This Privacy Policy explains how Alma Sereen ("we", "us", "our") collects, uses, and protects the personal data of visitors and customers of almasereen.com. We comply with the EU General Data Protection Regulation (GDPR / AVG) and Dutch privacy law.
Alma Sereen is a small natural haircare brand hand-blending scalp and hair oils in The Netherlands.
We are the data controller for the personal data described in this policy.
We only collect what we need to run the shop and serve you well.
We use only essential cookies and do not run third-party analytics, tracking pixels, or advertising tools. Our hosting provider may log standard technical data (anonymised IP address, browser type, page visited) for security and reliability. See our Cookie Policy for details.
We use your data for the following purposes only:
We do not use your data for profiling, advertising, or share it with marketing partners.
| Activity | Legal basis |
|---|---|
| Order processing | Performance of a contract (Art. 6(1)(b) GDPR) |
| Invoicing & tax records | Legal obligation (Art. 6(1)(c) GDPR) |
| Newsletter | Your explicit consent (Art. 6(1)(a) GDPR) |
| Customer service replies | Performance of a contract / legitimate interest (Art. 6(1)(b) / (f)) |
| Security & fraud prevention | Legitimate interest (Art. 6(1)(f) GDPR) |
We only share your data with the partners we need to deliver our service. We have a written processing agreement (verwerkersovereenkomst) with each one.
| Partner | Purpose | Location |
|---|---|---|
| Stripe | Processing iDEAL and credit-card payments | Dublin, Ireland |
| PostNL | Shipping your order to your address | The Netherlands |
| Netlify | Website hosting (only anonymised technical logs) | United States, under the EU-US Data Privacy Framework |
| Formspree | Sending the monthly newsletter | United States |
We do not sell or rent your personal data to anyone, ever.
All our partners process your data within the EU/EEA wherever possible. Where data is processed outside the EU (e.g. by certain hosting infrastructure), we ensure protection through the EU-US Data Privacy Framework, Standard Contractual Clauses, or another GDPR-approved mechanism.
Under GDPR, you have the right to:
To exercise any of these rights, email us at info@almasereen.com. We respond within 30 days.
We use HTTPS encryption on every page of our website. Payments are processed through Stripe's PCI-DSS certified infrastructure. We store the minimum personal data needed and review our security setup regularly.
We only use essential cookies (such as a session cookie during checkout). We do not use tracking, analytics, or marketing cookies. For full details, see our Cookie Policy.
We may update this policy from time to time, for example when we add new tools or when the law changes. The "Last updated" date at the top reflects the most recent version. Material changes will be communicated through our website.
Questions about your data, this policy, or our practices?
Email: info@almasereen.com
Post: Alma Sereen, Papisland 7, 4337 CX Middelburg, The Netherlands
Or contact the Dutch DPA directly: autoriteitpersoonsgegevens.nl