Käyttöehdot

// GLOBAL DATA PRIVACY STANDARD // REGULATORY SPECIFICATION

Global Privacy Policy

DOCUMENT ID: CB-POL-PRIVACY-V5.2 • LAST UPDATED: 2025 • CONTROLLER: CASEBOB SWEDEN

At CASE·BOB, we engineer protective phone hardware and treat your personal data with equivalent technical rigor. This Privacy Policy details how we capture, process, and secure your personal telemetry when you access our digital storefront, configure hardware variants, or communicate with our operations desk.

By using our storefront, saving device configurations, or executing purchases, you acknowledge the data governance protocols outlined herein.

1. Data Controller & Corporate Identity

For the purposes of the General Data Protection Regulation (EU/UK GDPR), the California Consumer Privacy Act (CCPA/CPRA), the Personal Information Protection and Electronic Documents Act (PIPEDA, Canada), and the Australian Privacy Act 1988, your Data Controller is:

LEGAL ENTITY: Casebob Sweden
REGISTRATION NUMBER (ORG): 790713-4931 • VAT ID: SE790713493101
REGISTERED OFFICE: Fjällbo Park 23B, 415 74 Göteborg, Sweden
COMMUNICATION DISPATCH: Digital FAQ & Help Center →

2. Categories of Personal Information We Collect

To engineer, verify, and route your orders, we process the following categories of personal information:

  • Direct Identifiers: Legal name, physical delivery address, billing address, contact telephone number, and email address.
  • Commercial & Transactional Records: Purchase histories, variant choices, authorized transaction tokens, order values, and fulfillment states. (Payment card data is encrypted and processed via Level 1 PCI-DSS compliant payment vaults; we never store unencrypted payment card details).
  • Hardware & Local State Telemetry: Active smartphone configuration parameters stored directly in your browser’s local storage (casebob_user_model) strictly used to synchronize catalog filters, display correct case sizing, and prevent dimensional ordering errors.
  • Device & Diagnostic Diagnostics: IP addresses, operating system signatures, browser configurations, approximate regional location, referring web pathways, and clickstream interactions across our interface controls.
  • Customer Inquiries: Communications, tickets, and photographic proof submitted via our help center or return portal.
// STATUTORY LEGAL GROUNDS

3. Lawful Grounds for Processing (GDPR Article 6)

  • Performance of Contract (Art. 6(1)(b)): Necessary to produce customized orders, route parcels with logistics networks, execute digital returns, and administer product replacements.
  • Legitimate Interests (Art. 6(1)(f)): Necessary to protect our checkout infrastructure against fraud, audit site security, maintain device UI continuity, and optimize catalog performance.
  • Legal Obligations (Art. 6(1)(c)): Compliance with statutory legal mandates, including commercial record retention under the Swedish Bookkeeping Act (Bokföringslagen (1999:1078)).
  • Consent (Art. 6(1)(a)): For opt-in direct marketing communications and non-essential analytical tracking pixels (which may be revoked at any time).

4. Categories of Authorized Sub-Processors

We do not sell personal telemetries for monetary gain. Data is transferred strictly to vetted operational sub-processor categories bound by confidentiality and data processing agreements:

  • E-Commerce Platform & Cloud Infrastructure: Enterprise cloud hosting services providing database encryption, checkout processing, and fraud screening.
  • On-Demand Manufacturing & Fulfillment Facilities: Regional fabrication hubs who receive order technical specifications, variant choices, recipient names, and shipping destinations exclusively to produce and package physical units.
  • Postal & Commercial Courier Networks: Global, national, and local delivery carriers tasked with physical parcel transit.
  • PCI-DSS Financial Gateways: Payment processors handling encrypted credit card, debit, digital wallet, and invoice transactions.
  • Statutory Authorities: Regulatory bodies, taxation offices, and law enforcement agencies exclusively pursuant to binding judicial warrants or statutory mandates.
// CLIENT-SIDE STATE & GPC CONTROLS

5. Local Storage, Cookies & Global Privacy Control

We deploy standard HTTP cookies, session tokens, and HTML5 client-side Local Storage:

  • Functional Local Storage Token: We save your active phone model selection directly in your browser (casebob_user_model). This strictly functional token contains zero identifiable personal data and serves exclusively to maintain consistent product variant filtering across page reloads.
  • Transactional Session Cookies: Essential cookies maintaining session continuity, shopping cart persistence, and checkout tokenization.
  • Analytical Trackers: Performance measurement tags deployed to audit browsing flows (governed by your cookie consent preferences).
Global Privacy Control (GPC): Our architecture automatically detects and honors automated Global Privacy Control (GPC) opt-out preference signals. When detected, non-essential tracking and data "sharing" for targeted cross-context marketing are immediately suppressed for that browser session.

