Free shipping on orders over EUR 30

Privacy policy

Last updated: 18 mei 2026

1. Data controller

AIFAIS B.V., trading as Mevora, is the data controller for the processing of your personal data via mevora.eu. Address: Gouda, the Netherlands. Chamber of Commerce 42036293, VAT NL822518476B01.

Privacy questions: privacy@mevora.eu.

2. What data we process

  • Name, address, email and phone number (when ordering)
  • Payment data (processed by Mollie, we only receive status and transaction ID)
  • Order history and order details
  • Communication via support@mevora.eu
  • IP address, browser info and visited pages (after cookie consent)

3. Purpose and legal basis

We process personal data for the following purposes:

  • Order execution (legal basis: contract performance, art. 6(1)(b) GDPR): name, address, email and phone are required for delivery and service.
  • Legal obligation (art. 6(1)(c) GDPR): tax retention obligation 7 years for invoices.
  • Legitimate interest (art. 6(1)(f) GDPR): fraud prevention, security and website improvement.
  • Consent (art. 6(1)(a) GDPR): analytics cookies and marketing emails (only with explicit consent).

4. Retention periods

  • Order and invoice data: 7 years (tax obligation)
  • Customer data after last contact: 2 years, then anonymized
  • Support communication: 1 year after closure
  • Analytics data: 14 months (Vercel Analytics default)
  • Cookie consent preference: 12 months

5. Data recipients (processors)

We only share your data with service providers necessary for our operations. With all these parties we have a data processing agreement and they process data exclusively within the EU or under valid adequacy decisions.

  • Mollie B.V. (NL) - payment processing
  • Supabase Inc. (EU region) - database hosting
  • Vercel Inc. (EU region) - website hosting and analytics
  • Resend Inc. (EU region) - transactional email
  • Logistics partner - for shipping (name + address only)

6. Your rights

Under the GDPR you have the following rights:

  • Right of access (what data do we have of you)
  • Right of rectification (correction of incorrect data)
  • Right of erasure (to be forgotten, as far as legally permitted)
  • Right to restriction of processing
  • Right to data portability (data in machine-readable format)
  • Right to object to processing based on legitimate interest
  • Right to withdraw consent (for cookies and marketing)

Send a request to privacy@mevora.eu with a copy of your ID (mask social security number and photo). We respond within 30 days.

7. Cookies

We use functional cookies (necessary for site operation) and, with consent, analytics cookies for anonymous visitor statistics. See our cookie policy for details.

8. Security

We take appropriate technical and organizational measures to protect your data against loss, unauthorized access or misuse: HTTPS encryption, limited database access, two-factor authentication for management, regular security audits.

9. Data breach procedure

In the event of a data breach with risk to data subjects, we report this within 72 hours to the Dutch Data Protection Authority and inform data subjects directly if the risk is high.

10. Complaints

If you have a complaint about how we handle your data, you can first report it to us at privacy@mevora.eu. You also always have the right to file a complaint with the Dutch Data Protection Authority (autoriteitpersoonsgegevens.nl).

11. Changes

This privacy policy may be amended. The most recent version is always on this page. For significant changes we inform registered customers by email.