Table of Contents

1. Background

2. Definitions

3. How does the company collect personal information?

4. What Personal Information do we collect about you as a customer, for what purpose and on what legal basis?

5. Social platforms

6. Cookies

7. How long do we store your Personal Information?

8. Your rights and choices

9. Consent

10. Who can we share your Personal Information with?

11. Where do we process your Personal Information?

12. How is your Personal Information protected?

13. Supervision and compliance

14. Third Party Terms

15. Amendment of the Privacy Policy

16. Contact us

1. Background

We protect your privacy. This policy ("Privacy Policy") has been designed to make you aware that Idéfix Tekoprodukter Aktiebolag (the "Company", "we", "us") processes your personal data in a legal, appropriate and secure manner when you purchase our products or use our services, visit our website or otherwise contact us.

The Privacy Policy describes when, how and why we collect, use, disclose and store personal data and what rights you have under the provisions of the EU Data Protection Regulation (GDPR) (EU) 2016/679 with associated implementing regulations and supplementary data protection regulations ("The Data Protection Rules ").

The privacy policy applies to (i) when the Company provides goods and services to you when purchasing and ordering in our online store, (ii) when sending out newsletters, (iii) in other marketing in the form of customized offers and discounts, (iv) in all other contact with the Company in connection with visits to our website (the "Website") or via social platforms and (v) in case of inquiries or other contact with us via e-mail or telephone.

Garphyttan Original AB, org. no 559228-2411, Enbärsvägen 18, 735 37 Surahammar, is the data controller responsible for the processing of your personal data that is done in accordance with this Privacy Policy.

Below is a summary of the personal information we collect during your visit to our Website:

● we track your web activity and may use it for marketing purposes;

● we collect personal data on completed purchases in order to process and send your order but also for marketing and customer communication;

● we process specified personal data by submitting them into integrated systems;

● we store personal data in our market analysis system; and

● we track what products you have looked at, put in the shopping cart and bought. We may occasionally use this data to provide you with personalized product recommendations.

2. Definitions

For the purposes of this Privacy Policy, the term "personal data" refers to information that can be attributed to an identified or identifiable natural person, e.g. name, address, social security number, e-mail address, telephone number, card number and IP address ("Personal Information").

In this Privacy Policy we describe how we process your Personal Information. For example, the term "processing" means that we record, store, send and otherwise use your Personal Information in the manner described in this Privacy Policy ("Processing").


The company obtains Personal Data primarily directly from you as a customer.

We register, or may register your Personal Information in connection with:

● a completed order on the Website;

● when you enter your email address on the Website;

● if you contact us by e-mail, phone, website or social media;

● if you sign up for the Company's newsletter;

● if you sign up to receive newsletters from the Company's Group Company; and

● your visit to the Website including but not limited to traffic data, site data, weblogs and other communication data, and e.g. the IP address, device type, operating system, and browser type used for the visit.


4. What Personal Information do we collect about you as a customer, for what purpose and on what legal basis?

Purpose Personal data is processed to be able to:  Categories of Personal Data
To be able to handle orders and purchases  ● Deliver an ordered product (including delivery notification or contacts in connection with delayed delivery).

● Manage the customer's payment (including to analyze which payment solutions are to be offered to the customer, which includes checking the customer's payment history and obtaining credit information from credit reporting companies.

● Manage complaints and warranty issues regarding an ordered or purchased product or service.

● Checking the customer's address against Klarna.

● Name

● Social security number

● Contact information (eg address, email and phone number)

● Payment History

● Payment information

● Credit information from credit reporting agencies

● Purchase information (eg which item has been ordered or if the item is to be delivered to another address)


Legal basis:  The purchase agreement with the customer. This collection of your Personal Information is required for us to fulfill our obligations under the Purchase Agreement.
Storage period: Until the purchase has been completed (including delivery and payment) and for a period of 7 years. The Accounting Act requires us to store transaction data for 7 years, then in order to be able to handle any complaints and guarantee cases.


To be able to manage and manage the customer's user account.  Personal data is processed in order to create the customer's personal pages and manage the account, eg. to: Grant permission to login. Maintain accurate and up-to-date information. Enable the customer to follow their order history. Manage the customer's choice of payment history settings and information.
Purpose Personal data is processed to be able to: Categories of Personal Data
To be able to manage and manage the customer's user account ● Give permission to login.

● Maintain accurate and up-to-date information.

● Enable the customer to keep track of their order history.


● Name

● Contact information (eg address, email and phone number)

● User name and password


Legal basis: Registered customers - legitimate interest (balance of interests)

Execution of the agreement on registered customers. This collection of your personal information is required for us to manage your user account.

