PRIVACY POLICY FOR HOUSE OF NEEDLEWORK
Last updated: 1 January 2026
House of Needlework
Vandmanden 12B
9200 Aalborg SV
Denmark
VAT: DK45404366
Email: info@houseofneedlework.com
Phone: +45 81655781
1. Data Controller
House of Needlework is the data controller for the processing of personal data when you visit our website, make a purchase in our webshop, create an account, contact us or subscribe to our newsletters.
2. Personal Data We Collect
We only process the personal data necessary to deliver our products, operate our webshop, manage customer relationships and comply with applicable laws.
We do not process sensitive personal data.
2.1 Data You Provide When Making a Purchase or Contacting Us
When you make a purchase or contact us, we process:
- Name
- Address
- Phone number
- Email address
- Order and delivery information
- Payment information (we do not have access to your full card details)
2.2 Data You Provide When Creating an Account
When you create an account, we process the information you enter:
- Username
- Email address
- First and last name
- Password (stored in encrypted form)*
- Company name (if applicable)
- Country
- CVR/VAT number (if applicable)
- Phone number
- Billing email
- Address
- Postal code and city
*Your password must contain at least one lowercase letter, one uppercase letter and one number.
These details are used to manage your customer account, verify your identity and ensure accurate billing and delivery.
2.3 Data Collected Through Customer Service Enquiries
When you contact us via email, phone or contact form, we process the information you provide and any information necessary to handle your enquiry.
2.4 Data Collected When Subscribing to Newsletters
When you subscribe to our newsletter, we process:
- Email address
- Name (if provided)
This information is used to send newsletters and marketing content based on your consent.
2.5 Technical Information
During the operation of our website, certain technical information is processed automatically by your browser, such as:
- IP address
- Browser type
- Device type
This is done for security, troubleshooting and system operation.
2.6 Systems and Plugins That Process Data
The following systems may process personal data to the extent necessary:
- WooCommerce (order and customer data)
- Klaviyo (newsletters and email distribution)
- Ultimate Member (account creation and login)
- Easy WP SMTP (system emails)
- PDF Invoices & Packing Slips (packing slips)
- EU/UK VAT Validation Manager (VAT number validation)
- Hosting provider and technical service partners
3. Purposes of Processing
We process personal data for the following purposes:
- Fulfilling and delivering your order
- Billing and compliance with accounting and bookkeeping legislation
- Customer service and communication
- Administration of customer accounts
- Sending newsletters (only with your consent)
- Operation, maintenance and security of the website
- Prevention of misuse and fraud
- Compliance with applicable legislation
4. Legal Basis
We process personal data on the following legal bases:
- Performance of a contract (GDPR Art. 6(1)(b))
- Legal obligations (GDPR Art. 6(1)(c))
- Consent (GDPR Art. 6(1)(a))
- Legitimate interests (GDPR Art. 6(1)(f)), e.g. for security and site operation
You may withdraw your consent at any time.
5. Data Retention
We retain personal data in accordance with the following:
- Order and invoice data: 5 years pursuant to Danish bookkeeping legislation
- Account data: as long as the account remains active
- Newsletter data: until you unsubscribe
- Customer service enquiries: until the enquiry is resolved
6. Disclosure of Personal Data
We only disclose personal data when necessary:
- Payment service providers
- Shipping provider: GLS
- Hosting provider: Simply
- IT service partners
- Klaviyo (newsletter distribution)
- Accounting system and bookkeeping services
All processors act only under our instructions and may not use the data for their own purposes.
Transfers of personal data outside the EU/EEA only occur where a valid legal transfer basis exists, such as the EU Standard Contractual Clauses (SCC).
7. Your Rights
You have the right to:
- Access your personal data
- Have inaccurate data corrected
- Have data deleted
- Restrict processing
- Data portability
- Object to processing, including marketing
You can exercise your rights by contacting us at info@houseofneedlework.com.
You have the right to file a complaint with the Danish Data Protection Agency: www.datatilsynet.dk.
8. Security
We protect personal data using appropriate technical and organisational security measures, including:
- SSL encryption
- Access control
- Limited employee access
- Secure operation with our hosting provider
9. Changes
We may update this privacy policy from time to time. The latest version will always be available on our website.