CTEK Global Privacy Policy

Effective Date / Last Updated: August 21, 2026

Document Version: 007 (Global Master)

1. Data Controller & Scope

This Global Privacy Policy ("Notice") applies to CTEK Sweden AB (Org. No. 556540-3234, Strandvägen 15, SE - 791 42 Falun, Sweden) and its global subsidiaries and affiliates ("CTEK", "we", "us", or "our").

This Notice applies when you visit our websites, use our e-commerce webshops, interact with our mobile applications and connected digital services, apply for employment with us, or contact our customer support globally.

2. Your General Rights

Regardless of your location, CTEK ensures you can exercise fundamental rights over your personal data:

  • Right to Access & Rectification: You can request a copy of the personal data we hold about you and request corrections to inaccurate or incomplete data.

  • Right to Erasure ("Right to be Forgotten"): You may request deletion of your personal data when it is no longer necessary for the purpose it was collected, or where processing is unlawful.

  • Right to Restrict or Object to Processing: You can object to processing based on legitimate interests or direct marketing, or request restricted processing during dispute resolution.

  • Right to Data Portability: Where technically feasible, you may request your automated data in a structured, machine-readable format.

  • Right to Withdraw Consent: Where processing is based on consent, you may withdraw it at any time without affecting prior lawful processing.

To exercise these rights, contact us at dataprivacy@ctek.com. You also have the right to lodge a complaint with your local data protection authority (see jurisdiction-specific schedules below).

3. Collection of Information

We collect data directly from you, automatically through your device, and from connected products:

  • Direct Interaction: Name, email address, telephone number, shipping/billing address, transaction history, customer service inquiries, and payment validation metadata.

  • Connected Products & Digital Services: Device serial numbers, operational logs, hardware/software telemetry, battery charging history, and crash diagnostic reports.

  • Automated Device & Usage Data: IP address, browser type, operating system, geolocation data, and site navigation patterns via cookies and tracking tools.

  • Job Applicants & Recruitment: CVs, cover letters, work history, educational background, references, contact details, and assessment notes provided when applying for employment or internships at CTEK.

  • B2B / Commercial Representatives: Name, business email, job title, and company details for business partners or corporate customers.

4. Purpose and Legal Bases for Processing

We process personal data only where we have a valid legal basis:

  • Contract Performance: Fulfilling e-commerce orders, delivering physical products, creating user accounts, and delivering digital app services.

  • Recruitment & Job Applications: Administering job applications, assessing candidate qualifications, conducting interviews, and contacting potential recruits. This processing is based on our legitimate interest to recruit qualified staff and, where applicable, taking steps at the request of the candidate prior to entering into an employment contract.

  • Consent: E-mail marketing/newsletters (subject to local opt-in laws), non-essential analytical or marketing cookies, and specific connected product features.

  • Legitimate Interests: Enhancing product performance, preventing fraud, troubleshooting software, B2B commercial communications, and improving user experience.

  • Legal Compliance: Tax, accounting, statutory product warranties, employment/labor regulations, and law enforcement requests.

5. Disclosure and Third-Party Sharing

We do not sell your personal data. We share data only with:

  • Group Companies: CTEK subsidiaries globally for centralized administration, logistics, and global recruitment operations.

  • Service Providers: Logistics/courier partners (e.g., DHL), payment gateways (e.g., Shopify Payments), recruitment platforms/ATS systems, cloud infrastructure, IT support, and customer communication platforms.

  • Legal & Regulatory Authorities: When mandatory under applicable statutory law or court orders.

All third-party service providers act under strict Data Processing Agreements (DPAs) ensuring confidentiality and organizational security.

6. International Data Transfers

When transferring data internationally from the EU/EEA or UK:

  • Transfers to the U.S.: Managed under the EU-U.S. Data Privacy Framework (DPF), UK Extension to the DPF, or standard contractual clauses.

  • Other Countries (Australia, China, Hong Kong, etc.): Conducted using the EU Standard Contractual Clauses (SCCs), UK International Data Transfer Agreements (IDTA), or adequacy decisions approved by relevant authorities.

7. Data Security and Retention

We apply end-to-end SSL/TLS encryption, restricted role-based access, and physical server safeguards. Personal data is retained only for as long as needed to fulfill the original purpose or to satisfy statutory retention obligations (e.g., tax, accounting, or labor law requirements). Job applicant data for unsuccesful candidates is retained for a limited period to fulfill legal requirements regarding equal treatment claims or future recruitment consent.

8. Cookies and Tracking Technologies

We use functional cookies to operate our store, and analytics/marketing cookies to personalize content.

  • In jurisdictions requiring explicit opt-in (e.g., EU, UK), non-essential cookies are blocked until you grant affirmative consent via our Cookie Management Banner.

  • You may adjust cookie settings at any time via the cookie preferences link on our website footer.

JURISDICTION-SPECIFIC SCHEDULES

Schedule 1: EU / EEA (Sweden, Germany, France, Spain)

  • Lead Supervisory Authority: Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten - IMY).

  • Local Supervisory Authorities: Consumers and applicants may complain to their local authority:

    • Germany: The Federal Commissioner for Data Protection and Freedom of Information (BfDI) or regional State DPAs.

    • France: Commission Nationale de l'Informatique et des Libertés (CNIL).

    • Spain: Agencia Española de Protección de Datos (AEPD).

  • E-Marketing Rules (Germany, France, Spain): Electronic marketing communications are sent strictly based on explicit prior consent (Opt-In / Double Opt-In where required by national law). Existing customer relationship exceptions ("soft opt-in") apply strictly within statutory bounds.

Schedule 2: United Kingdom (UK)

  • Applicable Law: UK GDPR and Data Protection Act 2018.

  • Supervisory Authority: Information Commissioner's Office (ICO) (www.ico.org.uk).

  • International Transfers: Data transfers outside the UK utilize the UK International Data Transfer Agreement (IDTA) or the UK Addendum to EU SCCs.

Schedule 3: United States (US Residents)

  • Applicable Laws: State privacy regulations including the California Consumer Privacy Act as amended by the CPRA, Virginia CDPA, Colorado CPA, and similar state laws.

  • Your US Rights:

    • Right to Know & Access: Request details on categories and specific pieces of personal information collected (including job application data where applicable under state law).

    • Right to Delete: Request deletion of personal information subject to statutory exceptions.

    • Right to Opt-Out of Sale / Targeted Advertising: CTEK does not sell your personal information or share it for cross-context behavioral advertising for monetary gain.

    • Non-Discrimination: We will not discriminate against you for exercising your privacy rights.

  • Exercising Rights: Submit requests via email to dataprivacy@ctek.com.

Schedule 4: Canada

  • Applicable Law: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial private sector privacy legislation.

  • Commercial Electronic Messages (CASL): Marketing emails comply strictly with Canada’s Anti-Spam Legislation (CASL). We require explicit or applicable implied consent prior to sending marketing communications.

  • Supervisory Authority: Office of the Privacy Commissioner of Canada (OPC).

Schedule 5: Australia

  • Applicable Law: Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

  • Overseas Disclosure: Personal data may be disclosed to CTEK entities and providers located in Sweden, the EU, the US, and Belgium.

  • Complaints: You may raise concerns with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au if we fail to resolve a privacy concern satisfactorily.