Privacy and Data Protection Policy

Bach & Co. takes your privacy and personal data seriously. This policy describes how information is collected, used, protected and shared when you visit the publisher’s website and how applicable data protection legislation, including GDPR, is complied with.

1. Data Controller

Bach & Co. Media ApS
Kasernevej 10
8800 Viborg
Denmark
VAT no. DK45729303
info@bachogco.dk

Bach & Co. Media ApS is the data controller for the processing of your personal data when you visit our website, purchase products, subscribe to our newsletter, enter into agreements with us, or otherwise interact with us.

2. Who we collect data about – and for what purposes

We process personal data about the following groups:

2.1 Website visitors

We collect data about your visit, including IP address, browser information, cookies, and user behavior, for technical operation, statistics, and content improvement.
Legal basis: consent (cookies), legitimate interest (functionality)

2.2 Webshop customers

When purchasing through our webshop, we collect your name, address, email, phone number, and payment information to process and deliver your order.
Legal basis: performance of contract and legal obligation (accounting rules)

2.3 Newsletter subscribers

When you subscribe to our newsletter, we process your name, email address, and optionally your profession to send you news and updates.
Legal basis: consent

2.4 Partners and suppliers

We process contact and payment information about partners and suppliers as part of our cooperation and accounting.

3. Categories of Personal Data

We typically process the following data:

  • Name, address, email, phone number
  • IP address and technical data (browser, device)
  • Order and payment information
  • Cookie and consent preferences

4. Recipients and Data Processors

We use trusted data processors and technical services to handle personal data on our behalf or as part of our hosting environment. All data processors are bound by data processing agreements and act only on our instructions.

Hosting and Email

Newsletter and Forms

Webshop and Payment

Statistics and Marketing

  • Google Analytics
    We use Google Analytics for both statistical purposes and – if you give consent – for marketing optimization, conversion tracking, and campaign improvement.
    Data may be linked to other Google services (e.g., Google Ads) for remarketing.
    Some technical data may be transferred to the USA under the EU–US Data Privacy Framework. Data is processed only with active consent.
    Read Google’s privacy policy
  • Meta-pixel (Facebook/Instagram)
    Vi bruger Meta-pixlen til at måle effekten af annoncer og vise målrettede annoncer på Facebook, Instagram og andre Meta-tjenester.
    Pixlen registrerer IP-adresse, browserdata, sidevisninger og handlinger (fx køb).
    Data sendes til Meta Platforms Inc. (USA) og behandles under EU–US Data Privacy Framework.
    Pixlen aktiveres kun efter aktivt samtykke til markedsføringscookies.
    Læs Metas privatlivspolitik

Design and Fonts

Adobe Fonts
We use Adobe Fonts to render typefaces. Your browser fetches the fonts directly from Adobe’s servers.
Adobe does not collect personal data like IP addresses and does not use cookies in this service. Only anonymous, aggregate font requests are recorded.
Read Adobe’s font privacy policy

Performance and Security (server-side processing)

  • LiteSpeed Cache
    Used for server-side caching to improve speed and user experience.
    Technical data such as IP address and browser data may be temporarily cached for optimization. Data is deleted automatically and not used for profiling.
  • Redis
    Used to cache and improve site performance. In some cases, temporary technical data such as session IDs or login status may be stored.
    No personal data is stored permanently, and access is protected in accordance with GDPR.

5. Data Retention and Deletion

We retain your personal data only as long as necessary to fulfill the purpose for which it was collected or to comply with legal obligations. Afterwards, data is deleted or anonymized.

Type of DataRetention Period
Newsletter DataUntil consent is withdrawn
Order and Purchase Data5 years (Danish Bookkeeping Act)
Contact DataUp to 12 months after last contact unless otherwise agreed
Cookie PreferencesAs defined in Cookiebot and your browser – consent is logged for 12 months
Meta Pixel and Google AnalyticsActivated only with consent. Retention per their respective privacy policies and automatic settings
Caching (LiteSpeed, Redis)Temporary storage of technical data, automatically deleted and not used for personal profiling

6. Your Rights

You have the right to:

  • Access your data
  • Correct inaccurate data
  • Request deletion (where legally permitted)
  • Restrict processing
  • Object to processing
  • Data portability (for consent or contract-based data)
  • Withdraw your consent at any time

Contact us at info@bachogco.dk to exercise your rights.
You can also complain to the Danish Data Protection Agency: datatilsynet.dk

7. Transfers to Third Countries

Stripe, Google, and Meta may in certain cases transfer technical data to the USA. Such transfers take place under the EU–US Data Privacy Framework, which is approved by the EU Commission as a valid transfer mechanism.

8. Security

We protect your data using technical and organizational measures, including access control, encryption, logging, updated software, and data processing agreements.

9. Cookie Consent and Management

We use Complianz to manage and log cookie consent in accordance with the GDPR and Danish cookie regulations. Cookiebot registers and logs your consent and shows an updated overview of cookies used.
You can change or withdraw your consent at any time via the cookie icon at the bottom of the page.
Also read our cookie declaration here

10. Changes

We update this privacy policy regularly to reflect changes in our data processing, technologies, or legal obligations.

If we make significant changes that affect your rights or how we use your data, we will notify you through appropriate channels.

Newsletter subscribers will be notified directly by email if changes affect their consent or data processing.