PRIVACY SNAPSHOT

This Privacy Policy explains how Nutrient1 AB collects, uses, shares, and protects your personal information, as well as the privacy rights and choices available to you. It applies to all personal data processed in connection with our websites, digital platforms, and subscription-based products and services (collectively referred to as the “Services”).


In this Privacy Policy, “NUTRIENT 1”, “Nutrient1 AB”, “Nutrient1” “we”, or “us” refers to Nutrient1 AB, a company incorporated in Sweden with organization number: 559524-1109.

1. Information You Provide to Us

We collect personal information that you voluntarily provide when interacting with Nutrient1 AB, including but not limited to when you place an order, create an account, subscribe to a newsletter, participate in a survey, or contact customer support.

1.1 Contact Information

You may provide us with your full name, email address, phone number, shipping and billing addresses, and, where applicable, your company name and VAT number. This information is required to process orders, deliver products, handle invoices, and maintain accurate customer records.

1.2 Account Credentials

When creating an account on our website, we collect a username and password, which are stored securely and encrypted. You may optionally choose to provide additional data associated with your account, such as saved shipping addresses or preferences for subscription frequency and product variants.

1.3 Order and Transaction Data

We retain detailed records of your purchase and subscription history. This includes products ordered, quantities, delivery intervals, payment confirmations, shipment tracking, subscription status (e.g. active, paused, cancelled), and communication related to transactions. This data enables us to fulfill our contractual obligations and to provide timely customer support.

1.4 Payment Information

We do not process or store full payment card or bank account numbers directly. All payments are securely handled by third-party processors (e.g. Stripe or Klarna), depending on the method selected at checkout. However, we may store partial payment data necessary for reconciliation, fraud prevention, or support purposes, such as transaction IDs, payment method used, and the last four digits of a card.

1.5 Customer Communications

We retain records of all communication between you and Nutrient1 AB. This may include inquiries sent via contact forms, emails, social media messages, or live chat interactions. These records are used to verify previous discussions, respond to customer service requests, and improve the quality of our support.

1.6 Surveys and User Feedback

If you choose to participate in customer surveys, feedback forms, or structured interviews, we may collect the information you voluntarily submit. This may include opinions about our products, usage behavior, lifestyle details, or product preferences. In some cases, we may record video or audio if you consent to participate in a research session or feedback call.

1.7 Marketing Preferences

We collect data regarding your choices and engagement with our promotional communications. This includes opt-in status, subscription to newsletters, response rates, and interaction with marketing content (e.g. email open and click behavior), allowing us to tailor our outreach in accordance with your preferences and applicable laws.

2. How We Use Personal Information

We use the personal information we collect for a variety of purposes, as outlined below. The legal bases for processing include: the performance of a contract, compliance with legal obligations, legitimate interests, and, where required, your consent.

2.1 Provision of Services

We process your personal information as necessary to deliver our products and services, including to:

  • Fulfill orders and manage subscriptions

  • Provide customer support and respond to inquiries

  • Issue order confirmations, shipping updates, and renewal reminders

  • Manage your account and preferences
    This processing is necessary to perform our contractual obligations to you.

2.2 Payment Processing and Fulfillment

We use order and billing information to process payments and prevent fraudulent transactions. While payment data is processed by third-party providers, we handle the coordination, confirmation, and record-keeping of financial transactions related to your purchases.

2.3 Service Improvement and Development

We analyze usage data, feedback, and support interactions to:

  • Understand user needs and behavior

  • Improve the functionality and usability of our website

  • Optimize product formulations, customer experience, and packaging

  • Identify and fix errors or service issues

This use is based on our legitimate interest in improving and maintaining our offerings.

2.4 Personalization and User Experience

We may use your account data, preferences, and past purchases to:

  • Suggest relevant subscription plans or complementary products

  • Customize the website interface and user journey

  • Display personalized content and recommendations

This is done to provide a more relevant and user-centered experience.

2.5 Marketing and Communication

We may use your information to send:

  • Newsletters, product updates, and exclusive offers

  • Reminders about subscription renewals or abandoned carts

  • Invitations to surveys, events, or product launches

These communications are sent in accordance with your preferences. Where required, we will obtain your explicit consent before sending marketing materials.

2.6 Interest-Based Advertising

We may share anonymized or pseudonymized data with advertising partners to:

  • Show relevant ads on third-party platforms (e.g. Meta, Google)

  • Create lookalike audiences based on user profiles

  • Track the effectiveness of ad campaigns

Where applicable, this is done only with your consent and in accordance with applicable laws. See our Cookie Policy for more details.

