Privacy Policy

Version 2026-09-18

1. Who we are (data controller)

Labs Nutrition Sweden AB, company registration number 559426-7030, Sockenvägen 2b, 184 42 Åkersberga, Sweden, is the controller for the personal data described in this policy. We are established in Sweden.

Contact for privacy matters: info@labsnutrition.com · +46 735 28 55 55

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR.

2. What this policy covers

This policy covers personal data processed through the website labsnutrition.com. It does not cover personal data we process under a signed manufacturing agreement with a customer; that processing is governed by the relevant agreement.

3. Personal data we collect

  • Enquiry data — when you use our contact form we collect the name, company, email address, telephone number (optional), product types of interest, estimated volume, timeline and the free-text description you provide.
  • Data you send us directly — anything contained in emails or phone calls to us.
  • Cookie choice — the categories you accepted or rejected, the time of the choice and the applicable consent and policy version, stored in your browser.
  • Technical server data — our hosting provider processes standard request data such as IP address, browser type and requested page in order to deliver the site securely. We do not use this data to build profiles.

We do not run analytics, advertising pixels or session-recording tools on this website. We do not knowingly collect special categories of personal data through the website, and we ask that you do not include such data in the enquiry form.

All personal data comes directly from you, except the technical server data generated automatically when your browser requests a page.

4. Purposes and legal bases

ActivityDataPurposeLegal basisRetention
Responding to enquiriesEnquiry dataAnswer your question, quote and prepare a possible contractSteps taken at your request prior to entering a contract (Art. 6(1)(b)); where you write on behalf of a company, our legitimate interest in handling B2B enquiries (Art. 6(1)(f))Up to 5 years from last contact
Occasional B2B marketing emailsBusiness contact detailsInform business contacts about relevant products and servicesLegitimate interest in direct marketing to existing and prospective business contacts (Art. 6(1)(f)); consent where required by applicable marketing rulesUntil you object or unsubscribe
Operating and securing the websiteTechnical server data, necessary cookieDeliver pages, prevent abuse and spamLegitimate interest in a functioning, secure website (Art. 6(1)(f))Short-term server logs; consent cookie 12 months
Recording your cookie choiceCategories chosen, timestamp, versionsRespect your choice and demonstrate itLegal obligation / necessity for the service you requested (Art. 6(1)(c) and (b)); the cookie itself is exempt from consent12 months
Optional cookies (none active today)Device and usage dataAnalytics, functionality, marketing — only if added in futureConsent (Art. 6(1)(a)) and ePrivacy consentStated in the Cookie Policy before any such cookie is set
Bookkeeping and legal complianceTransaction and correspondence data, if a contract followsMeet Swedish accounting and tax requirementsLegal obligation (Art. 6(1)(c))7 years under the Swedish Accounting Act

Providing enquiry data is voluntary, but without it we cannot answer your enquiry.

5. Who receives your data

  • Google Workspace (Google Ireland Limited) — our business email. Enquiries sent through the form arrive in and are stored in our mailboxes.
  • Lovable / Supabase — website hosting and backend platform used to run the site and deliver form submissions.
  • Advisers and authorities — accountants, lawyers or authorities where we are legally required or entitled to share data.

These providers act as processors on our instructions, under data processing agreements, except where they act as independent controllers for their own service operation. We do not sell personal data and we do not share it for third-party advertising.

6. Transfers outside the EEA

Our providers primarily process data within the EU/EEA. Some of them are US-based groups that may access data from outside the EEA for support purposes. Where that happens, the transfer relies on the European Commission's Standard Contractual Clauses and/or the EU–US Data Privacy Framework, together with the providers' additional safeguards. You can request more detail about a specific provider by contacting us.

7. How long we keep data

Retention periods are listed in the table in section 4. When a period ends, data is deleted or anonymised. Where a legal claim or accounting obligation requires it, we keep the relevant data for as long as that obligation lasts.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have data erased, where the conditions are met;
  • restrict our processing in certain situations;
  • object to processing based on our legitimate interests, including direct marketing — if you object to direct marketing we stop immediately;
  • receive data you provided in a portable format, where processing is based on consent or contract and carried out by automated means;
  • withdraw consent at any time, without affecting processing already carried out.

To exercise a right, email info@labsnutrition.com. We only ask for the information we need to identify you and your request. We respond within one month, and tell you if we need longer.

You can also complain to the Swedish Authority for Privacy Protection (Integritets­skydds­myndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se, or to the supervisory authority in your country of residence.

9. Cookies

We only set necessary cookies unless you consent to more. See our Cookie Policy for the full list and use the “Cookie settings” link in the footer to change or withdraw your choice at any time.

10. Automated decision-making

We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.

11. Security

The website is served over HTTPS with strict transport security, a content security policy and other protective HTTP headers. Access to mailboxes and systems is limited to staff who need it and protected by individual accounts. Form submissions are validated and rate-limited to reduce abuse.

12. Children

This is a business-to-business website aimed at companies. It is not directed at children and we do not knowingly collect data from them.

13. Changes to this policy

We update this policy when our processing changes. The version number at the top shows the current version. Material changes affecting cookies will trigger a renewed consent request.