PRIVACY POLICY
Last updated: 2026-06-16
This privacy policy describes how Swopti AB ("we", "us") collects, uses, and shares your personal data when you visit, use, or make a purchase at swopti.co or otherwise communicate with us.
Swopti AB, company registration number 559484-4713, is the data controller for the processing of personal data carried out within the scope of our services. We value your privacy and want you, as our customer, to feel confident in how we handle your data.
WHAT INFORMATION WE COLLECT
You may directly or indirectly provide information about yourself in several ways, for example when you place an order, contact our customer service, register an account, or sign up for our newsletter. This may include:
Contact details: name, address, billing address, shipping address, email address, phone number.
Prescription and lens-related data: sphere, cylinder, axis, addition (ADD), pupillary distance (PD), pupil height, and other optical information required to manufacture your lenses. This data is classified as health data under GDPR and is treated with particular care.
Order information: the products you have ordered, quantities, and amounts.
Payment method and status: payment details and transaction status. The card details themselves are not stored by us but are handled by our payment provider.
Account information: username, password, order history, and preferences if you register an account.
Communications with us: information you provide when contacting our customer service, including correspondence via email, chat, or other channels.
Technical information: IP address, device type, browser, language settings, and other information about how you use our website.
HOW WE PROCESS YOUR PERSONAL DATA
We process your personal data for the following purposes. For each purpose, we set out which data is processed, the legal basis we rely on, and how long the data is retained.
Orders and purchases
Purpose: to receive, process, and deliver your order.
Processing activities: verifying your identity, handling payment, forwarding order information to our lens lab for production, coordinating delivery, handling complaints and warranty matters.
Personal data: name, contact details, shipping address, billing address, payment method, order information.
Legal basis: performance of a contract (Article 6.1.b GDPR).
Retention period: up to 7 years in accordance with the Swedish Accounting Act.
Prescription and lens data
Purpose: to manufacture lenses according to your specific vision.
Processing activities: storing prescription data linked to your order, and transferring it to our lens lab which needs the information to manufacture the correct lenses.
Personal data: sphere, cylinder, axis, addition, pupillary distance, pupil height, and other optical parameters.
Legal basis: your explicit consent (Article 9.2.a GDPR). Prescription data is classified as health data and is only processed with your consent. You provide this consent when placing your order.
Retention period: up to 7 years, linked to your order and in accordance with the Swedish Accounting Act.
You can withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal, and may mean that we are unable to complete ongoing or future orders.
Customer service
Purpose: to handle inquiries, complaints, and other communication with you.
Processing activities: communication via email, chat, or other channels, complaint investigation, identification when handling inquiries.
Personal data: name, contact details, correspondence, case-related information.
Legal basis: legitimate interest (Article 6.1.f GDPR). The processing is necessary to serve our and your interest in handling customer service matters.
Retention period: up to 2 years after the most recent contact.
Marketing and newsletters
Purpose: to send relevant information and offers about our products and services.
Processing activities: sending newsletters by email or SMS, measuring open rates and clicks to adapt the content, personalisation based on purchase history.
Personal data: name, email address, possibly phone number, purchase history, click and visit history.
Legal basis: consent (Article 6.1.a GDPR) for those who have signed up to our newsletter, or legitimate interest (Article 6.1.f GDPR) for those who have made a purchase with us.
Retention period: until you unsubscribe. You can unsubscribe at any time via the link in each communication or by contacting us.
Improvement of our services
Purpose: to evaluate, develop, and improve our products, services, and website.
Processing activities: analysis of user behaviour, customer surveys, generating aggregated statistics.
Personal data: purchase history, click and visit history, technical information about device and browser.
Legal basis: legitimate interest (Article 6.1.f GDPR).
Retention period: up to 3 years.
Security and fraud prevention
Purpose: to protect our services and customers against fraud and misuse.
Processing activities: monitoring of suspicious activity, investigation of potential fraud, safeguarding IT security.
Personal data: IP address, click and visit history, technical information about device.
Legal basis: legitimate interest (Article 6.1.f GDPR), or legal obligation (Article 6.1.c GDPR) where applicable.
Retention period: up to 36 months.
Legal obligations
Purpose: to comply with obligations under applicable law, for example accounting, tax, and product liability.
Processing activities: storage of transaction data, handling of authority requests, documentation of product liability matters.
Personal data: name, contact details, transaction data, order history.
Legal basis: legal obligation (Article 6.1.c GDPR).
Retention period: up to 7 years in accordance with the Swedish Accounting Act, longer where required by other legislation.
WHO WE SHARE YOUR PERSONAL DATA WITH
To operate our service, we share personal data with a number of suppliers and partners. All are bound by contracts that regulate how the data may be processed, and we share only the data necessary for each purpose.
To fulfil your order
Our lens lab. Prescription data and necessary order information is shared with the laboratory that produces and fits your lenses. The laboratory acts as a data processor on our behalf and is bound by a signed data processing agreement that regulates how the data may be processed. Geographic location: EU/EEA.
Our third-party warehouse. To handle the dispatch of return kits, which you use to send your frame to us, we share necessary contact and delivery details with our logistics provider. The logistics provider acts as a data processor on our behalf and is bound by a data processing agreement. Geographic location: EU/EEA.
LensAdvisor (LensAdvisor Pte Ltd). To handle and store your prescription data in connection with your order, and to forward order information to our lens lab, we use a specialised application. LensAdvisor acts as a data processor on our behalf and is bound by a data processing agreement. Geographic location: Singapore with data hosted in the United States with Amazon Web Services and Salesforce (Heroku). Transfers are made under the European Commission's Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable.
Google LLC. When you upload a prescription image, Google's services are used by our order partner to automatically extract the data from the image. Sub-processor to LensAdvisor. Geographic location: United States, with the EU-US Data Privacy Framework and Standard Contractual Clauses.