2.7 Legal Compliance and Protection

We process personal information to comply with legal and regulatory obligations, including:

  • Accounting and tax reporting

  • Consumer rights and distance sales regulations

  • Responding to lawful requests from authorities

  • Preventing and detecting fraud, misuse, or security breaches

  • Enforcing our terms of service or defending legal claims

3. How We Disclose Personal Information

We may share personal information with trusted third parties where necessary to operate our business, fulfill our contractual obligations, or comply with legal requirements. We do not sell your personal data.

3.1 Service Providers

We share personal information with vendors who perform services on our behalf, including but not limited to:

  • Hosting and infrastructure (e.g. servers, databases)

  • Website functionality and customer experience tools

  • Email delivery and marketing automation

  • Payment processing (e.g. Stripe, Klarna)

  • Logistics and shipping services
    These providers are contractually bound to process data only in accordance with our instructions and applicable law.

3.2 Payment Processors

Payment card details and financial transactions are handled directly by certified third-party providers. Nutrient1 AB does not store or have access to full card numbers or bank account credentials. We may receive limited transactional metadata (e.g. payment status, method used, transaction ID) for order verification and reconciliation.

3.3 Analytics and Advertising Partners

We may share pseudonymized data with partners that help us:

  • Measure traffic and usage patterns (e.g. Google Analytics)

  • Serve personalized or retargeted ads (e.g. Meta Pixel)

  • Understand ad performance across channels

Any such sharing is limited, subject to consent where required, and governed by contractual safeguards.

3.4 Professional Advisors

We may disclose information to legal advisors, auditors, accountants, and insurers where necessary in connection with audits, legal compliance, risk management, or the exercise or defense of legal claims.

3.5 Authorities and Legal Requests

We may disclose your personal information to law enforcement agencies, regulatory bodies, courts, or other public authorities if:

  • Required to do so by law or legal process

  • Necessary to establish, exercise or defend legal claims

  • We believe in good faith that disclosure is necessary to prevent harm, investigate suspected fraud, or protect our legal rights

3.6 Business Transfers

In the event of a merger, acquisition, restructuring, sale of assets, or other business transfer, personal information may be disclosed as part of the due diligence process or included as a transferred asset, provided that appropriate safeguards are maintained.

3.7 User-Initiated Sharing

If you choose to publicly share content or interact in a way that displays your information (e.g. product reviews, comments, testimonials), that information may become visible to others. We encourage you to use discretion in such contexts.

4. Privacy Rights and Choices

As a data subject under the General Data Protection Regulation (GDPR) and other applicable laws, you have several rights regarding your personal data. Nutrient1 AB is committed to ensuring that your rights are respected and that you can exercise control over your information.

4.1 Access to Your Data

You have the right to request confirmation of whether we process your personal information, and, if so, to receive a copy of that information, including details about:

  • What categories of data we process

  • For what purposes we process it

  • With whom we have shared it

  • How long we retain it

4.2 Correction and Updating

You may request the correction of inaccurate or outdated personal data. Where applicable, you can also update your information directly via your account dashboard.

4.3 Right to Deletion (“Right to Be Forgotten”)

You may request the deletion of your personal data in the following cases:

  • The data is no longer necessary for the purposes for which it was collected

  • You withdraw your consent and no other legal ground applies

  • You object to the processing and there are no overriding legitimate grounds

  • The data has been unlawfully processed
    Please note that we may retain certain data where required by law or for legitimate business purposes, such as tax or accounting obligations.

4.4 Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format and, where technically feasible, to request that we transfer it directly to another data controller.

4.5 Objection to Processing

You may object to our processing of your personal data:

  • When processing is based on our legitimate interests

  • When your data is being used for direct marketing purposes

If you object to direct marketing, we will cease such activity immediately.

4.6 Restriction of Processing

You may request that we restrict the processing of your personal data if:

  • You contest the accuracy of the data

  • The processing is unlawful and you oppose deletion

  • We no longer need the data but you require it for the establishment, exercise or defense of legal claims

  • You have objected to processing pending verification of whether our legitimate grounds override yours

4.7 Withdrawal of Consent

Where we rely on your consent to process personal data, you have the right to withdraw that consent at any time. This does not affect the lawfulness of processing carried out prior to withdrawal.

4.8 How to Exercise Your Rights

To exercise any of your rights, please contact us at:

Email: privacy@nutrient1.com
Postal address: Nutrient1 AB, Sånggatan 5 b, 271 92 Ystad

We may request additional information to verify your identity before fulfilling your request. We aim to respond to all legitimate requests within one month. You will not be charged for exercising your rights unless the request is manifestly unfounded, repetitive, or excessive.

