Privacy Policy

shape
shape
shape
shape
shape
shape
shape
shape

Last Updated: December 2, 2025

1. INTRODUCTION

Welcome to Thingsatweb Sweden AB’s Privacy Policy. We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you about how we look after your personal data when you use our services and tell you about your privacy rights and how the law protects you.

1.1 Controller Information

Thingsatweb Sweden AB is the controller and responsible for your personal data (collectively referred to as “Thingsatweb”, “we”, “us” or “our” in this privacy policy).

Company Details:

1.2 Data Protection Officer

We have appointed a Data Protection Officer (DPO) who is responsible for overseeing questions in relation to this privacy policy. If you have any questions about this privacy policy, including any requests to exercise your legal rights, please contact:

Data Protection Officer

1.3 Changes to This Policy

We may update this privacy policy from time to time. We will notify you of any changes by posting the new privacy policy on this page and updating the “Last Updated” date. For material changes, we will provide additional notice through email or on our website.

2. OUR SERVICES AND DATA PROCESSING ROLES

2.1 Services We Provide

Thingsatweb Sweden AB provides comprehensive technology services including:

  • Web Development and Design: Custom websites, e-commerce platforms (WooCommerce, Magento), WordPress development
  • Mobile App Development: iOS and Android application development with AI integration
  • IoT Solutions: Internet of Things implementations for real-time monitoring and predictive maintenance
  • Digital Marketing: SEO optimization, Google Ads, social media marketing campaigns
  • Domain and Hosting Services: Web hosting on Amazon AWS, domain registration, SSL certificates
  • Cloud Infrastructure Management: AWS and Google Cloud Platform hosting and management

2.2 Our Data Processing Roles

We process personal data in two distinct capacities:

As Data Controller:

  • For our own business operations (website visitors, contact form submissions, marketing communications)
  • For direct client relationships where we determine processing purposes
  • For recruitment and employment data

As Data Processor:

  • When providing technology services to clients (we process data on their behalf)
  • When managing cloud infrastructure containing client data
  • When developing applications that handle end-user data for our clients

3. PERSONAL DATA WE COLLECT

3.1 Data We Collect as Controller

When you interact with our website or request our services, we collect:

Identity Data:

  • First name and last name
  • Company name and title
  • Organization number (for business clients)

Contact Data:

  • Email address
  • Telephone number
  • Business address

Technical Data:

  • IP address
  • Browser type and version
  • Device information
  • Time zone setting and location
  • Operating system and platform

Usage Data:

  • Information about how you use our website
  • Pages visited and time spent
  • Referral source

Marketing and Communications Data:

  • Your preferences for receiving marketing from us
  • Your communication preferences

3.2 Data We Process as Processor

When providing services to our clients, we may process various types of personal data on their behalf, including but not limited to:

  • End-user account information (names, emails, phone numbers)
  • Transaction and payment data (tokenized payment information)
  • Usage analytics and behavioral data
  • Device and technical information
  • Location data (when relevant to services)
  • Any other data our clients collect through systems we develop and maintain

Important: When we act as a processor, our clients (the data controllers) are responsible for informing their users about data collection and use. We process this data only according to our clients’ documented instructions and applicable data processing agreements.

4. HOW WE COLLECT YOUR PERSONAL DATA

4.1 Direct Interactions

You provide personal data directly when you:

  • Submit contact forms on our website
  • Request quotes or services
  • Subscribe to newsletters or marketing communications
  • Engage with us via email, phone, or social media
  • Participate in surveys or provide feedback

4.2 Automated Technologies

We automatically collect technical and usage data when you visit our website using:

  • Cookies and similar tracking technologies
  • Server logs
  • Analytics tools (Google Analytics)

4.3 Third Parties

We may receive personal data from:

  • Business partners and referral sources
  • Analytics providers
  • Publicly available sources (business registries)

5. HOW WE USE YOUR PERSONAL DATA

5.1 Legal Basis for Processing

We will only use your personal data when the law allows us to. Most commonly, we use your personal data in the following circumstances:

  • Contract Performance (Article 6(1)(b) GDPR): To provide our services and fulfill our contractual obligations
  • Legal Obligation (Article 6(1)(c) GDPR): To comply with legal requirements such as accounting and tax obligations
  • Legitimate Interests (Article 6(1)(f) GDPR): For business development, service improvement, and security purposes
  • Consent (Article 6(1)(a) GDPR): For marketing communications and optional data processing

5.2 Purposes of Processing

We use your personal data for the following purposes:

