Privacy Policy
Management System | SS-EN ISO 9001:2015, 14001:2015 & SS-EN ISO 45001:2018
| Document name | Privacy Policy |
| Company | Grafokett AB |
| Edition | 5 |
| Date | 2026-06-24 |
1. Data controller and contact
Grafokett AB is the data controller for the processing of personal data described in this Privacy Policy, unless otherwise expressly stated. Questions concerning personal data, privacy, or the exercise of data subject rights may be sent to Grafokett AB through its usual contact channels or to the company’s designated contact function for data protection matters.
2. Types of personal data we collect
Contact details
When you become a customer of Grafokett, we collect your contact details:
- Name
- Address
- Email address
- Telephone number
Information about your services
We also retain data about which of our products and services you order and use, and how you use them.
Support cases
When you contact our support team, we collect the information you provide so that we can assist you with your case.
3. How we collect personal data
We collect and process data that:
- you provide when you become a lead or prospect with us.
- you provide when you become a customer of ours.
- you provide when contacting us, including notes, chat conversations, and emails.
- is generated when you visit our website or log in to the customer portal.
- is collected through cookies that record information about your browser and how you use the website.
4. How we use personal data
For us to process your data, at least one of the following legal bases must apply:
- The processing is necessary to perform our contract with you.
- The processing is necessary for Grafokett to comply with a legal obligation.
- The processing is in both your and Grafokett’s legitimate interests.
- You have given consent to the specific processing.
To provide our services to you, we need to process your personal data. Below you will find information about how we use your data and the legal basis on which the processing is carried out.
Provision of services
We process personal data to identify you as a customer, manage and deliver the services you have ordered, and process the personal data required for invoicing and payment for the services you use.
Legal basis: Performance of a contract.
Communication and support
We may use personal data from previous contacts with us to provide you with better assistance. We use your contact details and information about the services you use as a basis for invoices and important information about your products and services.
Legal basis: Legitimate interests, consent, and performance of a contract.
Development of our services and products
We process personal data about how you use our services, as well as information from your contacts with us, to improve your individual experience and our services in general.
Legal basis: Legitimate interests and consent.
Marketing
To market relevant products and services to you based on your needs, we process personal data about which services you use and how you use them.
Legal basis: Legitimate interests and consent.
Security and prevention of misuse
We process personal data to detect and prevent the following within our network:
- misuse
- attempted intrusions
- attacks such as viruses
- violations of law
- use of our products and services contrary to our terms and conditions
Legal basis: Performance of a contract and compliance with a legal obligation.
Statutory obligations
We process personal data to comply with requirements imposed by law.
Legal basis: Compliance with a legal obligation.
5. How long we retain personal data
We retain personal data only for as long as necessary for the purpose for which it was collected, or for as long as we are required to retain it under law, contract, accounting requirements, warranty commitments, or documented business and security reasons. When the data is no longer needed, it is removed, anonymised, or deleted in accordance with Grafokett’s retention schedule.
| Category | Retention principle |
|---|---|
| Customer and contract data | Retained during the customer relationship and thereafter in accordance with legal requirements, contractual obligations, and documented business needs. |
| Support and service cases | Retained for as long as the case needs to be followed up, quality-assured, or handled for warranty, service, or security reasons. |
| Accounting and invoicing records | Retained in accordance with applicable accounting legislation. |
| Prospect and marketing data | Retained for as long as there is a relevant and documented business interest, or until an objection, unsubscribe request, or withdrawal of consent occurs. |
6. With whom we share personal data
In exceptional cases, personal data is disclosed to partners and subcontractors for the purpose of troubleshooting and resolving technical problems relating to supplied equipment.
We have agreements with all partners. These agreements regulate, among other things, which personal data is processed, why it is processed, how it must be protected, and for how long it is processed. The agreements also contain instructions from the data controller to the data processor on how the personal data may be processed.
We aim never to share more personal data than is strictly necessary with each partner.
We take appropriate safeguards to ensure that your personal data is handled in accordance with applicable laws concerning security and privacy. We impose the same requirements on our subcontractors.