4.9 Complaints to Supervisory Authority

If you believe that our processing of your personal data infringes applicable laws, you have the right to lodge a complaint with your national data protection authority. In Sweden, this is:

Integritetsskyddsmyndigheten (IMY)
Website: www.imy.se

5. Other Sites and Services

Our website and services may contain links to third-party websites, applications, and platforms that are not owned or operated by Nutrient1 AB. In some cases, our content may also be embedded or integrated into third-party services.

5.1 Third-Party Websites and Platforms

We are not responsible for the privacy practices, content, or security of any third-party websites or services that you may access through our site. This includes, but is not limited to:

  • Social media platforms (e.g. Instagram, Facebook, YouTube)

  • External payment gateways

  • Affiliate or partner websites

We recommend that you review the privacy policies of any third-party services you visit or interact with before providing them with personal data.

5.2 Embedded Tools and Integrations

Our services may include integrations such as:

  • Embedded videos (e.g. YouTube, Vimeo)

  • Live chat or chatbot services

  • Website analytics tools (e.g. Google Analytics)

These third-party tools may independently collect data about your interactions, subject to their own privacy policies.

5.3 Disclaimer

The inclusion of third-party links or tools does not imply endorsement by Nutrient1 AB. Any data you share directly with those parties is not covered by this Privacy Policy.

6. Security

We are committed to protecting your personal data and maintaining the confidentiality, integrity, and availability of the information we collect.

6.1 Technical and Organizational Measures

Nutrient1 AB implements a combination of technical, administrative, and physical safeguards designed to prevent unauthorized access, loss, alteration, or disclosure of personal information. These measures include:

  • Secure socket layer (SSL) encryption for data transmission

  • Access controls and user authentication protocols

  • Regular software updates and patching

  • Limited access to personal data on a need-to-know basis

  • Data pseudonymization or anonymization where appropriate

6.2 Third-Party Security Practices

We work exclusively with service providers who meet high data security standards. All third-party processors are contractually obligated to implement appropriate security measures and process personal data in accordance with our instructions and applicable law.

6.3 Limitation of Liability

While we take reasonable and industry-standard precautions to protect your personal information, no system or transmission over the internet is completely secure. Therefore, we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential and for notifying us immediately of any suspected unauthorized use of your account.

6.4 Incident Response

In the event of a data breach or other security incident involving your personal information, we will act promptly to mitigate the impact and notify affected individuals and authorities as required under applicable data protection laws.

7. International Data Transfer

Nutrient1 AB is based in Sweden and stores and processes most personal data within the European Union (EU). However, in certain cases, your personal information may be transferred to and processed in countries outside of the EU or European Economic Area (EEA), including jurisdictions that may not provide the same level of data protection as your home country.

7.1 Transfers to Third Countries

We may engage service providers, partners, or subcontractors located in non-EU countries, including the United States, for services such as:

  • Cloud hosting and data storage

  • Email delivery and marketing automation

  • Payment processing and subscription management
    In these cases, we ensure that appropriate safeguards are in place to protect your data.

7.2 Safeguards for Cross-Border Transfers

When transferring personal data to third countries, we rely on one or more of the following legal mechanisms:

  • The European Commission’s adequacy decisions

  • Standard Contractual Clauses (SCCs) approved by the European Commission

  • Binding Corporate Rules (where applicable)

  • Your explicit consent (in limited cases)

All transfers are made in accordance with Chapter V of the GDPR.

7.3 Your Rights

You have the right to obtain further information about the safeguards applied to any international data transfers concerning your personal data. You may request a copy of the relevant contractual clauses by contacting us at privacy@nutrient1.com.

8. Data Privacy Framework

While Nutrient1 AB is based in Sweden and primarily operates within the European Union, we may work with service providers or partners located in countries participating in the EU-U.S. Data Privacy Framework (DPF), the UK Extension to the DPF, or the Swiss-U.S. DPF.

8.1 U.S.-Based Service Providers

Certain third-party providers that process personal data on our behalf in the United States may be certified under the DPF. This certification confirms their commitment to comply with applicable privacy principles established by the U.S. Department of Commerce in collaboration with the European Commission, the UK government, and Swiss authorities.

We require our U.S.-based providers to maintain appropriate contractual safeguards and DPF adherence where applicable, especially in areas such as cloud hosting, email distribution, and analytics.

8.2 Our Commitment to Secure Transfers

We evaluate each international service provider’s privacy and security practices and rely on recognized legal mechanisms for cross-border transfers of personal data, including:

  • Adequacy decisions

  • Standard Contractual Clauses (SCCs)

  • Data Privacy Framework certification (where applicable)

We take all necessary steps to ensure your personal data is treated in accordance with European data protection standards, even when handled outside the EEA.

