Processing of Personal Data by
Grappling Lab Sweden AB
Effective from 2026-09-01
Grappling Lab Sweden AB, organisation number (559599-2891) (“Grappling Lab”, “we”), processes personal data relating to you when you contact us, participate in trial training, apply for membership or are a member (the “Member”) of our Submission Wrestling activities. This document (the “Privacy Policy”) describes the personal data we process, why we process it, the legal basis on which we rely, how long we retain it and the rights you have.
The Privacy Policy supplements our General Terms and Conditions of Membership (the “Terms”), available at grapplinglabsweden.se (the “Website”). The Terms and the Membership Agreement govern how a Membership is established and used; this policy governs how we process your personal data in connection with the Membership.
1. Data Controller and Contact Details
1.1 Grappling Lab Sweden AB is the data controller in respect of the processing described in this policy.
1.2 If you have any questions about our processing of personal data, or wish to exercise any of your rights under section 11, please contact us at Info@GrapplingLabSweden.se. We normally respond to your request within one month.
2. Categories of Personal Data We Process
The personal data we process about you depends on how you interact with us, whether as a visitor, Trial Participant or Member. The categories of personal data that may be processed as part of our activities are described below.
| Category | Examples of data |
|---|---|
| Identity and contact details | Name, Swedish personal identity number, email address, telephone number, address |
| Membership and contract data | Membership application, contents of the Membership Agreement, document status, data relating to electronic identification and signing, dates and times of signing, digital audit trail, termination details |
| Payment data | Bank account number, direct debit mandate, payment history, billing records |
| Communication data | Messages submitted through the contact form, email correspondence, support requests |
| Training and attendance data | Data relating to trial training, bookings, attendance and practical information connected with training |
| Health data (special category of personal data) | Voluntarily provided information about injuries or other health conditions relevant to safe training |
| Image and recording data | Photographs, videos and audio recordings in which a person can be identified |
| Technical and website data | IP address, browser and device information, cookie settings, aggregated visitor statistics |
3. Processing Activities, Purposes and Legal Bases
Below, we describe why we process personal data, which categories of data under section 2 may be involved and the legal basis on which we rely.
a) To Respond to Enquiries and Administer Trial Training
Examples of processing: responding to questions submitted through the contact form, and booking and administering trial training.
Categories of personal data: Identity and contact details, Communication data, Training and attendance data.
Legal basis: our legitimate interest in being able to respond to enquiries and plan our activities (Article 6(1)(f) GDPR). If the enquiry concerns a possible membership application, the processing is instead based on Article 6(1)(b) GDPR (steps taken prior to entering into a contract).
b) To Process the Membership Application, Enter Into the Membership Agreement and Identify the Party to the Agreement
Examples of processing: reviewing the membership application, preparing and sending the Membership Agreement, and enabling identification and electronic signing using BankID through the digital signing service specified in the Terms (currently Verified).
Categories of personal data: Identity and contact details, Membership and contract data.
Legal basis: Article 6(1)(b) GDPR (steps taken prior to entering into a contract, and performance of a contract). The Swedish personal identity number is also processed pursuant to Chapter 3, Section 10 of the Swedish Act (2018:218) with Supplementary Provisions to the EU General Data Protection Regulation, because secure identification of the correct party is clearly justified in view of the purpose.
c) To Administer the Membership, Communicate and Handle Notices of Termination
Examples of processing: sending practical information about training, handling notices of termination and other contractual amendments, and maintaining a membership register.
Categories of personal data: Identity and contact details, Membership and contract data, Communication data.
Legal basis: Article 6(1)(b) GDPR.
d) To Handle Payments, Direct Debits and Accounting
Examples of processing: invoicing, administering direct debits and other payment methods, bookkeeping and accounting.
Categories of personal data: Identity and contact details, Membership and contract data, Payment data.
Legal basis: Article 6(1)(b) GDPR for the payment processing itself; Article 6(1)(c) GDPR for data that must be retained under accounting legislation.
e) To Operate and Protect the Website
Examples of processing: operating and publishing the Website, handling web forms, troubleshooting and producing aggregated visitor statistics. Such statistics are normally generated from server logs rather than cookies in your browser and, where this is the case, are not governed by the Website’s cookie settings.