If personal data needs to be transferred to or processed in a country outside the EU/EEA, Grafokett ensures that the processing is supported by a valid transfer mechanism and appropriate safeguards, such as the European Commission’s Standard Contractual Clauses, an adequacy decision, or equivalent contractual and technical safeguards.
Cookies and similar technologies are used only to the extent required for functionality, security, statistics, or an improved user experience. Where consent is required, it is obtained before processing begins and may be changed or withdrawn in accordance with the cookie information provided on the website.
| Partner | Personal data shared and purpose |
|---|---|
| ClickUp | Name, email address, telephone number, company details, and information linked to customer cases, projects, support, and tasks. The purpose is to plan, administer, follow up, and document customer relationships, deliveries, support cases, and internal work processes. |
| LiveAgent | Email address, telephone number, company details, and contact name. The purpose is to manage support and troubleshooting in a secure, traceable ticket management system. |
| Suppliers | Company name, for the purpose of reserving a prospect or customer for a specific business opportunity. |
| Mailchimp | Name, email address, company affiliation, and information about receipt of and interaction with communications. The purpose is to manage newsletters, marketing communications, customer communication, and follow-up of consents, subscriptions, and communication preferences. |
| Service providers | Company, email address, telephone number, and contact person. The purpose is primarily to manage hardware service. |
| Oderland | Web hosting and virtual server hosting provider. Company details and employee contact details. |
| Tre | Employee names, telephone numbers, and email addresses. |
| Microsoft | Azure web hosting and user data required to use Cloudlabel. |
| Public authorities | We are required to disclose information upon request where legally obligated. |
7. How we protect your personal data
We store sensitive information, such as personal data, passwords, and company names, using standardised methods, for example SSL/TLS, VPN, and one-way hashing algorithms. The data is used to communicate effectively with customers, prospects, suppliers, and employees.
To ensure integrity, confidentiality, and availability, we apply a systematic approach and technical safeguards during implementation.
We have procedures and policies for:
- Incident management
- Risk analysis
- Internet policy
- Data policy
- Configuration and encryption of devices for secure data portability
- Grafokett personnel are bound by confidentiality agreements and process only the information required for their assignments.
- Personal data breaches are handled in accordance with an established internal procedure and, where required, reported to the Swedish Authority for Privacy Protection within 72 hours. Affected data subjects are informed when the breach is likely to result in a high risk to their rights and freedoms.
8. You control your personal data
You have the right to receive information about how your personal data is processed and to request access to the data we process about you. You also have the right to request rectification of inaccurate data, erasure of data, restriction of processing, data portability, and to object to processing based on legitimate interests or used for direct marketing. If processing is based on consent, you have the right to withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before consent was withdrawn. Certain rights may be restricted where continued processing is required by law, contract, or another legal obligation, for example under accounting legislation.
Requests to exercise rights are handled without undue delay and normally within one month. Where necessary, Grafokett may request additional information to verify the identity of the person making the request.
If you believe that Grafokett is processing your personal data in breach of applicable data protection rules, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
Grafokett does not use personal data for automated decision-making that produces legal effects or similarly significantly affects you. If such processing is introduced, specific information will be provided in advance.
9. Personal data when Grafokett acts as a data processor
Where the customer is the data controller and Grafokett processes personal data on the customer’s behalf, Grafokett acts as a data processor. Such processing is governed by a separate data processing agreement and is carried out only in accordance with the customer’s documented instructions.
10. How we process personal data when you are no longer a customer
When you terminate your account or the business relationship ends, we delete personal data where there is no longer a valid purpose or legal basis for continued processing. Data that must be retained by law, for example under accounting legislation, or that is needed to manage contracts, warranties, complaints, legal claims, or security, is retained only for as long as necessary. Where appropriate, we inform affected partners and subcontractors that data must be deleted or removed in accordance with applicable instructions and agreements. Where we are not informed that the business relationship has ended, the amount of information in our systems is managed through Grafokett’s retention schedule and removed where possible. A separate retention policy has been established.





