Legal

Privacy Policy

Last updated September 2026

This policy explains what personal data Enkel Step collects, why we collect it, who we share it with, how long we keep it, and the rights you have over it. It is written for customers in Denmark and the rest of the European Union.

Denne side findes kun på engelsk.

1. Who is responsible for your data

ENKEL SHOP LTD, a company registered in Hong Kong SAR under company number 12345679X and trading as Enkel Step, is the data controller for the personal data described in this policy. That means we decide why and how it is used.

Suite C, Level 7World Trust Tower50 Stanley StreetHong Kong

For anything to do with your personal data — a request, a question or a complaint — write to privacy@enkelstep.com. That inbox is read by the person responsible for data protection here. For anything about an order, use hello@enkelstep.com or our contact form. You can also write to us at the postal address above.

2. Our representative in the European Union

We are established outside the European Union but we offer goods to people inside it. Article 27 of the GDPR requires us to appoint, in writing, a representative in the EU. Our representative acts as a point of contact for you and for data protection authorities on all questions about how we process personal data. Appointing them does not reduce our own responsibility.

Our EU representative is:

[TO CONFIRM: name of our EU Article 27 representative][TO CONFIRM: full postal address of the representative, in an EU member state][TO CONFIRM: contact email address for the representative]

You may contact our representative instead of us on any matter covered by this policy, in your own language.

3. Data protection officer

We have not appointed a data protection officer. Under Article 37 of the GDPR one is only required where an organisation is a public body, where its core activity is large-scale regular monitoring of people, or where it processes special category data at scale. None of those apply to a shop of our size, so the appointment is not mandatory. We would rather say that plainly than leave you guessing. Data protection questions are handled by the contact named in section 1.

4. Which law applies

The GDPR applies to us under Article 3(2) because we offer goods to people in the European Union, even though we are established in Hong Kong SAR. If you are in Denmark, the Danish Data Protection Act applies alongside it, and Datatilsynet is your supervisory authority. See section 15.

As a company registered in Hong Kong SAR, we are also subject to the Personal Data (Privacy) Ordinance there. Where the two sets of rules differ, we apply whichever gives you more protection.

5. What we collect, and where it comes from

Most of this comes from you directly, when you browse, order or write to us. Where it comes from somewhere else, we say so.

  • Identity and contact details — name, email address, phone number, billing address and delivery address. From you, at checkout or in your account.
  • Order information — what you bought, order value and currency, delivery method, order history, returns and refunds. Generated when you order.
  • Account information — your email address, a password we only ever store hashed, and any saved addresses. From you, if you choose to create an account. You can buy without one.
  • Payment information — the card form at checkout is served by our payment processor, and your card number goes to them directly. We receive confirmation that payment succeeded and limited details such as the card brand and the last four digits. We never see or store your full card number.
  • Correspondence — the name, email address, order number and message you send through our contact form, and any email or message that follows. From you.
  • Technical and usage data — IP address, browser and device type, referring website, pages viewed, and the approximate country your IP suggests, which we use to show the right region, currency and language. Collected automatically by our servers and by our analytics, described in section 11.
  • Marketing preferences — whether you have consented to marketing email, and when you gave or withdrew that consent.

We do not collect special category data — health, ethnicity, religion, political opinions, biometrics and the like. Please do not send it to us in a message. We do not buy personal data from data brokers, and we do not build advertising profiles.

6. Why we use your data, and our lawful basis

The GDPR requires a lawful basis for every use of your data. Ours are set out below, paired with the purpose they cover.

