Privacy Policy
Version 2026-09-18
1. Who we are (data controller)
Labs Nutrition Sweden AB, company registration number 559426-7030, Sockenvägen 2b, 184 42 Åkersberga, Sweden, is the controller for the personal data described in this policy. We are established in Sweden.
Contact for privacy matters: info@labsnutrition.com · +46 735 28 55 55
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR.
2. What this policy covers
This policy covers personal data processed through the website labsnutrition.com. It does not cover personal data we process under a signed manufacturing agreement with a customer; that processing is governed by the relevant agreement.
3. Personal data we collect
- Enquiry data — when you use our contact form we collect the name, company, email address, telephone number (optional), product types of interest, estimated volume, timeline and the free-text description you provide.
- Data you send us directly — anything contained in emails or phone calls to us.
- Cookie choice — the categories you accepted or rejected, the time of the choice and the applicable consent and policy version, stored in your browser.
- Technical server data — our hosting provider processes standard request data such as IP address, browser type and requested page in order to deliver the site securely. We do not use this data to build profiles.
We do not run analytics, advertising pixels or session-recording tools on this website. We do not knowingly collect special categories of personal data through the website, and we ask that you do not include such data in the enquiry form.
All personal data comes directly from you, except the technical server data generated automatically when your browser requests a page.
4. Purposes and legal bases
| Activity | Data | Purpose | Legal basis | Retention |
|---|---|---|---|---|
| Responding to enquiries | Enquiry data | Answer your question, quote and prepare a possible contract | Steps taken at your request prior to entering a contract (Art. 6(1)(b)); where you write on behalf of a company, our legitimate interest in handling B2B enquiries (Art. 6(1)(f)) | Up to 5 years from last contact |
| Occasional B2B marketing emails | Business contact details | Inform business contacts about relevant products and services | Legitimate interest in direct marketing to existing and prospective business contacts (Art. 6(1)(f)); consent where required by applicable marketing rules | Until you object or unsubscribe |
| Operating and securing the website | Technical server data, necessary cookie | Deliver pages, prevent abuse and spam | Legitimate interest in a functioning, secure website (Art. 6(1)(f)) | Short-term server logs; consent cookie 12 months |
| Recording your cookie choice | Categories chosen, timestamp, versions | Respect your choice and demonstrate it | Legal obligation / necessity for the service you requested (Art. 6(1)(c) and (b)); the cookie itself is exempt from consent | 12 months |
| Optional cookies (none active today) | Device and usage data | Analytics, functionality, marketing — only if added in future | Consent (Art. 6(1)(a)) and ePrivacy consent | Stated in the Cookie Policy before any such cookie is set |
| Bookkeeping and legal compliance | Transaction and correspondence data, if a contract follows | Meet Swedish accounting and tax requirements | Legal obligation (Art. 6(1)(c)) | 7 years under the Swedish Accounting Act |
Providing enquiry data is voluntary, but without it we cannot answer your enquiry.
5. Who receives your data
- Google Workspace (Google Ireland Limited) — our business email. Enquiries sent through the form arrive in and are stored in our mailboxes.
- Lovable / Supabase — website hosting and backend platform used to run the site and deliver form submissions.
- Advisers and authorities — accountants, lawyers or authorities where we are legally required or entitled to share data.
These providers act as processors on our instructions, under data processing agreements, except where they act as independent controllers for their own service operation. We do not sell personal data and we do not share it for third-party advertising.
6. Transfers outside the EEA
Our providers primarily process data within the EU/EEA. Some of them are US-based groups that may access data from outside the EEA for support purposes. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with the providers' additional safeguards. You can request more detail about a specific provider by contacting us.
7. How long we keep data
Retention periods are listed in the table in section 4. When a period ends, data is deleted or anonymised. Where a legal claim or accounting obligation requires it, we keep the relevant data for as long as that obligation lasts.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have data erased, where the conditions are met;
- restrict our processing in certain situations;
- object to processing based on our legitimate interests, including direct marketing — if you object to direct marketing we stop immediately;
- receive data you provided in a portable format, where processing is based on consent or contract and carried out by automated means;
- withdraw consent at any time, without affecting processing already carried out.
To exercise a right, email info@labsnutrition.com. We only ask for the information we need to identify you and your request. We respond within one month, and tell you if we need longer.
You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se, or to the supervisory authority in your country of residence.
9. Cookies
We only set necessary cookies unless you consent to more. See our Cookie Policy for the full list and use the “Cookie settings” link in the footer to change or withdraw your choice at any time.
10. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
11. Security
The website is served over HTTPS with strict transport security, a content security policy and other protective HTTP headers. Access to mailboxes and systems is limited to staff who need it and protected by individual accounts. Form submissions are validated and rate-limited to reduce abuse.
12. Children
This is a business-to-business website aimed at companies. It is not directed at children and we do not knowingly collect data from them.
13. Changes to this policy
We update this policy when our processing changes. The version number at the top shows the current version. Material changes affecting cookies will trigger a renewed consent request.