Storage period: Until you close your account.


Purpose Personal data is processed in order to market the company's services and products Categories of Personal Data
To be able to market products and services


● View relevant product recommendations, remind the customer of forgotten / abandoned digital shopping baskets or save shopping lists to simplify future purchases or similar actions that simplify the customer.

● Send direct marketing via email, sms, social media or other similar electronic channels for communication as well as by mail.

● Carry out more campaigns

○ All customers

○ A certain customer segment (eg women / men between 30-40 years in Sweden)

○ An individual customer

● Name

● Age

● ● Place of residence

● Purchase and order history

● User-generated information, e.g. visitor and click history, based on the use of the Company's Website and other digital channel services

● Information about how the customer uses the Company's Website, and other digital channels

● Details of completed purchases 

Legal basis: Registered and unregistered customers - justified

interest (balance of interests). Recipients of newsletters and website visitors - legitimate interest (balancing of interests) and the marketing act's provisions on consent or established customer relationship.

Storage period: 36 months or until you unsubscribe.


Purpose Personal data is processed in order to:  Categories of personal data
To be able to conduct and manage participation in competitions and events


● Communicate with participants participating in a competition organized by the Company.

● Identify the participant..

● Appoint winners and mediate winnings.

● Name

● Contact information (e.g., address, email, phone number)

● Information submitted in competition entries


Legal basis: legitimate interest (balance of interests).


Storage period: 12 months after the end of the event or competition.


Purpose Personal data is processed to be able to: Categories of Personal Data
To be able to provide customer service and service


● Communicate with the customer and answer inquiries that come in to customer service via email, phone or digital channels (including social media).

● Secure the customer's identityt

● Investigate complaints and support cases (including technical support).


● Name

● Contact information (eg address, email and phone number)

● Customer correspondence

● Information about the time of purchase, place of purchase, the error / complaint on the product

● Person or coordination number


Legal basis: legitimate interest (balance of interests).


Storage period: 36 months.


Purpose Personal data is processed to be able to: Categories of Personal Data
To be able to evaluate, develop and improve the Company's services


● Make services more user-friendly, e.g. change the user interface to simplify the flow of information or to highlight features commonly used by customers in a company's digital channels.

● Develop documentation to develop and improve the company's product range.

● Give customers an opportunity to influence the range that a company provides.


● Purchase and user-generated data (eg click and visit history).

● Contact information (eg address, email and phone number).

● Technical data on devices used by the customer and settings. e.g. language setting, IP address, browser settings, time zone, operating system, screen resolution and platform.

● Information about how the customer interacted with the Company, i.e. how the customer used the service, login method, where and how long different pages were visited, response times, download errors, how the customer reaches and leaves the service etc. 

Legal basis: legitimate interest (balance of interests). The treatment is necessary to meet our and our customers' legitimate interest in evaluating, developing and improving our services, products and systems.


Storage period: 36 months.

By submitting information to the Company, you authorize the Company to register and store information about which service you purchased and process the specified Personal Information for specified purposes. As a legal basis for treatment, the Company will refer to compliance with agreements, legitimate interest, consent or to comply with legal requirements. If the Company uses legitimate interest as a basis, it will only be done for the purposes stated above. Please note that you can withdraw your consent at any time by contacting us, for contact details see the heading at the bottom "Contact us".

The processing takes place in accordance with current legislation and means that personal data is not retained for longer than is necessary for the purposes of the processing. The Company will store your Personal Information as long as you are a customer with us. For marketing purposes, information older than 36 months is not used. This means, in practical terms, that data is thinned out as they are no longer relevant or necessary for analysis or direct marketing for the purposes for which they have been collected. Some information can be retained longer when required due to other legal requirements, such as the Accounting Act.

5. Social platforms

The company uses Facebook and Instagram as a channel to get in touch with our customers and to market and inform about our business and products. In connection with this, the Company is responsible for personal data for publications and information containing Personal Data and made on the social platforms by you as a user in the form of, for example, comments, pictures and video clips. The company does not accept that offensive content is published on our social platforms. The company asks our users to report abusive content to us so that we can ensure that such content does not exist. We can therefore also remove content based on what the Company deems necessary.

6. Cookies

When you use our Website, Personal Information may be collected through eg. cookies. However, this is done only through a separate consent. This will store the information about your use and which pages are visited. It can be technical information about your device and internet connection such as operating system, browser version, IP address, cookies and unique identifiers. For more information about our use of cookies and how to revoke your consent to the use of cookies, see our Cookie Policy.