6. International Data Transfers

As an international direct-to-consumer brand, data captured in the EEA, UK, Canada, or Australia may be transferred to and processed in Sweden, the United States, or countries where regional fabrication partners operate. Where cross-border transfers occur, we safeguard data through European Commission Standard Contractual Clauses (SCCs), UK International Data Transfer Addenda, or adequacy determinations ensuring equivalent statutory protection.

7. Data Retention Protocols

  • Commercial & Tax Ledgers: Maintained for 7 full fiscal years to satisfy statutory Swedish bookkeeping mandates (Bokföringslagen).
  • Support & Warranty Records: Retained for 24 months following case resolution to administer our 12-Month Hardware Warranty and resolve subsequent claims.
  • Marketing Telemetries: Retained until affirmative consent is revoked or an unsubscribe instruction is logged.
// STATUTORY TERRITORIAL ADDENDUM

8. Your Territorial Privacy Rights

A. European Union (EEA) & United Kingdom Residents (GDPR)

You maintain the right to Access (Art. 15), Rectification (Art. 16), Erasure ("Right to be Forgotten", Art. 17), Restriction of Processing (Art. 18), Data Portability (Art. 20), and Objection (Art. 21). You retain the right to lodge complaints with your competent supervisory authority. In Sweden, this is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, www.imy.se.

B. United States Residents (CCPA/CPRA & State Privacy Laws)

Residents of California and other states with comprehensive data privacy legislation maintain specific statutory rights:

  • Notice at Collection: We collect identifiers, commercial purchase records, and device diagnostics for business fulfillment purposes.
  • No Sale of Personal Information: We do not sell personal data for monetary compensation. We do not use or disclose Sensitive Personal Information (SPI) for inferring consumer characteristics.
  • Right to Opt-Out of Targeted Advertising: You may opt out of automated advertising pixels or data sharing via our Opt-Out Portal or by enabling GPC.
  • Non-Discrimination: Exercising your privacy rights will never result in price penalties or degraded service tiers.
C. Canadian & Australian Residents

Pursuant to Canada's PIPEDA (and Quebec Law 25) and Australia's Privacy Act 1988 (including the Australian Privacy Principles, APP 8), you have the right to access and correct your personal information. Transfers to regional manufacturing sub-processors are governed by strict contractual safeguards ensuring equivalent confidentiality.

9. Protection of Minors

Our storefront is not directed toward children under 16 years of age. We do not knowingly capture or process personal telemetries belonging to minors. If a parent or legal guardian identifies that an unauthorized minor has transmitted personal data to our system, contact our desk for an expedited data purge.

10. Technical & Organizational Security Safeguards

We deploy industry-grade defenses including end-to-end TLS 1.3 encryption, role-based administrative access barriers, and isolated cloud infrastructure environments. While we maintain rigid technical standards, no internet-based data transmission or storage architecture can guarantee absolute mathematical invulnerability.

// FORMAL COMPLIANCE DESK

11. Inquiries, Data Requests & Governing Law

To exercise your statutory privacy rights (Access, Erasure, Correction, or Portability), or to appeal a prior data determination:

  • Digital Dispatch: Submit a verified ticket through our operations desk at casebob.com/pages/faq-help-center.
  • Postal Inquiries: Casebob Sweden, Attn: Data Protection Desk, Fjällbo Park 23B, 415 74 Göteborg, Sweden.

// JURISDICTION NOTICE: This Privacy Policy and any data disputes arising hereunder are governed exclusively by the laws of Sweden and adjudicated within the competent courts of Sweden or authorized European supervisory tribunals.