Your privacy is important to us. Here we describe how personal data is collected, used, stored and protected when you visit Swehealth, contact us or shop in our online store.

Who is responsible for your personal data?

The controller for the processing of personal data at Swehealth is:

SweHealth Worldwide AB
Reg. no.: 556808-5079
VAT number: SE556808507901
Magasinsgatan 17
903 27 Umeå
Sweden

E-mail: info@swehealth.com
Phone: +46 73 774 83 90

What personal data do we collect?

The data we process depends on how you use the website and which services you use.

We may, among other things, process:

  • Name
  • Billing address and delivery address
  • Phone number
  • E-mail address
  • Payment-related information
  • Company name and registration number for business purchases
  • Order history
  • Communication with customer service
  • IP address
  • Browser and device information
  • Information about how the website is used

We only aim to collect the data needed for the purpose in question.

Why do we process personal data?

We process personal data in order to run our business and provide our services.

This may, for example, be to:

  • Handle and administer orders
  • Process payments
  • Deliver ordered products
  • Send information about orders and deliveries
  • Handle questions and customer service
  • Handle returns and complaints
  • Fulfil legal obligations
  • Prevent fraud and misuse
  • Improve the website’s functionality and user experience
  • Carry out statistics and analysis
  • Market products and services where there is an applicable legal basis
What legal basis do we use?

Personal data is only processed when there is a legal basis under applicable data protection legislation (GDPR).

Depending on the processing, we may rely on:

  • Performance of a contract, for example to process an order and deliver a product.
  • Legal obligation, for example when data must be kept under accounting legislation.
  • Legitimate interest, for example for security, fraud prevention and certain development of our website.
  • Consent, where consent is required for a particular processing, for example for certain cookies or marketing purposes.

Where processing is based on consent, you have the right to withdraw your consent at any time.

How is payment data processed?

To carry out payments, necessary personal data may be shared with our payment providers.

Swehealth uses, among others:

  • Stripe (card payments and local payment methods)
  • Klarna
  • Bank transfer (via our bank)

The payment options available are shown at checkout.

Payment providers may process personal data as independent controllers in accordance with their own privacy policies.

Read our Payment Policy

What data is shared with carriers?

In order to deliver your order, we may share necessary data with carriers and logistics partners.

This may, for example, be your name, delivery address, phone number, e-mail address and information needed for the delivery.

The carrier used depends on the order, the size of the product and the delivery address.

Read our Delivery Policy

Do you use analytics and marketing services?

We use services for, for example, website analytics, statistics, advertising and marketing measurement.

Depending on your cookie choices, these services may process information about how the website is used.

Examples of services that may be used are:

  • Google Analytics
  • Google Ads
  • Google Tag Manager
  • Meta
  • Microsoft Advertising
  • Microsoft Clarity
  • Pinterest
  • TradeDoubler, Addrevenue, Partner-ads

Which services are actually activated depends on your cookie settings.

Read more about Cookies

How does Swehealth use cookies?

Swehealth uses cookies and similar technologies to make the website work, for statistics and analysis, and for marketing where permitted.

Necessary cookies may be required for, for example, the cart, checkout and other basic functions.

Other cookies are used according to the choices you make in the website’s cookie settings.

Read our information about Cookies

Newsletter, discount codes and reminders

Newsletter: If you sign up for our newsletter, for example via the offer of a discount on your first purchase, we process your name, your e-mail address and – if you choose to provide it – your birthday. Your birthday is used to send you a greeting or an offer on your birthday. The legal basis is your consent. You can unsubscribe at any time via the link in every mailing or by contacting us. Mailings are sent via our e-mail service Brevo (Sendinblue SAS, France), which processes the data on our behalf.

Discount codes: To ensure that a welcome discount can only be used once per customer, we store which e-mail address the code was sent to and whether it has been used. The legal basis is our legitimate interest in preventing misuse.

Reminder about an incomplete purchase: If you have started a purchase and entered your e-mail address at checkout but not completed the purchase, we may send you a reminder about your cart. The legal basis is our legitimate interest in helping you complete the purchase. You can decline such reminders at any time by replying to the e-mail or contacting us at info@swehealth.com.

Which service providers do we use?

We use providers that process personal data on our behalf (processors), for example for web hosting and operation of the online shop, e-mail and newsletters (Brevo), accounting, and security and performance of the website (Cloudflare). The providers may only process the data according to our instructions and have agreements with us governing the processing.

Data is also disclosed to payment providers, carriers and advertising platforms as described in this policy, and to authorities where we are required to do so by law.

How long is personal data kept?

We only keep personal data for as long as it is needed for the purpose for which it was collected or for as long as we are required to keep it by law.

For example:

  • Accounting records, such as receipts and invoices, are kept for seven years after the end of the calendar year in which the financial year ended, in accordance with the Swedish Bookkeeping Act.
  • Order data is kept for up to three years after the purchase in order to handle complaints and warranty cases.
  • Newsletter data is kept until you unsubscribe. Data from incomplete purchases is only kept for as long as it is needed to send the reminder and handle any questions.
  • Customer service cases may be kept for as long as the information is needed to handle and follow up the case.
  • Data for marketing is kept for as long as there is a legal basis for the processing.

When the data is no longer needed, it is deleted or anonymised in accordance with our routines and applicable legislation.

What rights do I have?

Under data protection legislation, you have several rights when your personal data is processed.

Depending on the situation, you may have the right to:

  • Request information about which personal data we process about you
  • Request rectification of incorrect or incomplete data
  • Request erasure when the conditions for this are met
  • Request restriction of processing
  • Object to certain processing
  • Request data portability where applicable
  • Withdraw a consent you have given

Some rights may be limited when we must retain or process data due to legal obligations.

Contact us if you wish to exercise any of your rights.

How do we protect your personal data?

We use appropriate technical and organisational security measures to protect personal data.

The measures are intended to reduce the risk of, among other things, unauthorised access, loss, alteration, misuse or unlawful processing of personal data.

We work continuously on the security of the website and our systems.

Is personal data transferred outside the EU and EEA?

Some of our service providers may process personal data outside the EU and EEA.

When such a transfer takes place, it must be based on a permitted transfer mechanism and appropriate safeguards under applicable data protection legislation.

This may, for example, be an adequacy decision (such as the EU–US Data Privacy Framework) or the European Commission’s standard contractual clauses where applicable.

Can I make a complaint?

If you believe that your personal data is being processed in breach of data protection legislation, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), which is our supervisory authority. You may also lodge a complaint with the data protection authority in the EU country where you live or work.

You are also welcome to contact us first if you have questions or comments about how we process your personal data.

Can the privacy policy change?

We may update this privacy policy. The latest version is always published on this page.