Categories of personal data: Technical and website data, Communication data.
Legal basis: Article 6(1)(f) GDPR, based on our legitimate interest in maintaining a secure and functional website.
f) For External Functional Services (Maps and Videos)
Examples of processing: displaying maps and embedded videos on the Website, where such services are used.
Categories of personal data: Technical and website data.
Legal basis: Article 6(1)(a) GDPR, based on your consent provided through the Website’s cookie settings. You may withdraw or change your consent there at any time.
g) To Comply With Legal Obligations
Examples of processing: compliance with accounting legislation, anti-money laundering legislation applicable to our payment service providers, or other applicable law.
Categories of personal data: all categories listed in section 2, to the extent required.
Legal basis: Article 6(1)(c) GDPR.
h) To Establish, Exercise or Defend Legal Claims
Examples of processing: handling objections, claims, disputes or insurance matters connected with the Membership or training.
Categories of personal data: all categories listed in section 2, to the extent relevant to the claim.
Legal basis: Article 6(1)(f) GDPR, or Article 9(2)(f) GDPR where health data is involved.
4. Health Data and Training Safety
4.1 Submission Wrestling is a physical contact sport. We therefore ask you to inform the instructors of any injuries or other circumstances that are important to ensure that training can be carried out safely.
4.2 We do not normally request health data in the Website’s forms and do not maintain a general register of Members’ health. If you voluntarily provide information about an injury or your health, it is generally used only in the specific training situation and is not documented.
4.3 If it is necessary to record or retain health data, this will normally only be done after separate and explicit consent has been obtained (Articles 6(1)(a) and 9(2)(a) GDPR). Consent may be withdrawn at any time without affecting the lawfulness of processing carried out before it was withdrawn.
4.4 If information about an injury or incident must be processed in connection with a legal claim, the processing may be based on Articles 6(1)(f) and 9(2)(f) GDPR. In an emergency where you are unable to give consent, processing may, in exceptional circumstances, be necessary to protect vital interests (Articles 6(1)(d) and 9(2)(c) GDPR).
5. Images and Film
5.1 Photographs, videos and audio recordings in which a person can be identified constitute personal data. We publish such material for marketing purposes, on the Website, on social media or in other marketing materials, solely on the basis of your consent (Article 6(1)(a) GDPR).
5.2 For persons under the age of 18, we obtain the approval of a legal guardian and also take the child’s own wishes and level of maturity into account.
5.3 Consent may be withdrawn at any time by contacting us. The material will then not be used in new publications, and we will take reasonable steps without undue delay to remove it from channels that we control. Withdrawal of consent does not affect the lawfulness of processing carried out before it was withdrawn.
6. Recipients of Personal Data
6.1 Personal data is primarily handled by people within Grappling Lab who need the data to perform their duties. We may also share data with the following categories of recipients, to the extent required for the relevant purposes under section 3:
- Providers of operational, IT and communications services for the Website and email.
- Providers of AI-based services and digital support tools that may be used to support, for example, administration, communication, document management and analysis. Personal data is processed through such services only to the extent necessary for the purposes set out in this Privacy Policy and in accordance with applicable data protection legislation.
- A provider of digital contract management, electronic signing and secure identification using BankID (currently Verified).
- Payment service providers and banks, for example in connection with Bankgiro payments and direct debits.
- Providers of bookkeeping, invoicing and accounting services.
- Providers of map and video services embedded on the Website, where such services are used.
- Advisers, such as lawyers, auditors and debt collection agents.
- Public authorities, where required by law.
- Courts and opposing parties, in connection with a legal claim.
- A potential purchaser or counterparty, if Grappling Lab’s operations or Membership Agreements are transferred in accordance with the Terms.
6.2 Service providers that process personal data on our behalf do so in accordance with our instructions and under a data processing agreement. Certain recipients, such as banks, payment intermediaries and providers of map or video services, may be independent data controllers for parts of their processing, in accordance with their own terms and legal obligations. We only disclose data that is necessary for the relevant purpose.