  • Taking and fulfilling your order — processing payment, arranging delivery from our warehouse, keeping you updated, handling returns and refunds, and answering questions about an order. Lawful basis: performance of a contract, Article 6(1)(b).
  • Running your account — signing you in, saving your addresses, showing your order history. Lawful basis: performance of a contract, Article 6(1)(b).
  • Tax, accounting and customs records — keeping invoices, payment records and export documents for the period the law requires. Lawful basis: legal obligation, Article 6(1)(c).
  • Preventing fraud and abuse — screening orders and payments for fraud, and rate-limiting our contact form so it cannot be flooded. Our legitimate interest is protecting the shop, our customers and our card processing from loss and misuse; we consider this expected and low-impact, and we do not use it to profile you. Lawful basis: legitimate interests, Article 6(1)(f).
  • Keeping the site working and secure — holding your basket and session, applying your region and currency, diagnosing faults, defending against attack. Lawful basis: legitimate interests, Article 6(1)(f) — running a functioning, secure shop. For the cookies that do this, see section 11.
  • Understanding how the site is used — aggregate visitor numbers, which pages are read, which sites refer people to us. Our legitimate interest is knowing whether the shop works well enough to improve it. We use cookieless analytics that produce counts rather than individual profiles, which is why we rely on this basis rather than consent; see section 11. Lawful basis: legitimate interests, Article 6(1)(f).
  • Marketing email — see section 7. Lawful basis: consent, Article 6(1)(a), or legitimate interests for our own similar products following a purchase.
  • Establishing or defending legal claims — including disputes about an order or a chargeback. Lawful basis: legitimate interests, Article 6(1)(f) — protecting our legal position.

Where we rely on legitimate interests, we have weighed our interest against your rights and freedoms and concluded that our use does not override them. Ask us at privacy@enkelstep.com and we will explain the assessment. You can object at any time — see section 14.

We do not sell your personal data.

7. Marketing

We do not currently operate a marketing mailing list. The email we send today is transactional: order confirmations, dispatch notices, return and refund updates, and replies to your messages. You cannot unsubscribe from those while an order is live, because we need them to perform the contract.

If we start sending marketing email, we will ask for your consent first, or rely on the narrow exception that lets us email an existing customer about our own similar products. Either way, every marketing email will carry an unsubscribe link, we will honour it, and you can also tell us at privacy@enkelstep.com. Withdrawing consent is as easy as giving it, and does not affect anything we did before you withdrew it.

Your right to object to direct marketing is absolute. If you object, we stop — we do not weigh it against anything.

8. Automated decisions and profiling

We do not make decisions about you by automated means alone that produce legal effects for you or similarly significantly affect you. Our payment processor runs automated fraud checks on transactions, which can cause a payment to be declined; where that happens you can contact us and a person will look at it. You have the right under Article 22 not to be subject to a solely automated decision of that kind, to ask for human involvement, to state your point of view and to contest the outcome.

9. Who we share your data with

We share data only with organisations that need it to run the shop, and only for that purpose. Our processors act on our written instructions under a contract that meets Article 28, and are bound by confidentiality.

  • Payment processors — to take payment and screen for fraud. Our checkout supports card payments and PayPal. They handle your card details as independent controllers under their own privacy notices, not on our instructions. [TO CONFIRM: which payment providers are live at launch, their legal entities and links to their privacy notices.]
  • Warehouse and fulfilment — our warehouse in Copenhagen, which picks, packs and dispatches your order. [TO CONFIRM: name and legal entity of the fulfilment operator in Copenhagen.]
  • Shipping carriers — your name, delivery address, phone number and email, so they can deliver your parcel and contact you about the delivery. [TO CONFIRM: names of the carriers we use.]
  • Hosting and infrastructure providers — who run this website, the store platform behind it, and our databases and backups. [TO CONFIRM: names and hosting locations of our website host and store platform host.]
  • Resend — our email provider, which delivers order emails and passes on contact-form messages. It processes your name, email address, order number and message content.
  • Rybbit — our website analytics, hosted on servers in the EU. See section 11.
  • Upstash — where configured, a hosted key-value store that holds short-lived counters against your IP address so the contact form can be rate-limited.
  • Customs and tax authorities — where required for an international shipment or a tax filing.
  • Professional advisers and authorities — our accountants and lawyers, and any authority we are legally obliged to disclose to, or where disclosure is needed to establish or defend a legal claim.

