Privacy policy
Privacy Policy
- General and Purpose
This privacy policy describes how Gylle Mec AB (“Gylle” or “We”) processes your personal data.
Gylle’s business consists of developing and manufacturing position and side marker lights, primarily intended for trucks, tractors, forestry machines, and similar vehicles.
Gylle values your personal privacy and strives for a high level of data protection. We always do our utmost to protect your information and handle it carefully, with great emphasis on IT security. The fundamental principles for Gylle’s processing of personal data are security, confidentiality, accuracy, purpose limitation, and minimization of sensitive data.
Gylle is the data controller for the processing of your personal data and is responsible for ensuring that your data is processed in accordance with applicable data protection legislation.
The individual whose personal data is processed is referred to as “Data Subject” or “You”.
The purpose of this policy is to inform you, in accordance with the EU General Data Protection Regulation (GDPR), about how We process your personal data, what We use it for, who has access to it, under what conditions, and how You can exercise your rights.
- Personal Data and Processing of Personal Data
2.1 Basic Concepts
2.1.1 Personal Data
Personal data is any information that can be linked to a living person. A single piece of information does not need to identify a person on its own — it is enough that several pieces of information together can identify someone.
Typical examples include:
name, address, phone number, email address, personal identity number, IP address, passwords, voice recordings, images, health data, biometric data, and genetic information.
Sensitive personal data includes:
racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data, health data, sexual life or sexual orientation.
A personal identity number is not considered sensitive under GDPR, but it is particularly protected.
2.1.2 Processing of Personal Data
Processing includes any action taken with personal data, whether automated or not.
Examples: collection, registration, organization, storage, modification, transfer, and deletion.
- Data Controller
Gylle is the data controller and responsible for ensuring that your personal data is processed lawfully. Contact details are provided in section 8.1.
- Collection of Personal Data
4.1 How We Obtain Personal Data
We collect personal data in several ways, for example when:
- You, as a representative of a reseller, provide contact details when ordering goods or contacting us via phone, email, mail, digital meetings, or visits.
- Agreements are entered into or administered with resellers, suppliers, designers, or partners.
- We receive information from partners in joint development projects.
- You apply for a job and submit a CV, cover letter, or references.
- You visit our website, where we automatically collect technical data such as IP address, cookies, and logs.
4.2 Types of Personal Data We Process
Name, address, email, phone number, personal identity number, bank details, invoice information, payment history, job title, contract information, IP address, CV, cover letter, references, and other voluntarily provided information.
4.3 Why We Process Your Personal Data
We process personal data mainly to:
- Provide products to resellers
- Ensure product quality (e.g., E‑marking, lab testing)
- Collaborate with manufacturers and subcontractors
- Develop new materials and products
- Ensure customer satisfaction
- Recruit and employ staff
- Fulfill legal obligations (e.g., bookkeeping laws)
A detailed table of purposes, legal bases, and retention periods is included in the document.
4.4 Secure Processing
We have routines to ensure secure handling. Only authorized personnel have access.
We have agreements with IT providers to ensure GDPR compliance.
4.5 Information Provided to You
When you contact us, we inform you about how we use your personal data, your rights, and how to exercise them — primarily by referring to this policy.
4.6 When We Share Your Personal Data
We only share data when we have a legal basis.
Subcontractors may process data as data processors under strict agreements.
Examples: IT services, accounting, invoicing.
We ensure all processors meet GDPR requirements.
Personal data is not stored outside the EU/EEA unless adequate safeguards exist.
4.7 Transfers Outside the EU/EEA
Transfers outside the EU/EEA are rare.
If they occur, they follow GDPR rules such as:
- Adequacy decisions
- EU‑US Data Privacy Framework
- Standard Contractual Clauses (SCC)
International freight companies may receive necessary contact details for deliveries.
4.8 Storage and Deletion
We retain personal data only as long as necessary for contractual or legal obligations.
Regular deletion routines are in place.
- Automated Decision-Making
We do not use automated decision-making that affects you.
- Your Rights
You have rights under GDPR, including:
- Right to information
- Right of access (register extract)
- Right to rectification or deletion
- Right to restriction
- Right to object
- Right to data portability
- Right to withdraw consent
Details are provided in the document.
- Changes to This Policy
We may update the policy when required by new guidance or legal developments.
You will be informed of significant changes.
- Contact Information
8.1 Data Controller
Gylle Mec AB
Holgatan 42, 784 72 Borlänge, Sweden
Phone: 0243‑142 10
Email: info@gylle.se
Contact person: Christopher Brandt
8.2 Supervisory Authority
Swedish Authority for Privacy Protection (IMY)
Box 8114, 104 20 Stockholm
imy@imy.se
www.imy.se