8.3 Questions or Complaints

If you have questions or concerns regarding international transfers of your personal data or the use of DPF-certified services, you may contact us at privacy@nutrient1.com. We will respond promptly and work to resolve any issue in accordance with applicable laws and best practices.

9. Children

Our website and services are not intended for, and should not be used by, individuals under the age of 18.

9.1 No Intentional Collection

We do not knowingly collect, process, or store personal data from children under 16 years of age. If we become aware that we have inadvertently collected such data without appropriate parental or guardian consent, we will take immediate steps to delete it.

9.2 Parental Responsibility

If you are a parent or legal guardian and believe that your child has provided us with personal information without your consent, please contact us at privacy@nutrient1.com, and we will promptly investigate and take appropriate action.

9.3 Legal Compliance

We comply with applicable laws concerning the protection of children’s data, including Article 8 of the General Data Protection Regulation (GDPR) and national implementations in EU member states.

10. Job Applicants

If you apply for a position at Nutrient1 AB, either through our website or via third-party recruitment platforms, we collect and process the personal data you provide in connection with your application.

10.1 Information We Collect

As part of the recruitment process, we may collect the following categories of personal data:

  • Contact details (e.g. name, email address, phone number)

  • Curriculum vitae (CV), cover letter, and other documents

  • Employment history and educational background

  • Professional certifications and skills

  • LinkedIn profile or public portfolios

  • Interview notes and evaluations

  • Any additional information you voluntarily submit (e.g. salary expectations, availability)

In some cases, we may also process diversity information that you choose to provide voluntarily (e.g. gender identity, pronouns), in accordance with applicable laws.

10.2 Purpose of Processing

We use applicant data solely for recruitment and evaluation purposes, including:

  • Assessing qualifications and suitability for a role

  • Communicating with candidates throughout the hiring process

  • Scheduling interviews and reference checks

  • Maintaining records of the recruitment process

  • Complying with applicable legal and regulatory obligations

10.3 Data Sharing

Your data may be shared internally with team members involved in the hiring decision. We may also use external recruitment tools or service providers who are contractually bound to protect your data and process it solely on our behalf.

10.4 Data Retention

We retain applicant data for as long as necessary to complete the recruitment process. If your application is unsuccessful, we may retain your data for up to 12 months (or longer with your consent) in case of future openings, unless you request erasure.

10.5 Your Rights

You may contact us at any time to access, correct, or request deletion of your application data by emailing privacy@nutrient1.com.

11. Retention of Personal Information

We retain personal data only for as long as is necessary to fulfill the purposes for which it was collected, including to comply with legal, accounting, or regulatory obligations.

11.1 General Retention Principles

The length of time we retain personal data depends on:

  • The nature and sensitivity of the data

  • The purpose for which it was collected

  • Legal obligations requiring retention (e.g. tax or consumer protection laws)

  • The potential risk of harm from unauthorized use or disclosure

  • Whether you have requested data deletion

When the data is no longer required, it is securely deleted, anonymized, or, where applicable, archived with restricted access.

11.2 Specific Retention Periods

While actual retention periods may vary, the following general guidelines apply:

  • Order and transaction data: Retained for at least 7 years in accordance with Swedish accounting law.

  • Marketing data: Retained until you opt out or withdraw consent.

  • Customer service correspondence: Typically retained for up to 24 months after resolution.

  • Job applicant data: Retained for up to 12 months after the end of the recruitment process unless consent for longer storage is provided.

11.3 Data Deletion and Archiving

Upon request, and where applicable by law, we will delete or anonymize your personal data. Please note that we may be legally required to retain certain data even after your request has been fulfilled.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in legal requirements, operational practices, or our services.

12.1 Notification of Changes

When we make material changes to this Privacy Policy, we will:

  • Update the “last modified” date at the top of this page

  • Publish the revised version on our website

  • Notify you by email or through the website interface where legally required or where we believe it is appropriate and effective

We encourage you to review this Privacy Policy periodically to stay informed about how we protect your personal data.

12.2 Effective Date

Unless stated otherwise, any updates to this Privacy Policy will become effective upon publication on our website. Your continued use of our services following such updates constitutes your acceptance of the changes.

13. How to Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or how we handle your personal data, you are welcome to contact us using the details below:

Nutrient1 AB
Org.nr: 559524-1109
Email: privacy@nutrient1.com
Website: www.nutrient1.com
Postal address: Sånggatan 5 b, 271 92 Ystad

We will do our best to respond promptly and in accordance with applicable data protection laws, including the General Data Protection Regulation (GDPR).

Privacy Policy last modified: 2025-05-28