15

Right of access

Request a copy of the personal data we hold about you.

Art. 16

Right to rectification

Request correction of inaccurate or incomplete data.

Art. 17

Right to erasure

Request deletion of your data ("right to be forgotten") where no legal obligation requires retention.

Art. 18

Right to restriction

Request that we limit how we process your data in certain circumstances.

Art. 20

Right to portability

Receive your data in a structured, machine-readable format.

Art. 21

Right to object

Object to processing based on legitimate interests or for direct marketing.

Supervisory authority

If unsatisfied with our response, you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.

08ePrivacy

Cookies and Tracking

Strictly necessary

Required for the website to function (session management, security). No consent required.

Analytics

Used to understand how visitors use our site. Activated only with your consent using anonymised data where possible.

Preference

Remember your language and theme preferences.

We do not use third-party advertising or tracking cookies. You can manage or disable cookies through your browser settings at any time.

09GDPR Art. 32

Data Security

We implement appropriate technical and organisational measures to protect your personal data, including:

  • TLS/HTTPS encryption for all data transmitted via our website
  • Access controls limiting data access to authorised personnel only
  • Regular review of our data handling practices
  • Secure infrastructure hosted on Vercel's enterprise-grade platform
Breach notification

In the event of a personal data breach posing a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours as required by GDPR Art. 33–34.

10Updates

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. The "Last updated" date at the top of this page indicates when the policy was last revised.

For material changes, we will notify registered newsletter subscribers by email. Continued use of our website after any changes constitutes acceptance of the updated policy.

Questions about this policy?

Contact Eagle DR AB at eagledrab@gmail.com or write to us at Sotingeplan 28 LGH 1001, 163 61 Spånga, Stockholm, Sweden.