Hoppa till innehållet
  • Free standard shipping from SEK 499
  • Ships from Sweden
  • Clear product specifications
Kontakta kundservice

Privacy policy

Privacy policy

Last updated: 21 August 2026

At Tilden, we care about your privacy. This privacy policy describes what personal data we process, why we process it, how long it may be retained, who it may be shared with and what rights you have.

We process personal data in accordance with the EU General Data Protection Regulation, GDPR, and other applicable data protection legislation.

Data controller

Tilden Medical, hereinafter referred to as Tilden, is the data controller for the processing of personal data described in this policy.

Contact:

Tilden Medical
Tempelgatan 1C
431 30 Mölndal
Sweden

Email: kontakt@tilden.se

Full company and contact details are available on the Contact details page.

What personal data do we process?

When you visit our website, make a purchase, use a customer account or contact us, we may process, for example:

  • name
  • delivery address and billing address
  • telephone number
  • email address
  • order number, purchase history and information about ordered products
  • payment status and other payment-related information
  • IP address, device information and technical log data
  • information about how the website is used
  • communications with customer service
  • information that you provide to us in connection with a purchase or customer service matter

Personal identity numbers or organisation numbers may in some cases be processed when necessary for a payment, legal obligation or other specific function. Such information may also be processed directly by, for example, payment providers.

Full card details are normally handled directly by our payment providers and are not stored by Tilden.

We ask you not to provide sensitive personal data or medical information to us unless it is necessary for us to handle your matter.

Why do we process your personal data?

We may process personal data in order to:

  • receive, administer and deliver orders
  • handle payments and refunds
  • send order confirmations and delivery information
  • manage customer accounts
  • handle returns and complaints
  • answer questions and provide customer service
  • comply with accounting, tax and other legal obligations
  • prevent fraud, misuse and security incidents
  • maintain, troubleshoot and improve the functionality of the website
  • analyse how the website is used where permitted
  • send marketing where you have consented to it or where otherwise permitted by law
  • establish, exercise or defend legal claims

Legal basis for processing

Performance of a contract

When you make a purchase, we process the personal data needed to administer the order, payment and delivery and to handle questions, returns and complaints.

The processing is necessary for us to perform our contract with you or to take steps at your request before entering into a contract.

Legal obligation

Certain personal data is processed and retained so that Tilden can comply with legal obligations under, for example, accounting, tax, product and consumer legislation.

Legitimate interests

We may process personal data where necessary for legitimate interests, for example to:

  • provide and improve customer service
  • protect the website and our systems
  • prevent fraud and misuse
  • improve our business and services
  • establish, exercise or defend legal claims

When processing is based on legitimate interests, we carry out an assessment in which our interest is balanced against your rights, interests and privacy.

Consent

We use consent where required, for example for certain forms of marketing, analytics or the use of non-essential cookies.

You may withdraw your consent at any time. Withdrawal of consent does not affect the lawfulness of processing carried out before the consent was withdrawn.

Medical devices and legal requirements

Tilden sells medical devices and disposable products.

We may need to retain certain order, product and transaction information where required by law, a decision by an authority or in order to handle, for example, complaint, safety or traceability matters.

We may disclose information to competent authorities where we are required to do so by law or by a binding decision of an authority or court.

Who may have access to the data?

We only share personal data where necessary to operate the business, fulfil an order, provide our services or comply with legal obligations.

Recipients may, for example, include:

  • Shopify and other providers of e-commerce and IT services
  • payment providers and banks
  • transport, shipping and logistics companies
  • providers of email, support, analytics and cloud services
  • providers of security and fraud prevention services
  • accounting consultants, auditors and legal advisers
  • authorities, courts and other public bodies where we are required to disclose data

Service providers that process personal data on our behalf may only process it in accordance with our instructions and applicable data protection legislation.

We do not sell your personal data to third parties.

Transfers outside the EU and EEA

Some of our service providers may process personal data in countries outside the EU and EEA.

When personal data is transferred to such a country, the transfer must be supported by a permitted transfer mechanism under the GDPR.

This may, for example, be:

  • an adequacy decision by the European Commission
  • the European Commission's Standard Contractual Clauses
  • another permitted safeguard under the GDPR

Additional security measures are used where considered necessary.

Cookies and similar technologies

The website uses necessary cookies so that, for example, the shopping cart, checkout, security functions and other basic functions work.

Depending on the choices you make, the website may also use cookies or similar technologies for:

  • analytics and statistics
  • customisation of website content
  • marketing
  • measurement of marketing performance

Where consent is required, such technologies are only used after you have made an active choice.

You can change your cookie choices through the website's cookie settings. You can also block or delete cookies through your browser settings.

If certain cookies are blocked, parts of the website may work less well or may not work at all.

How long do we retain personal data?

We retain personal data for as long as it is needed for the purpose for which it was collected or for as long as we are required to retain it by law.

For example:

  • Order and accounting records are retained for as long as applicable accounting rules require.
  • Customer service matters are retained for as long as needed to handle the matter, any follow-up questions and legal claims.
  • Information about returns and complaints is retained for as long as needed to handle the matter and comply with legal obligations.
  • Information about marketing consent is retained for as long as needed to administer and document the consent.
  • Technical logs are retained for as long as needed for security, troubleshooting and prevention of misuse.
  • Information linked to customer accounts is retained for as long as the account is active or for as long as the information otherwise needs to be retained.

When personal data is no longer needed, it is deleted or anonymised unless we are required to retain it for legal reasons.

Your rights

Depending on the circumstances, you may have the right to:

  • receive information about how your personal data is processed
  • request access to the personal data we process about you
  • request correction of inaccurate or incomplete data
  • request deletion of personal data
  • request restriction of processing
  • object to processing based on legitimate interests
  • object to direct marketing
  • request data portability where the conditions for this are met
  • withdraw consent you have given

Certain rights are limited. For example, we may need to retain data that is required by law or needed to establish, exercise or defend legal claims.

To exercise your rights, you can contact:

kontakt@tilden.se

We may need to verify your identity before handling a request. This is done to protect personal data from being disclosed to unauthorised persons.

Security

We use appropriate technical and organisational security measures to protect personal data against, among other things:

  • unauthorised access
  • loss or destruction
  • unauthorised alteration
  • unauthorised disclosure
  • other unauthorised processing

No method of transmitting or storing information is entirely risk-free. We therefore continuously adapt our security to the nature of the processing and the risks involved.

Complaints

Please contact Tilden first if you have questions or believe that we are processing your personal data incorrectly.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

More information is available on the Swedish Authority for Privacy Protection's website.

Changes to the privacy policy

We may update this privacy policy when our business, services, suppliers or applicable rules change.

The date at the top of the page shows when the policy was last updated.

In the event of significant changes, we may also provide information about them on the website or through other appropriate channels.

Contact

If you have questions about this privacy policy or how Tilden processes personal data, you are welcome to contact us.

Tilden Medical
Tempelgatan 1C
431 30 Mölndal
Sweden

Email: kontakt@tilden.se

Full company and contact details are available on the Contact details page.