7. How long do we store your personal data?

We will never store your Personal Data for longer than is necessary for each purpose.

Your Personal Information will only be stored as long as there is a need to save it to fulfill the purposes for which the Personal Information was collected in accordance with this Privacy Policy. See more about the specific storage periods in point 4.

If you have agreed to the Processing of your contact information for sending out newsletters, the Company processes the Personal Data for the specific purpose, until you withdraw your consent. You can do this by (i) contacting us and objecting in writing to this or (ii) following the link in the mailing.

In order to enable the Company to fulfill the legal obligations arising from the applicable law or to safeguard our legal interest, we may save the Personal Data for a longer period. However, personal data is never stored for longer than is necessary or required by law for each purpose.

8. Your rights and choicesl

You have the right to receive information about the Processing of your Personal Information we carry out. Below is a summary of the rights that you can assert by contacting us. You will find contact information for us at the end of this Privacy Policy.

Right of access

We want to be open and transparent with how we process your Personal Information. If you wish to gain insight into the personal data processing that we do in relation to you, you have the right to request information about the Processing. (i.e., information on purposes, categories of personal data, categories of recipients of personal data, retention period or criteria for determining retention period, information from which data has been collected and the existence of automated decision making including information on the logic behind and the importance of processing). You also have the right to receive an electronic copy of your Personal Information processed by us if you make the application electronically. If we receive an access request, we may ask for additional information to ensure which information you would like to access and that we disclose the information to the right person.

Right to correction

You have the right to request that your Personal Information be corrected if the information is incorrect. Within the scope of the stated purpose, you also have the right to supplement any incomplete Personal Information.

Right to deletion

You have the right to request the deletion of your Personal Information that we process


● the data is no longer necessary for the purposes for which it has been collected or processed;

● you have withdrawn a consent on which the treatment is based and there is no other legal basis for the treatment;

● you object to a balance of interests of legitimate interest that the Company has made and there is no legitimate interest for the Company that weighs heavier;

● you object to treatment for direct marketing purposes;

● the personal data was processed in an illegal manner; and

● personal data must be deleted in order to fulfill a legal obligation to which the Company is subject.

If you request deletion of personal data, we may not always respond to your request including:

● the treatment is needed to exercise someone's right to freedom of expression and information;

● to fulfill a legal obligation to which we are subject; and

● to be able to establish, enforce or defend legal claims.

Right of restriction

You have the right to request that the Company temporarily limit the processing of your Personal Information. Such a restriction may be requested in the following cases:

  • if you believe that the Personal Information we hold about you is inaccurate and that in connection with the requested correction,
  • when the Processing performed by your Personal Data is not in accordance with the rules in the Data Protection Rules but you do not yet want your Personal Data to be deleted but instead restricted, and
  • when we no longer need your Personal Information for the purposes of our Processing but then you need them to be able to establish, enforce or defend a legal claim.

 If you have objected to the Processing of your Personal Data, the use of the Personal Data may be restricted during the investigation. When limiting your Personal Information, the Company will only store your Personal Information and upon further processing obtain your consent.

Right to data portability

You have the right, in the event that we process your Personal Data with your consent or to fulfill a contractual obligation with you, to require that we provide all Personal Information that we have about you and that is processed in an automated way, in a machine-readable format, which t. ex. can be an Excel file or a CSV file. If technically possible, you further have the right to request that we transfer your Personal Data to another personal data controller.

Right to object

You have the right to object to our Processing of your Personal Data on the Processing with the aid of a balance of interests. In these cases, the company will ask you to specify which Treatment you object to. If you object to any Processing, we will only proceed with the Processing of your Personal Data if there are legitimate reasons for the Processing that outweighs your interests.

Direct marketing (including analyzes performed for direct marketing purposes)

You have the opportunity to object to your Personal Data being processed for direct marketing. The right to object also includes the analysis of personal data (so-called profiling) that is performed for direct marketing purposes. If you object to direct marketing, we will stop processing your Personal Information for that purpose as well as cease

with all types of direct marketing measures. Of course, you have the opportunity to refuse mailings and personal offers in certain channels, for example. You can choose to only receive offers from us via e-mail, but not sms. In these cases, you should not object to the processing of personal data, as we then have difficulty assessing which marketing is relevant to you.

