Privacy and Security Statement


Last updated 22 October 2025
Gudrun Sjödén Sverige AB (556193-8233) is responsible for the personal data that you entrust to us (when you register with us, shop in our stores, online or via phone, fax and letter, or if you make a complaint). When you do so, you also consent to us storing and using these data to enable us to meet our obligations to you, for direct marketing purposes, to enable us to develop our products and services, and to provide you with the best possible service. Your data are not disclosed to or shared with any third party for marketing purposes outside of Gudrun Sjödén.

 

Data protection and transfer of data to third parties and third countries
The personal data used by GSAB and our system suppliers (data processors) are protected and are processed in compliance with applicable data privacy laws.
In the rare cases when we may share your personal data with processors in a so-called Third country, i.e. a non-EU country, the data transfer is protected by standard contractual clauses in combination with additional safeguards (encryption, pseudonymisation). In applicable cases, we apply the EU-U.S. Data Privacy Framework for data transfer.
Under the General Data Protection Regulation (GDPR), you are entitled to see the information we hold about you. If you wish to make changes to the information (because you feel it is inaccurate, incomplete or irrelevant), simply log in to “My Account” on our website or contact our customer services. You can also change your preferences or unsubscribe from our marketing emails there. Would you like to be removed from our database? Please contact our customer services. You are welcome to contact us at order@gudrunsjoden.co.uk. 
We retain your data while you are an active customer with us. Please see below for more details.

 

Privacy statement - online purchases
We use data such as your name, address, email address, phone number, payment details, payment history and order information so that we can process the purchases you make in our webshop. If you choose to pay by invoice, we will also use your personal ID number.
We use your data to process your order and any returns, to notify you of delivery status, manage payments and provide you with the best possible service when you contact us.
We only keep your data while you are an active customer and while you have the right to complain, i.e. 36 months after you made your last purchase.
Processing of your personal data is essential to allow Gudrun Sjödén to provide the service to you and to deliver your order. The legal bases for processing are the “Execution of a contract” and “Legitimate interest”.

 

Privacy statement - marketing
We use your personal data to send you marketing offers, information surveys and invitations through emails, text messages, phone calls and postal mail.
In order to do this, we process your name, email address, phone number and your postal address. We also use data about products that you have purchased or shown an interest in to get to know you and be able to offer you information about products that we think you might like.
We also collect information on how you interact with our newsletters (e.g. what you open and click on) and how you navigate our website and which products you browse. This information is used to ensure that we can better target you with offers that are relevant to you.
Processing of your personal data is based on your consent when you agree to receive marketing communications. The exception to this is direct marketing communications via postal mail, including catalogues, which are sent to you based on our legitimate interest (after a balancing of interests).

 

Use of pseudonymised email addresses
To better understand our services and your experience of our webshop, we use pseudonymised email addresses. This means that your email address is converted into a pseudonym (a code) that cannot be traced back to you without additional information. This processing of your data helps us to analyse and optimise our marketing and to better understand the needs and preferences of our customers.

We ensure that all processing of your personal data is carried out in compliance with applicable data protection legislation, including GDPR. Your rights are fully respected and you have the right at any time to withdraw your consent to the use of pseudonymised email addresses. You can do this via My Account. Should you withdraw your consent, we will immediately cease to process your pseudonymised email addresses.

If you have any questions about how we process your personal data, please contact us at order@gudrunsjoden.co.uk
 

Privacy statement - My Account
We process your personal data to make it easy for you to access and manage your personal information, such as contact details, order history, order and subscription details.
To be able to do this, we use the data that you choose to provide us with, for example, your name, phone number, address, email address, order history and customer number.
Processing of your personal data is based on Gudrun Sjödén’s legitimate interests (after a balancing of interests).

 

Privacy statement - Gudrun Sjödén Club membership
To allow you to enjoy the benefits associated with our club, we process your personal data to give you access to our member offers, bonuses, gifts and invitations to events and competitions. We use data such as your name, address, email address, phone number, customer number and order history to be able to do this. We will retain your data for as long as you are an active customer, i.e. 10 years after you made your last purchase. You can log into My Account at any time, or call customer services, to manage your subscriptions.
It is necessary to process your personal data to provide you with Gudrun Sjödén Club services. The legal bases for processing are “performance of a contract” and “consent” for personalised advertising.