SendGrid (Twilio Inc.). Used by LensAdvisor to send order information to our lens lab by email. Sub-processor to LensAdvisor. Geographic location: United States, with Standard Contractual Clauses.
Shopify (Shopify International Ltd). Our e-commerce platform processes orders and technical aspects of the website on our behalf. It also sends order confirmations and delivery confirmations to you. Data processor. Geographic location: EU/EEA and the United States, with applicable safeguards under GDPR.
Shopify Payments. Transaction data at payment is handled by Shopify Payments. Acts as a controller for its own processing. Geographic location: EU/EEA and the United States, with applicable safeguards under GDPR.
PostNord. For shipping return kits to you and delivery of finished glasses, we share necessary delivery information. Acts as a controller for its own processing. Geographic location: EU/EEA.
Sendif (LensAdvisor Pte Ltd). Sends certain reminders and status messages during the order process, for example to upload a prescription or mark pupil height. Operated by the same data processor as LensAdvisor and covered by the same data processing agreement. Geographic location: Singapore with data hosted in the United States. Transfers are made under the European Commission's Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable.
For accounting and finance
Numerra. To handle invoicing and accounting, order-related data is shared with our accounting partner. Data processor. Geographic location: EU/EEA.
For customer service and communication
Gorgias. Our customer service system handles all communication with you via email, chat, and other channels. Data processor. Geographic location: EU/EEA and the United States, with applicable safeguards under GDPR.
Klaviyo. Our platform for email marketing and newsletters. Data processor. Geographic location: EU/EEA and the United States, with applicable safeguards under GDPR.
For reviews and customer content
Judge.me. Handles publication of customer reviews. Data processor. Geographic location: United States, with applicable safeguards under GDPR.
Cevoid. Handles customer-generated content such as images and reviews displayed on our website. Data processor. Geographic location: EU/EEA and the United States, with applicable safeguards under GDPR.
For affiliate programme
Addrevenue. To track affiliate conversions, certain order data is shared. Acts as a controller for its own processing. Geographic location: EU/EEA.
For marketing and analytics
The following tools are used only after you have given your consent via our cookie banner. You can change your settings at any time.
Meta (Facebook/Instagram). Platform for retargeting and conversion measurement on social media. Acts as a controller for its own processing. Geographic location: United States, with Standard Contractual Clauses.
Google Analytics and Google Ads. Tools for web analytics and advertising. Act as controllers for their own processing. Geographic location: United States, with Standard Contractual Clauses.
Contentsquare. Tool for analysing visitor behaviour on our website. Data processor. Geographic location: EU/EEA and the United States, with applicable safeguards under GDPR.
TripleWhale and BeProfit. Tools for analysing order and sales data. Data processors. Geographic location: United States, with Standard Contractual Clauses.
For cookie management
Consentik. Handles your consent settings for cookies and tracking. Data processor. Geographic location: EU/EEA.
For data synchronisation
Zapier. We use Zapier to synchronise data between our e-commerce system and external tools. Data processor. Geographic location: United States, with applicable safeguards under GDPR.
Authorities. Where required by law or upon a valid request, we may disclose data to authorities such as the Swedish Tax Agency, the Police, and similar bodies.
WHAT WE DO NOT DO WITH YOUR DATA
We never sell your personal data to third parties.
WHERE WE STORE YOUR PERSONAL DATA
We always aim to process your data within the EU/EEA. In some cases, data may be processed outside the EU/EEA by our suppliers, as specified above. Where this occurs, we ensure that the transfer takes place on a lawful basis, for example through the European Commission's Standard Contractual Clauses, the EU-US Data Privacy Framework, or transfers to countries that the EU has determined provide an adequate level of protection.
SECURITY
We take appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or misuse. This includes encrypted transmission, access restrictions, and regular review of our security routines.
As prescription data is classified as health data, we process it with particular security measures, including access restrictions and encrypted storage.
We cannot, however, guarantee complete security when information is transmitted over the internet. We recommend that you do not send sensitive personal data via unsecured channels.
COOKIES
Our website uses cookies to enhance your experience, analyse traffic, and enable certain functions. On your first visit, you will be given the opportunity to choose which cookies you accept via our cookie banner.
You can change your cookie settings at any time by clicking Cookies in the footer.
YOUR RIGHTS
Under GDPR you have the following rights:
Right of access. You can request a copy of the personal data we hold about you.
Right to rectification. You can request that we correct inaccurate or incomplete data.
Right to erasure. You can request that we erase your personal data, subject to certain exceptions. Some legal obligations may prevent us from erasing data immediately, for example under the Swedish Accounting Act.
Right to restriction. You can request that we restrict processing in certain cases, for example while we investigate a potential inaccuracy.
Right to data portability. You can request to receive your data in a structured format, or to have it transferred to another data controller.
Right to object. You have the right to object to processing based on legitimate interest, including direct marketing.
Right to withdraw consent. Where processing is based on your consent (for example processing of prescription data or newsletters), you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
To exercise any of these rights, contact us at hello@swopti.co. We will respond to your request within 30 days.
COMPLAINTS TO THE SUPERVISORY AUTHORITY
If you consider that we process your personal data in a manner that breaches GDPR, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY). You can contact IMY at imy@imy.se or via imy.se.
CHANGES TO THIS PRIVACY POLICY
We may update this privacy policy from time to time. In the event of material changes, we will notify you by email or via our website. The most recent version is always available at swopti.co.
CONTACT
If you have questions about this privacy policy or about how we process your personal data, please contact us at:
Swopti AB
Alingsåsvägen 30
121 48 Johanneshov
Sweden
hello@swopti.co