9. Consent

By completing a consent form on the Website (eg subscribing to newsletters, receiving offers etc.) you agree that your Personal Information (eg your name, telephone number and email address) may be used for marketing purposes. the service that is exposed in connection with where you are asked to fill in your Personal Information. When you visit the Website, you need to agree to our Cookie Policy. Such cookies track you and your browsing behavior in order to offer you marketing based on your behavior. Your consent applies to the following domains:

You have the right to withdraw your consent at any time. In this case, we will not continue to collect new information for purposes based on your consent. However, we have the right to continue processing already collected Personal Data in accordance with the consent provided, but we will not supplement or update this information. If there is no other legal basis that requires us to save the data, we will delete it. If you wish to withdraw your consent, you are welcome to contact us via email data protection @.

10. Who can we share your Personal Information with?

Personal Data Assistants. In cases where it is necessary for us to be able to offer our services, we share your personal information with companies that are so-called. personal data assistants for us. A personal data assistant is a company that processes the information on our behalf and according to our instructions. We have personal data assistants who help us with:

1) Transport (logistics companies and freight forwarders).

2) Payment solutions (card-redeeming companies, banks and other payment service providers).

3) Marketing (print and distribution, social media, media agencies or advertising agencies).

4) IT services (companies that handle the necessary operations, technical support and maintenance of our IT solutions). When your Personal Data is shared with Personal Data Assistants, it only happens for purposes that are consistent with the purposes for which we have collected the information (for example, in order to fulfill our obligations under the Purchase Agreement. We check all Personal Data Assistants to ensure that they can provide sufficient We have written agreements with all personal data assistants through which they guarantee the security of the personal data being processed.

We may also share your Personal Information with our Group companies if you have given your consent to receive marketing through the sending of newsletters from these.

We will also disclose your Personal Information if required by law or if we, as a company, reasonably believe that disclosure is necessary to protect our company's rights and / or to obey a court decision or follow the outcome of a court hearing or legal process. However, we will do what we can to ensure that your Personal Information will continue to be protected.

The company will not sell your Personal Information to third parties, as we are currently operating, unless we have first obtained your approval. However, in the event that the Company decides to sell, buy, merge with another company or other organization, or otherwise reorganize the business, we may transfer your Personal Information to potential or actual buyers and their potential advisors.

11. Where do we process your Personal Information?

The company only cooperates with partners who process personal data within the EU/EEA or with companies that maintain the same level of protection as within the EU/EEA by, for example, having joined the so-called Privacy Shield agreement between the EU and the US.

12. How is your Personal Information protected?

We use IT systems to protect the privacy, privacy and access to personal data. We have taken special security measures to protect your Personal Information from illegal or unauthorized processing (such as illegal access, loss, destruction or damage). The Company ensures that access to your Personal Data is only granted to personnel who need it for the performance of their duties and that they observe confidentiality in accordance with the Company's applicable policies and procedures.

13. Supervision and compliance

The company will, on its own or the customer's initiative, correct any information that is found to be incorrect. You can also request that your information be deleted at any time or that its use be restricted by contacting us. You may refrain from receiving marketing communications from us at any time by contacting us or by unsubscribing from further communication in email that we send to you. You are always welcome to contact our customer service for help refusing our communication. You can, once a year free of charge, obtain information about which personal data is registered, by requesting in writing a so-called. register extract from us.

If you believe that we are handling your Personal Information incorrectly, you may contact us in the first place. You also have the right to file a complaint with the supervisory authority, currently the Data Inspectorate. You can find more information on how to do this at

The company annually evaluates this Privacy Policy.

14. Third Party Terms

In some cases, the company's services may be subject to third party terms. The Company is not responsible for the use of your Personal Data by such third parties as they are solely responsible for personal data and are responsible for the processing of your Personal Data. Thus, it is important that you consider and read through the terms and conditions that apply to third parties. The same applies if there is a link on the Website that links to other websites.

15. Amendment of the Privacy Policy

The Company reserves the right to change this Privacy Policy when we believe this is necessary to comply with applicable law. Such changes are primarily required in the event of any legislative changes, following statements by the supervisory authority or other bodies issuing opinions in response to the Data Protection Rules. Furthermore, this Privacy Policy will be updated when needed due to changes in our operations.

If the Company makes major changes to this Privacy Policy or changes to how we process your Personal Information, you will be informed of this before the change takes effect.

16. Contact us

If you have questions regarding this Privacy Policy or the current Processing of your Personal Information, wish to make a request in accordance with the Privacy Policy or if you wish to report a violation of this Privacy Policy and more. please feel free to contact us.

Personal Data Controller

Garphyttan Original AB

Org. No. 559228-2411

Enbärsvägen 18

735 37 Surahammar


This Privacy Policy applies from 2019-09-30