1. About this policy
This policy explains what happens to personal data in connection with smithchevyland.com. It covers the website itself, the contact form, and any email you choose to send us. It is written to meet the requirements of the EU General Data Protection Regulation (GDPR), which applies in Norway through the Norwegian Personal Data Act (personopplysningsloven), and it is addressed primarily to visitors in Norway and the wider European Economic Area.
We have tried to keep this document free of legal padding. If anything here is unclear, write to [email protected] and we will explain it in plain language.
2. Who is responsible for your data
The data controller for this website is:
Matvii Bereza
3 Stratonavtiv Street
Kyiv, Ukraine, 02000
Email for privacy matters: [email protected]
General enquiries: [email protected]
We have not appointed a Data Protection Officer. We are not required to have one, because we do not carry out large-scale monitoring or process special categories of data on any significant scale. Privacy questions go directly to the address above and are answered by the controller.
3. What this website does and does not collect
This point matters more than anything else in this policy, so we state it first and plainly.
The website itself has no back end and stores nothing about you. There is no user account system, no shopping basket, no order database, no newsletter list, no analytics, no advertising pixels, no tracking scripts, and no third-party embeds. Nothing you type into a page is transmitted to a server that we control.
The contact form does not submit data to us. When you fill in the form and press the send button, your browser opens your own email program with a message already drafted. Nothing leaves your device until you personally press send in that program, and at that moment the message travels through your own email provider, not through this website. If you close the draft without sending it, we never see it and never know it existed.
The same applies to the enquiry buttons on product pages: they prepare a message for you to send yourself.
3.1 Data we receive when you email us
Once you send an email, we receive what an email normally carries:
- your name, if you give it or if it appears in your email address
- your email address
- the subject line and the full text of your message
- anything you attach
- routine technical headers added by your email provider
We also receive this if you write to us directly without using the form.
3.2 Server log data
The website is served by a hosting provider. Like almost all web servers, that provider records basic technical information about each request, typically the requesting IP address, the date and time, the page or file requested, the HTTP status code, and the browser’s user-agent string. These logs exist for security and for keeping the server running. They are generated by the hosting infrastructure, not by any script we wrote, and we do not combine them with anything else or use them to build a profile of you.
3.3 What we never collect
We do not collect payment card details, bank details, national identity numbers, health data, biometric data, location data beyond whatever a raw IP address implies, or any of the special categories of data listed in Article 9 GDPR. We do not buy personal data from data brokers, and we do not enrich what you send us with data from other sources.
4. Why we use your data, and on what legal basis
We only have two real processing activities, and both are set out below.
Answering your message. When you email us, we read your message and reply. The legal basis is our legitimate interest under Article 6(1)(f) GDPR in responding to people who contact us, and if your message is a step towards a possible transaction, Article 6(1)(b) as pre-contractual steps taken at your request. We consider this processing entirely expected: you wrote to us precisely so that we would read and answer.
Keeping the site available and secure. Server logs are processed on the basis of legitimate interest under Article 6(1)(f), specifically our interest in operating the site, diagnosing faults and detecting abuse such as automated scanning or denial-of-service attempts.
If we ever need to keep correspondence to defend a legal claim, the basis would be Article 6(1)(f) as well, and where a law requires us to retain something, Article 6(1)(c).
We do not rely on consent for anything, because we do not do anything that would require it. There is consequently no consent for you to withdraw.
5. How long we keep things
Correspondence. We keep email threads for as long as the conversation is live, and then for up to twenty-four months afterwards, so that we can pick up a thread if you come back to us about the same subject. After that we delete them. If you ask us to delete a thread sooner, we will, unless we have a specific legal reason to keep it, in which case we will tell you what that reason is.
Server logs. Retention is set by the hosting provider and is typically between fourteen and ninety days, after which logs are rotated and overwritten automatically.
We do not keep data indefinitely, and we do not maintain an archive of visitors.
6. Who else sees your data
Our hosting provider processes server logs as part of delivering the site, and acts as a processor on our behalf under Article 28 GDPR.
Our email provider processes the messages you send us, in the same way that your own email provider does.