 

When you are a member of the Gudrun Sjödén Club
We need to process your personal data in order to be able to create and manage your membership in the Gudrun Sjödén Club. Without the data, we are unable to register or manage your membership. If you choose not to provide us with your personal data, you will not be eligible for membership.
Based on your member profile, we may send you marketing about our products through various digital channels. You always have the right to refuse marketing information from us if you do not wish to receive it. For further details on your rights, please see the section on marketing.
To create and manage your membership and member account, we obtain and process details about you, such as your name, address, email address, mobile phone number, membership number, personal ID number, username, password and the settings and preferences that you choose to make in your member profile. The processing includes, among other things, verifying your identity and age, creating a login for My Account, maintaining correct and current data, and providing a quick and easy way to create membership.
The legal basis for processing your personal data is that it is necessary for the performance of a contract as it enables us to create and manage your membership in accordance with our terms and conditions of membership. We will retain your personal data for as long as you are a member with us. If your membership has been inactive for 10 years, i.e. you have not registered any membership purchases during this period, your membership and associated details will be deleted, provided you do not have any outstanding debt with us.
To manage your bonus, we process details about you, such as your name, contact details, purchase and order history, and, in some cases, personal ID number or date of birth. We process this information so that you can collect bonus points on purchases, receive bonus payouts, identify yourself as a member when you make purchases, get information about your current bonus status, and be offered cardless membership in our stores. It is necessary for us to process this information in order to perform our contract with you in accordance with our terms and conditions of membership.
When processing cardless membership, the legal basis for the processing of your personal ID number is our legitimate interest in being able to identify you as a member and provide a smooth membership experience so that you do not miss out on bonus-eligible purchases. The points that you earn are saved for 24 months or until your membership ends.
We also process details about your purchase and order history to enable you to view and track your current and past purchases. The legal basis for processing these details is that it is necessary for the performance of a contract as it enables us to manage your member account in accordance with our terms and conditions of membership. The data are processed for 36 months from the date on which the purchase was made.

 

Privacy statement - newsletter
When you choose to subscribe to our newsletter, we process your personal data in order to be able to send you inspiration, information and relevant offers. We collect and process your name and email address to enable us to manage your subscription.
We process your personal data based on your consent, which you give when you subscribe to the newsletter. You can withdraw your consent at any time by clicking the unsubscribe link found in every newsletter or contacting our customer service team.
We will retain your data for as long as you remain subscribed to our newsletter. If you have been inactive (i.e. have not opened or acted upon our newsletters) for a period of 36 months, your data will automatically be removed. If you unsubscribe, we will immediately stop sending you newsletters and your personal data will be deleted within a reasonable period of time.

 

Privacy statement - customer services
To enable us to provide an optimal service when you require information about our products, technical support or advice via email, our chat service, phone or our social media platforms, we need to process your data, such as contact details (name, address and phone number), date of birth, payment details and history, credit information, order information, account or customer number, and any previous correspondence.
We retain any personal data contained in telephone calls for 90 days, data in email correspondence for 24 months and other data about you for 36 months after your last purchase. 
Processing of your personal data is based on Gudrun Sjödén’s legitimate interests (after a balancing of interests).

 

Data subject’s rights
You have certain rights in relation to the processing of your personal data. What these rights are, what they mean and how you exercise them is explained below.

 

Right of access
We aim to be transparent in all aspects of how we manage your personal data. If you wish to receive information on our processing of personal data relating to you, you have the right to request access to your data. If we receive a request to exercise the above right, we may ask for further details to verify your identity before acting on the request.

 

Right to rectification
Is any of the data that we hold about you out-of-date or inaccurate? If so, you have the right to ask us to correct the information. If you have a user account with us, you are able to update your details yourself and view your latest order history there.

 

Right to erasure and right to restriction
You have the right to request the deletion of your personal data and the right to restrict processing of your personal data if, for example, you consider that your data are being processed in violation of applicable laws.

 

Right to object to processing
You have the right to object to us processing your personal data (for example, processing based on our legitimate interests), including the right to object to processing for direct marketing purposes and automated decision-making. Your personal data may not be processed for direct marketing purposes if you object to such processing. If you object to our direct marketing, we will stop sending all forms of communications to you. If you would still like to receive communications via certain channels, you do not have to object to all types of marketing. In which case you can choose to only receive offers from us in the channels that you select, e.g. by email but not text message.
You have the right to object to a decision that has been made by automated processing when it has an adverse legal or similarly significant effect on you. This does not apply if the decision is necessary, for example, for entering into, or the performance of, a contract with you (such as for credit applications).
You also have the right to submit a complaint to the authority for privacy protection. More information can be found on the website of the Swedish Authority for Privacy Protection imy.se.

 

Right to withdraw your consent
In circumstances where you have given us permission to process your personal data, you have the right to withdraw your consent at any time. If you withdraw your consent for data processing, no further data based on that consent will be collected about you. However, we still have the right to process the data that we collected before you withdrew your consent. We will erase the data unless another legal basis requires us to retain them.

 

Right to data portability
Where the legal basis for our processing of the personal data that you have given us is consent or is necessary for the performance of our contract with you, you have the right to ask us to transfer the data to another data controller.
Your right to lodge a complaint with the supervisory authority    
You have the right to file a complaint with the supervisory authority responsible for data protection if you believe that we are not processing your personal data correctly.