6.3 If you would like more information about the specific providers we use for any of the categories above, please contact us.
6.4 Grappling Lab may use AI-based services and digital support tools as aids in its operations. In connection with such use, personal data may be processed, for example, for administrative, communication, document-related or analytical purposes. Such processing takes place only when it is relevant and necessary for a purpose set out in this Privacy Policy and on the legal basis applicable to the processing in question. Grappling Lab seeks to limit the amount of personal data processed through AI-based services to what is necessary for the relevant purpose.
7. Transfers of Personal Data Outside the EU and EEA
7.1 Some of the service providers we use may process personal data outside the EU and EEA, for example where a provider has servers or support functions in a third country.
7.2 Any such transfer is always made on one of the legal bases set out in section 3 and is protected by an adequacy decision, the European Commission’s standard contractual clauses or another safeguard required under the GDPR.
7.3 You may contact us for further information about a specific transfer, the safeguard used, or to obtain a copy of the applicable safeguards.
8. How Long Do We Retain the Data?
8.1 We do not retain personal data for longer than is necessary for the purpose for which it was collected, unless we are required to retain it by law or in order to establish, exercise or defend legal claims.
8.2 Trial training that does not lead to Membership: the data is normally deleted or anonymised no later than three months after the most recent trial training session or contact, whichever occurs later.
8.3 Membership applications that do not lead to a Membership Agreement: the data is normally deleted or anonymised no later than three months after the application has been closed or the most recent contact, whichever occurs later.
8.4 During an active Membership: data required for membership administration, communication, payment and contract management is retained for as long as the Membership remains active.
8.5 After a Membership has ended: membership register data and current contact details are normally deleted or anonymised no later than twelve months after the Membership ends. Limited contract, signing, consent and payment data that may be needed to handle claims or disputes, including the signed Membership Agreement and the signing records, may be retained for up to three years after the Membership has ended, or longer if a matter is still ongoing.
8.6 Accounting records: retained for seven years after the end of the calendar year in which the financial year ended, in accordance with accounting legislation.
8.7 Injuries, incidents and insurance matters: retained only for as long as necessary for the matter and as required by any applicable legal obligations.
9. Are You Required to Provide Your Personal Data?
9.1 Data marked as mandatory in our forms is required so that we can respond to your enquiry, administer trial training, process a membership application and enable electronic signing in accordance with the Terms. Data required for payment must be provided so that we can administer the chosen payment method.
9.2 If the necessary data is not provided, we may in some cases be unable to process your application, prepare or sign the Membership Agreement, or perform our obligations under it.
9.3 Data that is not marked as mandatory is voluntary, as is consent to external functional services, photography, filming and other consent-based processing.
10. Automated Decision-Making and Profiling
10.1 Grappling Lab does not use automated decision-making or profiling to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. Decisions on membership applications are made by Grappling Lab, even where electronic identification and signing in accordance with the Terms are used as tools in the process.
10.2 AI-based services may be used as support tools in the operations, but they are not used to independently make decisions about individual Members that have legal or similarly significant consequences.
11. Your Rights
11.1 You have the right to obtain confirmation as to whether we process personal data relating to you and, if so, to access that data and receive a copy.
11.2 Where the conditions under the GDPR are met, you also have the right to:
- request rectification of inaccurate or incomplete data,
- request erasure of personal data,
- request restriction of processing,
- object to processing based on legitimate interests, and
- request data portability for data processed by automated means on the basis of consent or a contract.
11.3 Where processing is based on consent, you have the right to withdraw that consent at any time without affecting the lawfulness of processing carried out before the consent was withdrawn.
11.4 These rights are not absolute. A request may be rejected in whole or in part where continued processing is required by law or in order to establish, exercise or defend a legal claim.
11.5 To exercise your rights, please contact us as described in section 1.2.
12. Complaints
12.1 If you believe that your personal data is not being processed correctly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).
13. Changes to This Policy
13.1 We may update this policy if our activities, the Website, our service providers or our processing of personal data changes. If we intend to process data already collected for a new purpose, we will inform you before the new processing begins.