Privacy Policy

Management System | SS-EN ISO 9001:2015, 14001:2015 & SS-EN ISO 45001:2018

Document name Privacy Policy
Company Grafokett AB
Edition 5
Date 2026-06-24

1. Data controller and contact

Grafokett AB is the data controller for the processing of personal data described in this Privacy Policy, unless otherwise expressly stated. Questions concerning personal data, privacy, or the exercise of data subject rights may be sent to Grafokett AB through its usual contact channels or to the company’s designated contact function for data protection matters.

2. Types of personal data we collect

Contact details

When you become a customer of Grafokett, we collect your contact details:

  • Name
  • Address
  • Email address
  • Telephone number

Information about your services

We also retain data about which of our products and services you order and use, and how you use them.

Support cases

When you contact our support team, we collect the information you provide so that we can assist you with your case.

3. How we collect personal data

We collect and process data that:

  • you provide when you become a lead or prospect with us.
  • you provide when you become a customer of ours.
  • you provide when contacting us, including notes, chat conversations, and emails.
  • is generated when you visit our website or log in to the customer portal.
  • is collected through cookies that record information about your browser and how you use the website.

4. How we use personal data

For us to process your data, at least one of the following legal bases must apply:

  • The processing is necessary to perform our contract with you.
  • The processing is necessary for Grafokett to comply with a legal obligation.
  • The processing is in both your and Grafokett’s legitimate interests.
  • You have given consent to the specific processing.

To provide our services to you, we need to process your personal data. Below you will find information about how we use your data and the legal basis on which the processing is carried out.

Provision of services

We process personal data to identify you as a customer, manage and deliver the services you have ordered, and process the personal data required for invoicing and payment for the services you use.

Communication and support

We may use personal data from previous contacts with us to provide you with better assistance. We use your contact details and information about the services you use as a basis for invoices and important information about your products and services.

Development of our services and products

We process personal data about how you use our services, as well as information from your contacts with us, to improve your individual experience and our services in general.

Marketing

To market relevant products and services to you based on your needs, we process personal data about which services you use and how you use them.

Security and prevention of misuse

We process personal data to detect and prevent the following within our network:

  • misuse
  • attempted intrusions
  • attacks such as viruses
  • violations of law
  • use of our products and services contrary to our terms and conditions

Statutory obligations

We process personal data to comply with requirements imposed by law.

5. How long we retain personal data

We retain personal data only for as long as necessary for the purpose for which it was collected, or for as long as we are required to retain it under law, contract, accounting requirements, warranty commitments, or documented business and security reasons. When the data is no longer needed, it is removed, anonymised, or deleted in accordance with Grafokett’s retention schedule.

Category Retention principle
Customer and contract data Retained during the customer relationship and thereafter in accordance with legal requirements, contractual obligations, and documented business needs.
Support and service cases Retained for as long as the case needs to be followed up, quality-assured, or handled for warranty, service, or security reasons.
Accounting and invoicing records Retained in accordance with applicable accounting legislation.
Prospect and marketing data Retained for as long as there is a relevant and documented business interest, or until an objection, unsubscribe request, or withdrawal of consent occurs.

6. With whom we share personal data

In exceptional cases, personal data is disclosed to partners and subcontractors for the purpose of troubleshooting and resolving technical problems relating to supplied equipment.

We have agreements with all partners. These agreements regulate, among other things, which personal data is processed, why it is processed, how it must be protected, and for how long it is processed. The agreements also contain instructions from the data controller to the data processor on how the personal data may be processed.

We aim never to share more personal data than is strictly necessary with each partner.

We take appropriate safeguards to ensure that your personal data is handled in accordance with applicable laws concerning security and privacy. We impose the same requirements on our subcontractors.

If personal data needs to be transferred to or processed in a country outside the EU/EEA, Grafokett ensures that the processing is supported by a valid transfer mechanism and appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, an adequacy decision, or equivalent contractual and technical safeguards.

Cookies and similar technologies are used only to the extent required for functionality, security, statistics, or an improved user experience. Where consent is required, it is obtained before processing begins and may be changed or withdrawn in accordance with the cookie information provided on the website.

Partner Personal data shared and purpose
ClickUp Name, email address, telephone number, company details, and information linked to customer cases, projects, support, and tasks. The purpose is to plan, administer, follow up, and document customer relationships, deliveries, support cases, and internal work processes.
LiveAgent Email address, telephone number, company details, and contact name. The purpose is to manage support and troubleshooting in a secure, traceable ticket management system.
Suppliers Company name, for the purpose of reserving a prospect or customer for a specific business opportunity.
Mailchimp Name, email address, company affiliation, and information about receipt of and interaction with communications. The purpose is to manage newsletters, marketing communications, customer communication, and follow-up of consents, subscriptions, and communication preferences.
Service providers Company, email address, telephone number, and contact person. The purpose is primarily to manage hardware service.
Oderland Web hosting and virtual server hosting provider. Company details and employee contact details.
Tre Employee names, telephone numbers, and email addresses.
Microsoft Azure web hosting and user data required to use Cloudlabel.
Public authorities We are required to disclose information upon request where legally obligated.

7. How we protect your personal data

We store sensitive information, such as personal data, passwords, and company names, using standardised methods, for example SSL/TLS, VPN, and one-way hashing algorithms. The data is used to communicate effectively with customers, prospects, suppliers, and employees.

To ensure integrity, confidentiality, and availability, we apply a systematic approach and technical safeguards during implementation.

We have procedures and policies for:

  • Incident management
  • Risk analysis
  • Internet policy
  • Data policy
  • Configuration and encryption of devices for secure data portability
  • Grafokett personnel are bound by confidentiality agreements and process only the information required for their assignments.
  • Personal data breaches are handled in accordance with an established internal procedure and, where required, reported to the Swedish Authority for Privacy Protection within 72 hours. Affected data subjects are informed when the breach is likely to result in a high risk to their rights and freedoms.

8. You control your personal data

You have the right to receive information about how your personal data is processed and to request access to the data we process about you. You also have the right to request rectification of inaccurate data, erasure of data, restriction of processing, data portability, and to object to processing based on legitimate interests or used for direct marketing. If processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. Certain rights may be restricted where continued processing is required by law, contract, or another legal obligation, for example under accounting legislation.

Requests to exercise rights are handled without undue delay and normally within one month. Where necessary, Grafokett may request additional information to verify the identity of the person making the request.

If you believe that Grafokett is processing your personal data in breach of applicable data protection rules, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Grafokett does not use personal data for automated decision-making that produces legal effects or similarly significantly affects you. If such processing is introduced, specific information will be provided in advance.

9. Personal data when Grafokett acts as a data processor

Where the customer is the data controller and Grafokett processes personal data on the customer’s behalf, Grafokett acts as a data processor. Such processing is governed by a separate data processing agreement and is carried out only in accordance with the customer’s documented instructions.

10. How we process personal data when you are no longer a customer

When you terminate your account or the business relationship ends, we delete personal data where there is no longer a valid purpose or legal basis for continued processing. Data that must be retained by law, for example under accounting legislation, or that is needed to manage contracts, warranties, complaints, legal claims, or security, is retained only for as long as necessary. Where appropriate, we inform affected partners and subcontractors that data must be deleted or removed in accordance with applicable instructions and agreements. Where we are not informed that the business relationship has ended, the amount of information in our systems is managed through Grafokett’s retention schedule and removed where possible. A separate retention policy has been established.

Grafokett AB | QR-12 | Privacy Policy | Edition 5