LEGAL

Privacy Policy

Last updated 26 July 2026

1. About this policy

This policy explains how Gram handles personal data in connection with our website at getgram.eu, our application at app.getgram.eu, and our communications with you (together, the "Service").

It does not cover the websites or services of third parties, including the e-commerce platforms you export data from, the authorities and producer responsibility organisations you file with, or any site we link to.

2. Who is responsible

The Service is operated by the business trading as Gram. You can reach us about anything in this policy at hello@getgram.eu.

Gram is currently operated in Sweden and is in the process of being established as a company. We will update this policy with our full legal and registration details once that is complete.

3. Two different roles

We handle personal data in two distinct capacities, and your rights work differently in each.

CapacityWhat it covers
ControllerData about you as a user and as a business contact: your account, your settings, your enquiries and waitlist submissions, our correspondence with you, and technical and usage data about how the Service is used. Sections 4 to 7 apply.
ProcessorData you upload or enter into the application about your business, your suppliers, your colleagues and your operations. You decide what goes in and why; we process it on your instructions in order to run the Service for you. Section 8 applies.

4. Personal data we process as controller

Account data. Your email address, a salted hash of your password, the date your account was created, and whether the account has administrative rights. We do not store your password itself.

Settings and preferences. The email address you nominate to receive reminders, your reminder lead times, self-declared figures you enter such as annual turnover per market, and record of which in-app notices you have dismissed.

Enquiry and waitlist data. When you submit a form on our website, we receive the information you provide. Depending on the form, this may include your name, email address, telephone number, the free-text content of your message, the topic you selected, your store address, the e-commerce platform you use, the markets you ship to, an estimate of your monthly order volume, and which page you submitted from.

Correspondence. The content of emails, calls and messages between us, and records of when they took place.

Technical and usage data. Information about your device and how the Service is used, including IP address, browser and device type, approximate location derived from IP address, the pages and features accessed, timestamps, referring pages, and technical error information. This is collected through our hosting provider and our product-analytics provider.

5. Where the data comes from

From you, when you fill in a form, create or use an account, or contact us. Automatically from your device and browser when you use the Service. From the files and entries you submit to the application.

PurposeLegal basis (Regulation (EU) 2016/679)
Create, administer, secure and provide access to your accountPerformance of a contract, Article 6(1)(b)
Provide the Service and produce the output you ask forPerformance of a contract, Article 6(1)(b)
Manage waitlist and early-access requests, and respond to enquiriesPerformance of a contract or steps prior to entering one, Article 6(1)(b), and our legitimate interests, Article 6(1)(f)
Send the reminders you have switched onPerformance of a contract, Article 6(1)(b)
Send service messages, such as security notices, changes to our terms, and notice of pricing changesPerformance of a contract, Article 6(1)(b), legal obligation, Article 6(1)(c), and our legitimate interests, Article 6(1)(f)
Keep the Service secure, prevent and investigate abuse, and troubleshoot faultsOur legitimate interests, Article 6(1)(f)
Understand how the Service is used, and improve and develop itOur legitimate interests, Article 6(1)(f)
Send occasional relevant updates to business contacts about the ServiceOur legitimate interests, Article 6(1)(f). You can opt out at any time
Comply with legal obligations, including accounting and tax obligationsLegal obligation, Article 6(1)(c)
Establish, exercise and defend legal claimsOur legitimate interests, Article 6(1)(f)

Where we rely on legitimate interests, we have considered the effect on you and use the minimum data needed for the purpose. You can ask us for our assessment, and you can object as described in section 12.

7. What we do not want, and do not knowingly collect

The Service is designed so that your customers' personal data is neither needed nor stored.

When you upload an order export, it is read using a fixed list of permitted columns. Columns that appear to contain names, email addresses, telephone numbers or postal addresses are filtered out, their contents are not carried into the Service, and any sample of them shown to you during review is masked. The uploaded file itself is held in temporary storage only for as long as the processing session needs it, and abandoned sessions expire within one hour.

What the application does retain from an order export is limited to the order reference, the order date, the destination country, the item identifier, the item title, the quantity, and the order tags.

We cannot rule out that personal data reaches us despite this, because some of the fields we retain are free text under your control. Order tags, item titles, product and supplier names, notes and uploaded documents can all contain personal data if you or one of your apps place it there. Where that happens we hold it as processor on your instructions, and we ask you not to put personal data into those fields.

8. Data we process on your behalf as processor

When you use the application, the following may be entered or uploaded by you and stored in your account:

  • order-derived records: order reference, date, destination country, item identifier, item title, quantity, tags;
  • product, packaging and supplier records, including supplier names and supplier contact email addresses;
  • your company details, including company name, registration number and address;
  • names, titles and places of the individuals who draft, verify or sign a declaration of conformity; and
  • documents you upload, including supplier declarations, certificates and test reports, whose contents are determined by you.

We process this material only to provide the Service, on your instructions, and in accordance with our agreement with you. We do not use it for our own purposes, do not sell it, and do not use it to train machine-learning models.

