Privacy policy

Applies to: bodynity.com  |  Markets: Netherlands, Belgium, Sweden, Norway  |  Last updated: May 2026

Company name: Bodynity Ltd
Company registration: 16196139
Registered address: 71–75 Shelton Street, Covent Garden, London WC2H 9JQ, United Kingdom
Email: info@bodynity.com

This Privacy Policy explains how Bodynity Ltd collects, uses, stores, and shares your personal data when you visit bodynity.com, place an order, or contact us. Bodynity Ltd is the data controller for the purposes of the GDPR and applicable national data protection laws in the Netherlands, Belgium, Sweden, and Norway.


1. What Personal Data We Collect

Information you provide directly:

  • Name
  • Billing and shipping address
  • Email address
  • Phone number
  • Order details and purchase history
  • Messages sent to customer support
  • Return, refund, or complaint information

Information collected automatically when you visit our site:

  • IP address
  • Browser type and device type
  • Pages viewed and time spent on pages
  • Referring website
  • Cookie and tracking data (see Section 4)

Information received from third parties:

  • Shopify (our e-commerce platform)
  • Payment service providers
  • Shipping and fulfilment partners
  • Analytics and advertising partners
  • Fraud prevention services

2. How We Use Your Personal Data

To process and fulfil your order — including processing payment, confirming your order, arranging shipment, providing tracking updates, and handling returns and refunds.
Legal basis: performance of a contract.

To provide customer support — responding to questions, complaints, and service requests.
Legal basis: performance of a contract, or our legitimate interests in managing customer service.

To improve our website and services — analysing site performance, customer behaviour, and user experience.
Legal basis: legitimate interests, or your consent where required for non-essential cookies.

To send marketing communications — promotional emails about our products, offers, or updates.
Legal basis: your consent where required, or our legitimate interests where permitted. You can unsubscribe at any time.

To prevent fraud and protect our business — detecting, preventing, and responding to fraudulent or unlawful activity.
Legal basis: legitimate interests and compliance with legal obligations.

To comply with legal obligations — including tax, accounting, consumer law, and law enforcement requirements.
Legal basis: compliance with a legal obligation.


3. How We Share Your Personal Data

We share your personal data only where necessary with:

  • Shopify — our e-commerce platform provider
  • Payment providers — to process payments securely (including Klarna, Stripe, and others)
  • Shipping and fulfilment partners — to deliver your order
  • IT, hosting, and analytics providers — to operate and improve our website
  • Marketing and advertising partners — where you have consented or where permitted by law
  • Professional advisers — legal, accounting, or compliance advisers where necessary
  • Public authorities — where required by law

We do not sell your personal data.


4. Cookies and Tracking

We use cookies and similar technologies to operate our website, remember your preferences, analyse traffic, and support marketing activities.

Strictly necessary cookies are required for the website and checkout to function. These do not require your consent.

Non-essential cookies — including analytics and advertising cookies such as the Facebook Pixel — are only placed after you have given your consent through our cookie banner. We do not activate tracking before consent is given.

You can manage or withdraw your cookie consent at any time through our cookie banner or your browser settings. Withdrawing consent will not affect the lawfulness of processing before withdrawal.

For more information on cookies used by Shopify, see Shopify's Cookie Policy.


5. International Data Transfers

Some of our service providers process data outside the EEA. Where personal data is transferred outside the EEA, we rely on recognised legal transfer mechanisms including Standard Contractual Clauses (SCCs) or transfers to countries with an adequacy decision from the European Commission.

Norway, while not an EU member, participates in the EEA and applies equivalent data protection standards under the Norwegian Personal Data Act (Personopplysningsloven), which incorporates the GDPR.


6. How Long We Keep Your Data

We keep your personal data only for as long as necessary for the purposes described in this policy. The criteria we use to determine retention periods include:

  • The duration needed to fulfil your order and handle any related disputes or returns
  • Legal obligations to retain business and tax records (typically 7 years in the Netherlands, Belgium, Sweden, and Norway)
  • The period during which a legal claim could be brought against us
  • Any regulatory guidance on retention for specific categories of data

When data is no longer needed it is securely deleted or anonymised.


7. Your Rights

Under the GDPR and applicable national law, you have the following rights regarding your personal data:

  • Right to be informed — to know how your data is used (this policy fulfils that obligation)
  • Right of access — to request a copy of the personal data we hold about you
  • Right to rectification — to have inaccurate data corrected
  • Right to erasure — to request deletion of your data where we no longer have a lawful basis to hold it
  • Right to restrict processing — to limit how we use your data in certain circumstances
  • Right to object — to object to processing based on legitimate interests or for direct marketing
  • Right to data portability — to receive your data in a structured, machine-readable format
  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time

To exercise any of these rights, contact us at info@bodynity.com. We will respond within one month. We may ask you to verify your identity before processing your request.

You also have the right to lodge a complaint with your national data protection authority:

  • Netherlands: Autoriteit Persoonsgegevens (autoriteitpersoonsgegevens.nl)
  • Belgium: Gegevensbeschermingsautoriteit (gegevensbeschermingsautoriteit.be)
  • Sweden: Integritetsskyddsmyndigheten (imy.se)
  • Norway: Datatilsynet (datatilsynet.no)

8. Marketing Communications

If you receive marketing emails from us, you can unsubscribe at any time by clicking the unsubscribe link in any email or by contacting us at info@bodynity.com.

Opting out of marketing will not affect service-related communications such as order confirmations, shipping updates, or important policy changes.


9. Security

We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, misuse, or alteration. These include encrypted connections (SSL/TLS) and access controls on systems holding personal data.

No system is completely secure and no transmission over the internet is entirely risk-free. If you have concerns about the security of your data, contact us at info@bodynity.com.


10. Children

Our website and services are not directed at children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at info@bodynity.com so we can take appropriate action.


11. Third-Party Websites

Our website may contain links to third-party websites. We are not responsible for the privacy practices or content of those sites. We recommend reviewing their privacy policies separately before providing any personal data.


12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our operations, legal requirements, or regulatory guidance. The latest version will always be available at bodynity.com/policies/privacy-policy with the updated date shown at the top.

For significant changes we will make reasonable efforts to notify you directly, for example by email or a prominent notice on our website.


13. Contact

For any questions about this Privacy Policy or to exercise your data protection rights:

Bodynity Ltd
71–75 Shelton Street, Covent Garden
London WC2H 9JQ, United Kingdom
Email: info@bodynity.com


This Privacy Policy is drafted to comply with: EU General Data Protection Regulation (GDPR) 2016/679, Norwegian Personal Data Act (Personopplysningsloven), Dutch Implementation Act (UAVG), Belgian Data Protection Act, Swedish Data Protection Act, and ePrivacy Directive 2002/58/EC as implemented in national law across the Netherlands, Belgium, Sweden, and Norway.