Privacy Policy

This Privacy Policy explains how Cycle Haven processes personal data in connection with its website and bicycle repair workshop services.

Policy guidance

This overview highlights the principal topics addressed in this notice and directs readers to the relevant support path when further clarification is needed.

Use of information
Handled under this policy framework
User rights
Requests and access options are described below
Support channel

Depending on your location and the applicable law, you may have rights to know what we process, correct inaccurate information, request deletion, limit certain processing, object to certain uses, and receive a copy of your data. We will assess each request in light of the legal basis, the service relationship, and any retention obligations.

Available rights may vary depending on the legal basis and the type of data involved.

To exercise a privacy right, send a clear request describing the data or action concerned. We may ask for information needed to verify your identity and to locate the relevant records. If a request is incomplete or cannot be granted in full, we will explain the outcome in general terms.

Requests are reviewed against identity, scope, and legal retention requirements before action is taken.

We keep personal data only for as long as needed for the relevant purpose, including booking administration, repair records, payment handling, dispute management, and legal compliance. When data is no longer needed, we delete it or anonymise it unless a longer period is required by law or for legitimate recordkeeping.

Retention depends on the purpose of the record and any legal duty to keep it.

If we make material changes, we will update the policy text on the website and may provide additional notice where appropriate. The version in force is the one published at the time of your visit or interaction, unless a later version is stated to apply.

We may revise this policy to reflect legal, operational, or technical changes.
GDPR

GDPR Overview

When GDPR applies, we process personal data on a lawful basis such as performance of a contract, compliance with legal obligations, legitimate interests, or consent where required. We limit processing to what is relevant for workshop operations, website administration, and related communication.

Where GDPR applies, it governs our processing of personal data for users in the European Economic Area.

This section is intended for individuals whose data is protected by GDPR.
GDPR aware

Your GDPR Rights

Where GDPR applies, you may have rights to access, rectify, erase, restrict, or object to processing, and to receive a copy of certain data in a portable format. If processing is based on consent, you may withdraw it for future processing. Some requests may be limited where we must keep data for legal, contractual, or security reasons.

The rights described here apply subject to the conditions and limits set by GDPR.

Contact Information

Email contact
help@grapeshapepractice.click
Telephone contact
+46 70 640 02 20
Postal address
Florettgatan 16, 25466 Helsingborg
Privacy contact
Data category

Data We Collect

We may process contact details, bicycle and service information, appointment details, payment-related records, communication content, and technical data such as device or browser information. Where needed for repair assessment, we may also process information you provide about the bicycle’s condition, requested work, and collection or service summary details.

The categories collected depend on the service inquiry, booking, or workshop visit.
Collection source

How We Collect Data

We collect data when you submit an inquiry, make a booking, visit the workshop, communicate with us, approve a quote, or complete payment. We may also receive information from your browser or device through standard website functions and from records created during intake, inspection, repair, quality check, and collection.

Information is obtained directly from users and from normal use of the website and workshop services.
Cookie category

Types of Cookies

We may use session cookies, persistent cookies, and similar technologies. Essential cookies support core site functions, such as form handling and security. Other cookies may help us understand site use, remember preferences, or improve service performance. Non-essential cookies are used only where permitted.

Cookie use is limited to essential operation, basic analytics, and preference handling where enabled.
User control

Cookie Controls

We use standard browser and device controls to manage cookies and similar technologies. You can block or delete cookies through your browser settings, although some site functions may not work as intended if essential cookies are disabled. Preference choices may need to be renewed if settings are cleared.

Cookie settings can be adjusted through browser controls and, where available, site preferences.
01
Processing purpose

Purposes of Processing

We use personal data to respond to inquiries, manage bookings, receive and hand over bicycles, inspect and repair bicycles, prepare quotes, record approvals, arrange payment, provide service summaries, handle follow-up communication, maintain business records, secure the website, and meet legal or accounting requirements. We may also use limited technical data to keep the website functioning and to understand basic usage patterns.

Processing is limited to workshop operations, website administration, and related legal obligations.
02
Sharing partners

Service Providers

We may share personal data with payment providers, communication tools, website hosting or technical support providers, and other service partners that help us operate the workshop and website. These parties may process data only for the agreed purpose and are expected to handle it under appropriate confidentiality and security obligations.

Service providers receive only the information needed to perform their assigned tasks.
03
Legal basis

Legal Disclosure

We may disclose personal data when required to comply with law, court orders, tax or accounting obligations, or lawful requests from public authorities. We may also share information where necessary to protect our rights, prevent fraud, or respond to a safety or security issue.

Disclosure to public authorities is limited to situations where a legal duty exists.