PRIVACY POLICY
In short
- We collect what we need to take your order, deliver it, get paid, and help you afterwards. Nothing beyond that.
- We do not sell your data, and we do not share it with anyone who is not helping us run the shop.
- We only place cookies beyond the strictly necessary ones if you agree, and refusing is as easy as agreeing.
- You can ask us at any time what we hold about you, have it corrected, or have it deleted.
- Email info@oblia.eu for anything on this page.
The rest of this page sets out the detail.
Who we are
OBLÍA, trading as OBLÍA is responsible for the personal data described in this policy. You can reach us at info@oblia.eu. Our supervisory authority is the Dutch Autoriteit Persoonsgegevens.
What we do with your data
Your order. To take and deliver your order we use your name, delivery and billing address, email address, telephone number and the details of what you bought. We do this to perform our contract with you. We share what is needed with our webshop platform, our hosting provider and the carrier delivering to you. We keep order records for seven years, because Dutch tax law requires it.
Payment. Our payment provider handles your payment. We see your name, the amount, the method used and a transaction reference. We never receive or store your full card details. This is part of performing our contract with you, and the transaction record is kept for seven years for the same tax reason.
Preventing fraud. Our payment provider assesses transactions for signs of fraud, using order details and technical signals such as your IP address. We do this because we have a legitimate interest in not dispatching goods against stolen cards or payments that will be reversed. These records are kept for as long as a payment can still be disputed or reversed, and then deleted.
Answering you. If you contact us we use your message and your contact details to answer. Where it concerns an order, this is part of our contract with you; otherwise we rely on our legitimate interest in responding to people who write to us. We keep correspondence for as long as it may still be relevant to your order or a possible dispute, and then delete it.
Your account, if you create one. We store your email address, a secured version of your password, your addresses and your order history so that you do not have to enter them again. This is part of our contract with you. If you delete your account we remove it, other than data we must keep for tax purposes.
Returns and withdrawals. If you withdraw from a purchase we record your declaration, the date and time you sent it, the order details, and what we received back including photographs of the returned goods. We do this because the law requires us to handle withdrawals correctly and to be able to show that we did, and because it forms part of our contract with you. These records are kept with the order record for seven years.
Complaints about a product. If you report a fault we use your order details, your description and any photographs to assess and resolve it. This is part of our contract with you and of our statutory obligations. We keep the file for as long as the claim is open and for a reasonable period afterwards in case it revives.
Product safety. We keep a limited record linking your contact details to the product and production batch you received, so that we can reach you if a safety issue is ever identified. The law obliges us to be able to do this, and we keep this record for ten years from the date of sale.
Accounts and tax. We keep invoices, order data and payment data for seven years from the end of the financial year, as Article 52 of the Dutch General Tax Act requires. Our accountant and, where required, the tax authorities have access.
Our newsletter. If you sign up, we use your email address and, so that we can see whether our emails are useful, whether you opened or clicked them. We do this on the basis of your consent. We keep sending until you unsubscribe. After you unsubscribe we keep a record of that fact, so that we do not email you again by mistake.
Website security. Our systems log technical data including IP addresses, requests and errors. We do this because we have a legitimate interest in keeping the shop available and protected against attacks and abuse. Logs are kept on a short rolling cycle and then overwritten.
Analytics and advertising. We do not use analytics or advertising tools. We do not track you across other websites, and we do not build advertising profiles.
Where we rely on legitimate interests
In three places above we rely on our legitimate interests rather than on your consent or on our contract with you, and we have weighed our interest against your rights in each case.
For fraud prevention, our interest is in not losing goods and money to stolen cards and reversed payments. The data used is what arises in the course of taking the payment; we do not build profiles or use it for marketing. A flagged order leads to a manual check and, if necessary, contact with you — not to an automatic refusal.
For answering enquiries that are not about an order, our interest is simply in being able to reply. We use only what you send us.
For security logging, our interest is in keeping the shop running and protecting it and our customers. Logs contain IP addresses, but they are used only for security and troubleshooting, are not combined with your account for any other purpose, and are deleted quickly.
You can object to any of these at any time. See “Your rights” below.
Who receives your data
We share personal data only with organisations that help us run the shop, and only with what they need for that. In categories, these are: our webshop platform and hosting provider; our payment provider; the carriers who deliver orders and handle returns; our email and newsletter provider; and our accountant. We do not use analytics or advertising providers, and we do not use an external IT provider.
Where these organisations process data on our behalf, we have a written data processing agreement with them as the GDPR requires. Carriers, payment providers and our accountant also act in their own right for parts of what they do, under their own privacy policies.
We do not sell personal data. We disclose it to authorities only where we are legally required to.
If you want to know which specific organisations we use at any moment, email info@oblia.eu and we will tell you.
Data outside Europe
We prefer providers that store data within the European Economic Area, and most of the data described here stays in Europe.
Our website and all order data are hosted on servers in Germany. Our payment provider is established in the Netherlands, and our carriers operate within the EU.
We do not transfer your personal data outside the European Economic Area.
Marketing emails
We send our newsletter only to people who have asked for it, and nothing is pre-ticked anywhere on our site.
If you have bought from us, we may email you about similar products of our own. Every message contains a link to unsubscribe, which works immediately and costs you nothing. You can also unsubscribe by emailing info@oblia.eu.
Cookies
We use cookies and similar techniques. Anything that is not strictly necessary to make the site work is placed only after you have agreed to it.
Refusing is as easy as agreeing, nothing is pre-ticked, and refusing does not stop you from buying anything. We record your choice and when you made it. You can change or withdraw it at any time through the cookie settings link in the footer of our site.
Automated decisions
We do not make decisions about you by purely automated means that have legal or similarly significant effects. Our payment provider applies automated checks to transactions, which can result in a payment being declined. Where one of your orders is flagged, a person here looks at it before we refuse it, and you can contact us to have it reviewed.
Your rights
You can ask us for a copy of the data we hold about you, ask us to correct it if it is wrong, and ask us to delete it where we no longer need it. You can ask us to restrict what we do with your data while a question about it is being sorted out. You can object to processing based on our legitimate interests, and you can object to direct marketing at any time, always and without needing a reason. You can ask for the data you gave us in a machine-readable format. Where we rely on your consent, you can withdraw it at any time, which does not affect what we did lawfully before.
Email info@oblia.eu to exercise any of these. We reply within one month, and there is no charge. If a request is unusually complex we may need longer, and we will tell you within that first month if so.
If you are not satisfied you can complain to the Autoriteit Persoonsgegevens, which supervises us, or to the data protection authority in the EU country where you live or work.
Children
Our products are not aimed at children and we do not knowingly collect their data. The age at which someone can consent for themselves online varies between EU countries, from 13 to 16. If you think a child has given us personal data, email info@oblia.eu and we will delete it.
Security
We take appropriate technical and organisational measures to protect your data. These include encrypted connections across the site and at checkout, limiting access to the people who need it, and written agreements with the organisations that handle data for us. We never have access to your full card details.
If a data breach happens we assess it immediately, report it to the Autoriteit Persoonsgegevens within 72 hours where it is likely to put your rights at risk, and contact you directly where the risk to you is high.
Changes
We update this policy when what we do changes. The version and date are at the bottom of this document, and we will tell you about any change that materially affects you.
Version 1.0 · 02-08-2026
