Privacy policy
Last updated: 25 September 2026
This is an English translation of the Swedish privacy policy. In case of any discrepancy the Swedish version prevails. Your privacy matters to us. This policy explains what personal data Luma Massage Malmö collects, how it is used and what rights you have under the General Data Protection Regulation (GDPR).
1. Controller
Genti Musliu, operating under the business name Luma Massage Malmö (company no.: 19840117-0637), is the controller responsible for the processing of your personal data.
- Address: Spångatan 10b, 211 44 Malmö
- Email: Lumamassage@outlook.com
- Telephone: 073-559 38 13
2. What data we collect
- Booking details: name, email, telephone number, selected treatment, date and time.
- Membership details: name, email, telephone, type of membership, payment status and period of validity.
- Payment details: payment method and status. We never handle the card details ourselves; they are handled by Stripe.
- Communication: messages you send by email, telephone or the enquiry form for businesses.
- Discount code and newsletter: the email address you provide to receive a discount code and, if you have agreed to it, to receive our newsletter.
- Technical data: IP address, browser and visit data via our hosting provider (anonymised visitor statistics).
3. Why we process the data
- To carry out and administer bookings and to send booking confirmations.
- To manage memberships and related payments.
- To respond to enquiries by email, telephone or the enquiry form for businesses.
- To send the discount code you asked for, and the newsletter if you have agreed to it.
- To send information about your booking, e.g. reminders or changes.
- To send offers to members (only if you are a member and have not actively unsubscribed).
- To meet the requirements of the Swedish Bookkeeping Act regarding the retention of transaction data.
- To document serious incidents during a treatment, if something happens that means we need to be able to show what occurred.
4. Legal basis
- Contract: processing of booking details is necessary to perform the booking.
- Legal obligation: the Swedish Bookkeeping Act requires us to retain transaction data for 7 years.
- Legitimate interest: communication about bookings and improvement of the service.
- Consent: marketing emails and newsletters. You can withdraw your consent at any time via the link in every mailing.
- Legal claims: if a serious incident occurs during a treatment, we document it so that a legal claim can be established, exercised or defended. Such notes are read only by the person in charge of the business and by the person who wrote them.
5. How long we keep the data
- Bookings and invoicing records: 7 years (under the Swedish Bookkeeping Act).
- Membership details: for as long as the membership is active, then 7 years for bookkeeping purposes.
- Marketing consent: until you withdraw it or have been inactive for 24 months.
- Enquiries and emails: a maximum of 24 months if no further relationship arises.
- Documentation of a serious incident: 24 months, after which it is deleted automatically. If the incident has led to a police report or an insurance claim, it is kept until the matter is closed.
6. Who we share data with
We never sell your data. We share it with suppliers who help us run the service, all of them under data processing agreements, and in the two cases described below the list:
- Stripe (Ireland): payments.
- Resend (USA, EU Standard Contractual Clauses): sending of booking confirmations and membership emails.
- Supabase (EU, Frankfurt): database storage of bookings and memberships.
- Vercel (USA, EU Standard Contractual Clauses): hosting of the website.
- Meta (Facebook and Instagram, USA, EU Standard Contractual Clauses): measurement of ad performance, only if you have accepted cookies.
- Bokadirekt (Sweden): displays public reviews, if you have chosen to publish one yourself.
Associated therapists. If you book an appointment with one of our associated therapists, who run their own business, the therapist receives your name, your telephone number and the booking details so that the treatment can be carried out.
Google (map on the contact page): the map is only loaded if you choose to display it yourself. Your IP address is then sent to Google, which displays the map.
7. Your rights
Under the GDPR you have the right to:
- Request a copy of the personal data we hold about you.
- Have inaccurate data corrected.
- Request erasure of your data (unless we are required by law to keep it).
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw your consent to marketing.
Send a request to Lumamassage@outlook.com and we will get back to you within 30 days.
8. Cookies and visitor statistics
We use technically necessary cookies for the booking flow and login. To understand how the site is used we also collect anonymous, cookie-free visitor statistics in our own database: page views, approximate region at country level, device type and which channel the visit came from. The statistics contain no personal data and cannot be linked to you as a person, so they do not require consent.
If you accept cookies we also use the Meta Pixel and Meta's Conversions API to measure the results of our ads on Facebook and Instagram. This happens only with your consent.
If you choose Necessary only the Meta Pixel is never loaded, and the site works just as well. You can change your mind at any time: click Cookie settings at the bottom of the page and you will be asked again. Withdrawing consent afterwards should be just as easy as giving it.
10. Changes to this policy
This policy may be updated. In the event of major changes we will inform you by email if you are a member or have an active booking.