 

How do I exercise my rights?
If you want to exercise any of your privacy rights, please contact our customer service team. You are welcome to contact us at order@gudrunsjoden.co.uk

 

Privacy statement - competitions
When you take part in our competitions, we process your data in order to be able to contact you with information about the competition, to contact the winners and to send out and follow up prizes.
To be able to do this, we process your contact details (name, address and phone number), possibly your email address and information that was sent in for the competition.
We retain these data until the competition has ended and the winners have been contacted.
Processing of your personal data is based on your consent when you choose to take part in a competition.
#yesgudrun
Gudrun Sjödén wants to see products in real life on social media and we may ask you to share images that you post on Instagram or Facebook on our channels. These channels are primarily Gudrun Sjödén websites (gudrunsjoden.com), but may also include Gudrun Sjödén newsletter, Gudrun Sjödén Facebook, Gudrun Sjödén Instagram and other Gudrun Sjödén channels.
By answering with #yesgudrun on an image after a request from Gudrun Sjödén on Instagram or Facebook, hereafter referred to as “the image(s)”, you agree to grant Gudrun Sjoden Group AB (Gudrun Sjödén Design & Produktion AB, Gudrun Sjoden AS, Gudrun Sjoden ApS, Gudrun Sjoden OY, Gudrun Sjoeden GmbH, Gudrun Sjoden HK Ltd, Gudrun Sjödén Sverige AB, Gudrun Sjoden UK Ltd, Gudrun Sjoden US Inc, Gudrun BV, Gudrun Sjoden FRA S.A), a Swedish company with CRN 556438-3148 (hereafter referred to as Gudrun Sjödén), a non-exclusive, royalty-free, worldwide licence to use, at its own discretion and without any obligations to you, your images and photographs where you can be identified, including inter alia the right to reproduce, distribute, modify and edit your photographs for the purposes of marketing and/or advertising, in accordance with the Swedish Act on Names and Pictures in Advertising (Sw: Lag om namn och bild i reklam) (1978:800).
You acknowledge and guarantee that you own or have the rights to use the submitted material and that you have obtained the permission of those people who appear in the photographs. Furthermore, you warrant that you are a private individual (i.e. not a business), that you are at least 18 years old or have your parents’ consent, and that Gudrun Sjödén’s use of your images does not infringe any third party right or violate any law.
You hereby release Gudrun Sjödén from any obligation to pay for the use of your images, and you further agree to indemnify and hold Gudrun Sjödén, and any persons acting on behalf of Gudrun Sjödén, harmless from any and all claims (including from third parties) and liabilities, of any nature, arising out of or relating to the above described use of the images.
These terms and conditions shall be governed by and construed in accordance with Swedish law, and an appropriate court in Stockholm shall have sole jurisdiction over any dispute arising in relation to these terms and conditions.
You can always contact us if you have any questions about our services or data protection: order@gudrunsjoden.co.uk
If you wish to withdraw your consent to share your images with Gudrun Sjödén, please contact us by clicking on the “i” symbol in the bottom left-hand corner of the shared image published on our website. This symbol takes you to a form where you can request to withdraw your consent.

 

Privacy statement - cookies and our webshop

Cookie Settings

Cookies
When you visit a website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your language preferences or your device and is mostly used to make the site work as you expect it to. We collect information about how visitors interact with our website. The information includes clicks, scrolls, pages and products viewed, mouse movement, session duration, device, browser, operating system, IP address and geographic location. In some cases, we also use the information to analyse behaviour patterns, run A/B tests and customise content for you. This information is used to enhance the functionality of our website, analyse user behaviour and optimise our marketing activity. The information will only be processed after receipt of your consent, provided when you accept cookies in our cookies banner, for us to use performance and targeting cookies. The data will be retained for a period of 13 months.

The information does not usually directly identify you, but it can give you a more personalised online experience. Because we respect your right to privacy, you can choose not to allow some types of cookies. If you disable some types of cookies, your experience of using our website and the services we offer may be affected. You can withdraw your consent or change settings at any time via our cookies banner at the bottom of the page.

 

Strictly necessary
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.

 

Functional Cookies
These cookies enable the website to provide enhanced functionality and personalisation. They may be set by us or by third party providers whose services we have added to our pages. If you do not allow these cookies, then some or all of these services may not function properly.

 

Performance Cookies
These cookies allow us to count visits and traffic sources so we can measure and improve the performance of our site. They help us to know which pages are the most and least popular and see how visitors move around the site. Information collected through these cookies is aggregated and therefore anonymous. If you do not allow these cookies, we will not know when you have visited our website.

 

Targeting cookies
These cookies are set by our advertising partners on our website. They can be used by these companies to build a profile of your interests and show you relevant adverts on other websites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will have a less targeted experience.


Encryption
We use encryption technology in our webshop to protect your information. SSL stands for Secure Sockets Layer and ensures that all information transmitted between the buyer and seller is encrypted.

 

Links
Here on www.gudrunsjoden.com you may find links to other websites. Gudrun Sjödén Sverige och Produktion AB is not responsible for the privacy practices of these websites and does not accept any liability in connection with their content.

 

Copyright
All content on this website is protected by international copyright laws.

 

Data controller – Gudrun Sjödén Sverige AB, company reg. no. 556193-8233.