We access it where necessary to provide the Service, to give you support, to investigate and correct faults, to keep the Service secure, to operate and migrate our infrastructure, and to comply with law. Access is limited to those of our personnel and providers who need it for those purposes.

If you issue a declaration of conformity, certain fields become publicly accessible without authentication at a verification address, including your company name and registration number and the name and title of the signatory. That publication happens on your instruction, and it is your responsibility to have a lawful basis for it and to inform the signatory.

A data processing agreement under Article 28 of Regulation (EU) 2016/679 is available on request.

If you are an individual whose data was entered into the application by one of our customers, please direct your request to that customer, who decides how it is used. We will assist them in responding.

9. Who we share personal data with

We do not sell personal data, and we do not use it for advertising or share it with advertising networks.

We share it with the following categories of recipient, each only to the extent needed for the purposes above:

  • cloud application hosting, within the EU;
  • managed database hosting, within the EU;
  • transactional email delivery, for reminders and service messages;
  • web form handling, for submissions from our website;
  • product analytics, hosted in the EU;
  • professional advisers, such as lawyers and accountants, where needed;
  • authorities, courts and regulators, where we are legally required to disclose or where necessary to establish or defend legal claims; and
  • an acquirer or successor, in connection with a reorganisation, financing, merger, or sale of our business or assets, in which case we will require it to handle personal data consistently with this policy.

Our providers act on our instructions and are bound by written terms that restrict what they may do with personal data.

If you are a customer and need to know which specific providers we use, ask us at hello@getgram.eu. We will publish a named list of our sub-processors alongside our data processing agreement, and will give notice of changes to it.

10. International transfers

Our application, database and analytics infrastructure are located in the EU. Some of our providers are established outside the EU or EEA, or belong to a group with a parent company outside it, which means personal data may be transferred to or accessible from a third country.

Where that happens, we rely on a European Commission adequacy decision where one applies, and otherwise on the European Commission's standard contractual clauses together with any additional safeguards required in the circumstances. You can ask us at hello@getgram.eu which mechanism applies to a given provider.

11. How long we keep it

DataRetention
Account data and settingsFor as long as your account is open, and up to 12 months after it is closed
Data you have uploaded or entered in the applicationFor the term of your use of the Service, and for the 30-day export window after it ends, after which it may be deleted
Enquiry and waitlist submissionsUntil you ask us to delete them, and in any event no longer than 24 months after our last contact with you
CorrespondenceUp to 24 months, or longer where needed to establish, exercise or defend a legal claim
Technical and usage dataFor the period applied by the relevant provider, which is shorter than the periods above
Records we must keep by law, such as accounting recordsFor the period required by that law

Where we no longer need personal data, we delete it or irreversibly aggregate it. We may keep material for longer where we must do so by law, or where it is needed for an actual or anticipated legal claim.

Please note that we do not keep your records on your behalf for the purposes of your own statutory retention obligations, including those under Regulation (EU) 2025/40. You must keep your own copies. See section 12 of our Terms of Service.

12. Your rights

Where we act as controller, you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • rectification of data that is inaccurate or incomplete;
  • erasure, where we no longer have a valid basis for holding the data;
  • restriction of processing in certain circumstances;
  • object to processing based on our legitimate interests, and to object at any time to direct marketing;
  • data portability, for data you provided to us where processing is based on contract or consent; and
  • withdraw consent, where we rely on consent, without affecting processing that already took place.

To exercise a right, email hello@getgram.eu. We will respond within one month, and will tell you if we need longer because the request is complex. We may need to verify your identity first. Exercising these rights is free, unless a request is manifestly unfounded or excessive.

You also have the right to lodge a complaint with a supervisory authority. In Sweden this is the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, imy.se. You may also complain to the authority in the EU or EEA country where you live or work.

13. Automated decisions

The Service performs automated calculations, categorisations and threshold comparisons, and presents indications based on them. These are working material intended for your review, and they are not decisions about any individual. We do not carry out automated decision-making that produces legal effects, or similarly significantly affects any individual, within the meaning of Article 22 of Regulation (EU) 2016/679. We do not carry out profiling for advertising purposes.

14. Machine learning and artificial intelligence

We do not use your data, or the data you upload, to train machine-learning models, and we do not transmit it to third-party artificial-intelligence providers. Our calculation and column-matching logic is deterministic.

15. Security

We take appropriate technical and organisational measures to protect personal data, including transport encryption, storing passwords only as salted hashes produced with a strong key-derivation function, hosting infrastructure in the EU, separating each customer's data by account, and limiting internal access to those who need it.

No service can be completely secure, and we do not guarantee that unauthorised access, loss or alteration will never occur. If a personal data breach occurs that is likely to result in a risk to individuals, we will notify the supervisory authority, and affected individuals or customers, as required by law.

16. Children

The Service is intended for businesses and is not directed at children. Do not use it if you are under 18.

17. Changes to this policy

We may update this policy. The date at the top shows when it was last changed. Where a change is material we will notify account holders by email or through the Service.

18. Contact

hello@getgram.eu