If our business is sold or reorganised, customer data may pass to the buyer. It stays subject to this policy, and we will tell you if the controller changes.

10. Sending data outside the EU

Two different things happen here, and they are worth keeping apart.

Data reaching us in Hong Kong SAR. We are established in Hong Kong SAR, which does not have an adequacy decision from the European Commission. When your order and account data reaches us, that is a restricted transfer under Chapter V of the GDPR. We rely on the European Commission's Standard Contractual Clauses, backed by a transfer risk assessment of the law and practice in Hong Kong SAR and by supplementary measures including encryption in transit, encryption at rest and strict access control. We will send you a copy of the clauses and a summary of the assessment on request, with commercial terms redacted. [TO CONFIRM: SCCs executed with each processor and the transfer risk assessment completed and dated, before launch.]

Analytics data. Rybbit is hosted on servers in the EU. Our analytics data stays in the European Union and is not transferred out of it. This is separate from the point above and is not affected by it.

Some of our other providers operate internationally. Where they transfer personal data out of the EEA, we require an adequacy decision, Standard Contractual Clauses or another Article 46 safeguard.

11. Cookies and analytics

We use a small number of first-party cookies that are strictly necessary for the shop to work — signing in, keeping your basket, and remembering the region, currency and language you chose. Under the Danish rules implementing the ePrivacy Directive, cookies strictly necessary to provide a service you have asked for do not need consent. Everything in the list below falls in that category, which is why you are not shown a consent banner. If we ever add a cookie that is not strictly necessary, we will ask for your consent before setting it and update this policy.

  • _medusa_jwtKeeps you signed in to your account. Expires after 7 days.
  • _medusa_cart_idRemembers your basket between visits. Expires after 7 days.
  • _medusa_cache_idCaches your region's catalogue so pages load faster. Expires after 24 hours.
  • _medusa_region_idRemembers the region and currency you chose. Expires after 1 year.
  • _medusa_localeRemembers the language you chose, or the one detected from your browser. Expires after 1 year.

We set no advertising cookies, no social media pixels, and nothing that tracks you across other websites. You can block or delete cookies in your browser settings, but the basket, checkout and sign-in will not work without them.

For analytics we use Rybbit, a privacy-focused product hosted on servers in the EU. It is configured to run without cookies and without any identifier stored on your device. It gives us aggregate figures — how many people visited, which pages were read, which site referred them, roughly which country they were in — rather than profiles of individuals, and it does not follow you around the web. Because it sets nothing on your device, it does not require consent under the ePrivacy rules; we rely on legitimate interests for the limited processing involved, and you can object under section 14.

12. How long we keep your data

We keep personal data only as long as we need it, then delete or anonymise it.

  • Order, invoice and payment records 7 years from the end of the financial year in which the order was placed. This covers the 5-year minimum under the Danish Bookkeeping Act and the 7-year record-keeping requirement under Hong Kong SAR tax law. We cannot delete these earlier on request, because we are required by law to hold them.
  • Returns and refunds — kept with the order record. Our return window is 30 days from delivery and transit damage must be reported within 14 days, so an order stays fully live for us well beyond delivery. See our Refund & Returns policy.
  • Account data — while your account is open, and for 24 months after your last activity, after which we close and delete it. You can ask us to delete it sooner.
  • Correspondence24 months after the matter is closed, so we can pick up a follow-up. Messages relating to a dispute are kept until it is resolved and any limitation period has run out.
  • Marketing consent records — for as long as the consent stands, and for 3 years after it is withdrawn, as evidence that we honoured the withdrawal.
  • Fraud and abuse records 12 months, unless we need them for an ongoing investigation or claim.
  • Rate-limiting counters — minutes to hours. They expire on their own.
  • Analytics — aggregate figures only, kept in the EU. [TO CONFIRM: the retention period configured in Rybbit.]

Where we must keep a record for tax but no longer need the rest, we reduce what we hold to the minimum the law requires.

