Your cart is currently empty!
Privacy Policy
Last updated: 12/08/2025
By installing our mobile application or in any way using or accessing our services, you accept the terms of this Privacy Policy and the processing of your personal data in accordance with applicable data protection legislation, including the EU General Data Protection Regulation (GDPR).
Responsible for the processing of your personal data is:
Company Name:
Gympak AB, org. nr 559373-8411
Address:
Henckels Torg 4, 252 36 Helsingborg, Sweden
E-mail:
hello@gympak.com
When you register for Gympak services, we collect personal information from you such as:
As you use the Gympak services, you may upload additional personal information to your account, depending on your use of the services, including:
In an ongoing effort to improve our services, additional personal information may be collected. In such cases, we will notify you when the collection occurs.
We only process your personal data in accordance with this Privacy Policy and relevant legislation. Below are the purposes for processing your data.
Under GDPR, you have the right to:
To exercise your rights:
Contact hello@gympak.com or delete your account through the app.
We may share your data with:
Transfers outside the EU/EEA will only be made with appropriate safeguards, such as standard contractual clauses.
We use industry-standard technical and organisational measures to protect your personal data, including:
You should also use a strong password, limit device access, and log out after using the Gympak app.
We may update this Privacy Policy when necessary. Any significant changes will be communicated in advance via our website, app, or email.
For questions or complaints about our handling of your personal data:
Email: hello@gympak.com
You also have the right to file a complaint with the relevant supervisory authority.
Personal Data | Legal Basis | Retention Time |
Identity data, Contact details, Profile data, Technical data | Fulfilment of a contract – processing necessary to comply with current terms of delivery. | Retained as long as your user account is active, then deleted. |
Personal Data | Legal Basis | Retention Time |
Identity data, Communication, Contact information, Order data, Profile data | Legitimate interest – necessary to manage orders. Fulfilment of agreements – if carried out by an individual company. | Retained for as long as necessary to process your order, and 10 years thereafter for legal requirements. Accounting data stored for 7 years from year-end per Swedish Accounting Act (1999:1078). |
Personal Data | Legal Basis | Retention Time |
Identity data, Communication, Contact information, Order data, Profile data | Legitimate interest – manage customer/supplier relationships. Fulfilment of agreements – if concluded with an individual company. | Retained for as long as there is an active relationship, plus 10 years thereafter. A relationship is active if contact occurred in the previous 12 months. |
Personal Data | Legal Basis | Retention Time |
Identity data, Order data, Profile data, Purchase and order history, Communication history, Activity history | Legitimate interest – evaluate customer/supplier relationships. | Retained for 27 months from collection. Reports without personal data stored indefinitely. |
Personal Data | Legal Basis | Retention Time |
Identity data, Audio/video materials, Communication, Contact information, Order data, Profile data | Legitimate interest – communicate offers in various channels. Consent – for cookies/technologies where applicable. | Retained as long as there is an active relationship, plus 12 months thereafter. If no relationship, retained for 3 months from collection. |
Personal Data | Legal Basis | Retention Time |
User-generated data, Identity data, Contact details, Order data, Technical data | Legitimate interest – communicate and provide offers about services in different channels. | Retained during customer relationship and 12 months thereafter. If no customer relationship, retained for 3 months from collection. |
Personal Data | Legal Basis | Retention Time |
Identity information, Contact information | Legitimate interest – manage newsletter subscriptions. | Retained indefinitely until you unsubscribe. |
Personal Data | Legal Basis | Retention Time |
Identity information, Communication, Contact information, Order information, Organisational information | Legitimate interest – respond to inquiries. | Retained during customer relationship and 10 years thereafter. If no customer relationship, retained for 1 year from last communication. |
Personal Data | Legal Basis | Retention Time |
Identity information, Contact information | Legitimate interest – collect feedback. | Retained during survey period and 3 months thereafter. Non-personal statistics stored indefinitely. |
Personal Data | Legal Basis | Retention Time |
Technical data | Legitimate interest – enable functionality for better user experience. | Retained during your visit and 12 months thereafter. |
Personal Data | Legal Basis | Retention Time |
User-generated data, Technical data | Legitimate interest – monitor and evaluate usage. Includes Leadoo tracking (see Leadoo Privacy Policy). | Retained for 3 months. Non-personal statistics stored indefinitely. |
Personal Data | Legal Basis | Retention Time |
All relevant categories of personal data | Legitimate interest – maintain technical functionality and security. | Retained as long as account is active. Logs kept for 12 months from event. |
Personal Data | Legal Basis | Retention Time |
Necessary personal data for the claim | Legitimate interest – handle/respond to legal claims. | Retained for the period necessary to resolve the claim. |
Personal Data | Legal Basis | Retention Time |
All necessary categories of personal data | Fulfil legal obligation – comply with laws. | Retained as required by each legal obligation. Accounting data kept for 7 years per Swedish Accounting Act. |
Personal Data | Legal Basis |
Identity information, Communication, Contact information | Legitimate interest – carry out events and activities. |
Purpose: Communicate and provide offers in various channels.
Personal Data | Legal Basis |
User-generated data, Identity information, Contact information, Technical data | Legitimate interest – marketing and communication. |
Purpose: Communicate about our services.
Personal Data | Legal Basis |
Identity information, Contact information, Technical data | Legitimate interest – customer communication. |
Purpose: Communication between employees and external individuals.
Personal Data | Legal Basis |
Identity information, Communication, Contact information, Order information | Legitimate interest – facilitate communication. |
Purpose | Legal Basis |
Manage and adhere to legal requirements | Legitimate interest – handle legal requirements. |
Fulfil legal obligations | Legal obligation – comply with law. |
Respond to legal requests | Legal obligation (if required) or legitimate interest (otherwise). |
Category | Examples |
User-generated data | Data provided when using services, websites, or digital channels; clicks, visits, behavioural data. |
Identity data | Name, social security number, username, IP address. |
Communication data | Email content. |
Contact data | Address, phone number, email address. |
Payment and purchase data | Name, date of birth, card type, expiry date, certain card digits, address, phone number, purchase history. |
Order data | Service, delivery time, price. |
Organisational data | Title, company name, company address. |
Profile settings | Information about your user profile when using our services. |