Privacy Policy

Last updated: February 27, 2026

1. Identity of the Data Controller

In accordance with the provisions of Regulation (EU) 2016/679 (GDPR), Organic Law 3/2018 (LOPDGDD), and Law 34/2002 on Information Society Services and Electronic Commerce (LSSI-CE), the following is hereby disclosed:

Data controller: VIKADI AB
Registration number: 559297-7796
Trade name: Wheelyshop
Website: www.wheelyshop.es
Contact email for data protection matters: info@wheelyshop.se

VIKADI AB is responsible for processing the personal data collected through the website and within the scope of the commercial activity carried out in Spain.

2. Scope of Application

This policy applies to:

3. Purposes of Processing, Legal Basis, and Retention Periods

3.1 Order Management and Contract Performance

Data processed: name, address, email, phone number, billing details, payment information, order history.
Legal basis: performance of the contract (art. 6.1.b GDPR).
Retention period: for the duration of the contractual relationship and thereafter for the periods required by tax and accounting regulations, as well as during the legal warranty period (3 years).

Providing this data is mandatory in order to formalize the contract. If it is not provided, the order cannot be processed.

3.2 Creation and Maintenance of a User Account

Data processed: name, email, order history.
Legal basis: performance of the contract and legitimate interest (art. 6.1.b and 6.1.f GDPR).
Retention period: until the user requests deletion of their account.

3.3 Customer Service and Support

Data processed: identifying data, communications, support cases, and serial number where applicable.
Legal basis: performance of the contract and legitimate interest.
Retention period: up to 1 year after the case is resolved, unless additional legal obligations apply.

3.4 Compliance with Legal Obligations

Data processed: billing details and purchase history.
Legal basis: legal obligation (art. 6.1.c GDPR).
Retention period: in accordance with current tax and accounting regulations (generally up to 6 years or the applicable legal period).

3.5 Commercial Communications

Data processed: email and/or phone number.
Legal basis: consent (art. 6.1.a GDPR) or legitimate interest under art. 21 LSSI-CE in the case of existing customers.
Retention period: until consent is withdrawn or an objection is raised.

The data subject may withdraw their consent at any time.

3.6 Web Analytics, Advertising, and Profiling

We use tools such as:

  • Meta Pixel
  • Google Analytics
  • Google Ads Conversion Tracking

These tools allow us to analyze browsing behavior, measure conversions, and display personalized advertising.

Legal basis: prior consent (art. 6.1.a GDPR and art. 22.2 LSSI-CE).
Non-essential cookies are activated only after the user gives consent through the corresponding banner.

You can withdraw your consent at any time from the cookie settings.

4. Automated Decisions and Fraud Prevention

In certain cases, automated fraud detection systems associated with Shopify Payments (Stripe infrastructure) may be used in order to prevent fraudulent transactions.

These assessments may involve automated decisions that affect the validation of the order.

Legal basis: performance of the contract and legitimate interest (art. 6.1.b and 6.1.f GDPR).

The data subject may request human intervention and express their point of view in the event of disagreement.

5. Recipients of the Data

The following may have access to personal data:

  • Shopify (e-commerce platform).
  • Shopify Payments (Stripe infrastructure).
  • Logistics and shipping providers.
  • Technology and marketing providers.
  • Meta Platforms and Google (analytics and advertising services).
  • Tax and accounting advisors.

All providers act as data processors in accordance with article 28 GDPR and have signed the corresponding data processing agreements, including the Shopify DPA.

6. International Transfers

Some providers may be located outside the European Economic Area.

In such cases, transfers are carried out through:

  • Adequacy decisions of the European Commission, or
  • Standard Contractual Clauses (SCC), or
  • Additional safeguards in accordance with the GDPR.

7. Rights of the Data Subject

The data subject may exercise:

  • The right of access
  • The right to rectification
  • The right to erasure
  • The right to restriction
  • The right to object
  • The right to data portability
  • The right not to be subject to automated decisions where applicable

You can exercise your rights by sending a request to:

info@wheelyshop.se

You may also file a complaint with the:

Spanish Data Protection Agency (AEPD)
www.aepd.es

8. Security Measures

Appropriate technical and organizational measures are applied, including:

  • SSL/HTTPS encryption
  • Restricted access control
  • Backups
  • Internal security policies

9. Cookies

The use of cookies is governed by the corresponding Cookie Policy.

Non-essential cookies require prior consent in accordance with the LSSI-CE.

10. Modifications

This policy may be updated to adapt to regulatory or technical changes.

In the event of substantial changes, users will be duly informed.