13. How we protect your data

Our measures are practical rather than decorative:

  • all traffic to and from this site is encrypted with TLS, and the session and basket cookies are marked http-only, secure and same-site, so they cannot be read by scripts or sent from another site;
  • account passwords are stored only as salted hashes — we cannot read them, and neither can anyone who obtains the database;
  • card numbers never touch our systems; the card form is served by our payment processor;
  • access to customer data is limited to the people who need it, over individual accounts with multi-factor authentication, and is removed when someone leaves;
  • data is encrypted at rest by our hosting providers, and backups are encrypted;
  • our public form endpoints are rate-limited, and input is validated and escaped before it is used;
  • dependencies are patched and our measures are reviewed at least once a year.

No system is perfectly secure. If a breach is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours of becoming aware of it, and we will tell you directly without undue delay where the risk to you is high.

14. Your rights

Under the GDPR you have the following rights. They are free to exercise, and you will not be treated any differently for using them.

  • Access — to be told whether we hold data about you and to receive a copy of it, with an explanation of how we use it.
  • Rectification — to have inaccurate data corrected and incomplete data completed.
  • Erasure — to have data deleted where we no longer need it, where you withdraw the consent it rested on, or where we have used it unlawfully. This does not extend to records we are legally required to keep, such as invoices.
  • Restriction — to have us pause our use of your data while a dispute about its accuracy or our lawful basis is resolved.
  • Portability — to receive the data you gave us, in a structured, commonly used, machine-readable format, and to have it sent to another controller where that is technically feasible. This applies to data we process by consent or for a contract.
  • Objection — to object to processing based on legitimate interests, including our analytics and fraud prevention. We will stop unless we can show compelling legitimate grounds that override your interests. For direct marketing the right to object is absolute and we will stop immediately.
  • Withdrawing consent — where we rely on consent, you can withdraw it at any time, as easily as you gave it. This does not affect processing carried out before you withdrew.
  • Automated decisions — not to be subject to a decision based solely on automated processing that produces legal effects for you or similarly significantly affects you. See section 8.

How to exercise them. Email privacy@enkelstep.com, use our contact form, or write to the postal address in section 1. You may also go through our EU representative in section 2. Tell us which right you are exercising and, if it helps, which order you mean.

How quickly we respond. Within one month of receiving your request. If the request is complex, or you have made several, we may extend that by up to two further months — we will tell you within the first month if we do, and why. We may need to verify your identity before we act, and we will ask only for what is necessary to do that.

15. Complaints

If you think we have handled your data badly, please tell us first at privacy@enkelstep.com — most things are quicker to fix directly.

You also have the right to lodge a complaint with a supervisory authority, whether or not you come to us first. If you are in Denmark, that is:

Datatilsynet (the Danish Data Protection Agency)Carl Jacobsens Vej 352500 ValbyDenmarkdatatilsynet.dk

If you live elsewhere in the EU, you may complain to the supervisory authority in your country of residence or place of work instead. In Hong Kong SAR, the equivalent body is the Office of the Privacy Commissioner for Personal Data.

16. Children

This shop is for adults. Our Terms of Service require you to be 18 or over to place an order, and we do not knowingly collect data from children. If you believe a child has given us personal data, tell us at privacy@enkelstep.com and we will delete it.

17. Other websites

Our site links to other websites, including our social accounts and our carriers' tracking pages. We are not responsible for their content or their privacy practices. Read their policies before giving them your data.

18. Changes to this policy

We may update this policy as our business or the law changes. The date at the top shows when it was last revised. If a change materially affects how we use your data, we will highlight it on this page and, where the change is significant, tell you by email before it takes effect. Where a change requires your consent, we will ask for it.

19. Contact us

Data protection requests and questions about this policy: privacy@enkelstep.com. Anything about an order: hello@enkelstep.com or our contact form. By post: ENKEL SHOP LTD, Suite C, Level 7, World Trust Tower, 50 Stanley Street, Hong Kong. In the EU, through the representative named in section 2.