Privacy Policy

Last updated: August 2026

Summary

Wellth AB processes your personal data to deliver health services under GDPR and Swedish healthcare law. We never sell your data. You can access, correct, or delete your data at any time.

1

Data Controller and Legal Basis

Wellth AB, org. nr. 559111-9036, Västra Norevägen 9, 181 32 Lidingö, Sweden, is the data controller. Processing complies with the GDPR.

Processing is based on: (a) performance of a contract, (b) legal obligations, (c) legitimate interest, and (d) your consent for specific activities.

Wellth is registered as a healthcare provider with the Swedish Health and Social Care Inspectorate (IVO). Processing is carried out in accordance with Swedish healthcare legislation.

Health data is a special category of personal data. We process it under Article 9(2)(h) of the GDPR — the provision of health care — and the Patient Data Act (2008:355).

Your name, personal identity number and contact details are required for us to order a test and keep a patient record. Without them we cannot deliver the service.

2

Purposes of Processing

We process your personal data to:

  • Deliver services and products (blood tests, supplements, health reports)
  • Process billing and payments
  • Make test results and medical records available to you
  • Provide customer service and support
  • Comply with the Patient Data Act (2008:355), the Health and Medical Services Act (2017:30), and the duty of confidentiality under the Patient Safety Act (2010:659)
  • Send newsletters and marketing (with your consent)
  • Develop and improve our services
3

Personal Data We Collect

  • Identity: First name, surname, personal number (personnummer), gender
  • Contact details: Billing and delivery address, email, phone
  • Payment: Data required to process payments
  • Health data: Test results, blood values, questionnaires, physician comments, medical records
  • Service/product: Tests, analyses, or supplements you have ordered
  • IT data: IP address, browser type, operating system
  • Authentication: BankID or other identification service data
4

Recipients of Personal Data

We never sell your data. We share data only when necessary:

  • Laboratories and clinics: Sampling and analysis of blood tests
  • Physicians and health experts: Analysis and comments on test results
  • Suppliers and carriers: Product delivery
  • Payment providers: Secure payment processing
  • IT providers: Operation and maintenance of infrastructure
  • Public authorities: When required by law

Sensitive health data is only accessible to personnel entitled to access it under law.

5

Data Retention

  • Patient records: 10 years from the last entry (Patient Data Act)
  • Accounting records: 7 years (Swedish Bookkeeping Act 1999:1078)
  • Account data: As long as your account is open

You may close your account at any time. Data is deleted when no longer required for legal retention.

6

Erasure and Anonymisation

Personal data is erased or anonymised when no longer needed. Before data is used for statistics, it is anonymised so it can no longer be linked to you. Erasure is irreversible.

7

Data Security

We protect your data with the technical and organisational measures required by Article 32 of the GDPR. How we do that is set out on our security page.

If your data is affected by a security incident, we will contact you per GDPR Article 34.

8

Cookies and Tracking

  • Necessary cookies: For the website to function — login, basket, currency and your cookie choice
  • Visitor statistics: We use Plausible, a privacy-friendly service that sets no cookies and stores no personal data. It is hosted in the EU and cannot identify you or follow you across sites.
  • Advertising cookies: We do not use any.

No identifying information is stored through cookies. Manage preferences via the cookie banner or browser settings.

9

Your Rights

Under GDPR, you have the right to:

  • Withdraw consent at any time, without affecting prior processing
  • Restrict or object to processing
  • Access a report of how your data is processed (normally within one month)
  • Rectify inaccurate or incomplete data
  • Erase data not required for legal obligations
  • Data portability — receive your data in a machine-readable format

You always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.

10

Contact

Wellth AB · Org. nr. 559111-9036
Västra Norevägen 9, 181 32 Lidingö, Sweden
[email protected]