That is the complete list. We do not sell personal data, we do not share it with advertisers, we do not pass it to data brokers, and we do not disclose it to anyone else except where we are legally compelled to do so by a competent authority, in which case we will inform you unless we are legally prohibited from doing so.
7. Transfers outside the EEA
This is a point we want to be straightforward about rather than bury.
The controller is based in Ukraine. Ukraine has not received an adequacy decision from the European Commission, which means that when you email us from Norway or elsewhere in the EEA, your message is read in a country outside the EEA that is not covered by an adequacy finding.
Where the transfer is not simply the necessary consequence of you choosing to contact us, we rely on the appropriate safeguards in Chapter V GDPR, and in particular on Standard Contractual Clauses with our providers. Where you initiate contact yourself, the transfer is also necessary for the pre-contractual steps you have requested under Article 49(1)(b).
In practice the exposure is limited: we hold a message you chose to write, and nothing more. But you should know where it goes, and now you do. If you would rather not have your data read outside the EEA, please do not use the contact form or email us.
8. Security
The website is served over HTTPS. It loads no third-party scripts, no external fonts, no advertising code and no analytics, which removes an entire category of risk that most sites carry. A strict Content Security Policy is applied, and additional security headers are set at the HTTP level.
Email correspondence is protected by the ordinary account security measures of our email provider, including strong authentication. No transmission over the internet is ever completely secure, and we do not claim otherwise, but the amount of personal data involved here is deliberately small.
9. Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Access. You can ask whether we hold data about you and receive a copy of it.
- Rectification. You can ask us to correct data that is wrong or incomplete.
- Erasure. You can ask us to delete your data. Because the only data we hold is correspondence you sent us, this is usually straightforward.
- Restriction. You can ask us to stop using your data while a dispute about it is resolved.
- Portability. You can ask for the data you provided in a structured, commonly used, machine-readable format where the processing is based on contract or consent.
- Objection. You can object at any time to processing based on legitimate interest. If you object, we will stop unless we can show compelling legitimate grounds that override your interests.
To exercise any of these, write to [email protected] and describe what you want. We will respond within one month. If your request is unusually complex we may extend that by a further two months, and if we do, we will tell you within the first month and explain why. There is no charge, unless a request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse, and we will explain our reasoning either way.
We may need to confirm your identity before acting, but we will not demand more identification than is proportionate to the request.
10. Complaints
If you believe we have handled your personal data unlawfully, you have the right to complain to a supervisory authority.
In Norway, the supervisory authority is Datatilsynet (the Norwegian Data Protection Authority), Postboks 458 Sentrum, 0105 Oslo, www.datatilsynet.no.
If you are elsewhere in the EEA, you may complain to the supervisory authority in your country of residence, your place of work, or the place where you believe the infringement occurred.
You are also welcome to raise the matter with us first. We would rather hear about a problem and fix it than learn about it from a regulator, but you are under no obligation to come to us before going to Datatilsynet.
11. Children
This website is intended for adults. We do not knowingly collect personal data from children under the age of 15, which is the age of digital consent under Norwegian law. If you believe a child has sent us personal data, write to [email protected] and we will delete it.
12. Automated decision-making and profiling
We do not carry out automated decision-making that produces legal or similarly significant effects, and we do not profile visitors. There is no algorithm here that sorts you into a category, scores you, or decides anything about you.
13. Cookies
This website does not set cookies and does not use local storage or any similar technology for tracking. Because there are no non-essential cookies, no consent banner is shown. Our Cookie Policy explains this in more detail and tells you how to manage cookies in your browser generally.
14. Changes to this policy
If we change how we handle personal data, we will update this page and change the date at the top. Where a change is significant, we will describe what changed rather than quietly replacing the text. This page is the current version; there is no archive of earlier versions, so if a specific wording matters to you, keep your own copy.
15. How to contact us
Privacy questions and rights requests: [email protected]
General enquiries: [email protected]
Legal notices: [email protected]
Postal address:
Matvii Bereza, 3 Stratonavtiv Street, Kyiv, Ukraine, 02000
We read email Monday to Friday, 09:00–18:00 EET.