Purpose Data Categories Legal Basis
Service delivery and project management Identity, Contact, Technical Contract Performance
Customer support and communication Identity, Contact, Communications Contract Performance, Legitimate Interests
Marketing and business development Identity, Contact, Marketing Consent, Legitimate Interests
Website analytics and improvement Technical, Usage Legitimate Interests
Security and fraud prevention Technical, Usage Legitimate Interests
Legal compliance and reporting All categories Legal Obligation

5.3 Marketing Communications

We will only send you marketing communications if you have opted in. You can opt out at any time by:

  • Using unsubscribe links in emails
  • Contacting dpo@thingsatweb.se
  • Updating your preferences in your account settings

6. WHO WE SHARE YOUR DATA WITH

6.1 Service Providers (Data Processors)

We share personal data with trusted third-party service providers who assist in delivering our services:

Service Provider Location Services Safeguards
Amazon Web Services (AWS) Stockholm, Sweden Cloud hosting and infrastructure ISO 27001, SOC 2, AWS DPA
Google Cloud Platform Finland (EU) Backup and disaster recovery ISO 27001, Google Cloud DPA
Google Analytics USA (EU processing) Website analytics IP anonymization, SCCs
Email service providers EU/EEA Email communications GDPR compliance, DPAs

6.2 Other Recipients

We may also share your personal data with:

  • Professional Advisors: Lawyers, accountants, auditors (under confidentiality obligations)
  • Government Authorities: Tax authorities (Skatteverket), law enforcement when legally required
  • Business Partners: With your consent or when necessary for service delivery

6.3 Data Processing Agreements

All our data processors are required to sign Data Processing Agreements (DPAs) that ensure they:

  • Process data only on our documented instructions
  • Implement appropriate security measures
  • Assist with GDPR compliance obligations
  • Delete or return data upon termination

7. INTERNATIONAL DATA TRANSFERS

7.1 Primary Data Location

Your personal data is primarily stored and processed within the European Economic Area (EEA):

  • Primary Location: AWS eu-north-1 (Stockholm, Sweden)
  • Backup Location: Google Cloud europe-north1 (Hamina, Finland)

7.2 Transfers Outside EEA

When we transfer data outside the EEA, we ensure appropriate safeguards are in place:

  • Standard Contractual Clauses (SCCs): EU Commission approved contracts for data transfers
  • EU-US Data Privacy Framework: For certified US companies
  • Adequacy Decisions: For countries deemed adequate by the EU Commission
  • Transfer Impact Assessments: Risk assessments for all third-country transfers

You can request copies of our transfer safeguards by contacting dpo@thingsatweb.se

8. DATA SECURITY

8.1 Security Measures

We implement appropriate technical and organizational measures to protect your personal data:

Technical Measures:

  • Encryption in transit (TLS 1.3) and at rest (AES-256)
  • Multi-factor authentication for system access
  • Regular security audits and vulnerability assessments
  • Firewalls and intrusion detection systems
  • Secure backup and disaster recovery procedures

Organizational Measures:

  • Limited access on need-to-know basis
  • Employee confidentiality agreements
  • Regular data protection training
  • Incident response procedures
  • Vendor security assessments

8.2 Data Breach Response

In the unlikely event of a personal data breach:

  • We will notify Integritetsskyddsmyndigheten (Swedish Data Protection Authority) within 72 hours
  • If the breach poses high risk to your rights, we will notify you directly
  • We maintain a breach register as required by GDPR

9. DATA RETENTION

We retain personal data only as long as necessary for the purposes collected:

Data Category Retention Period Legal Basis
Client project data Duration of relationship + 3 years Legal claims defense
Financial records 7 years Swedish Accounting Act
Marketing consents Until withdrawn Active consent required
Website analytics 14 months Google Analytics default
Customer support logs 3 years Service improvement
Anonymized data Indefinite No longer personal data

10. YOUR LEGAL RIGHTS

Under GDPR, you have the following rights regarding your personal data:

10.1 Your Rights

  • Right to Access (Article 15): Request a copy of your personal data
  • Right to Rectification (Article 16): Correct inaccurate personal data
  • Right to Erasure (Article 17): Request deletion of your data (‘right to be forgotten’)
  • Right to Restriction (Article 18): Limit how we process your data
  • Right to Data Portability (Article 20): Receive your data in machine-readable format
  • Right to Object (Article 21): Object to certain processing activities
  • Rights regarding Automated Decision-Making (Article 22): Not be subject to purely automated decisions

10.2 How to Exercise Your Rights

Contact our Data Protection Officer:

  • Email: dpo@thingsatweb.se
  • Phone: +46707770727
  • Mail: DPO, Thingsatweb Sweden AB, Sockerbruksgatan 7, 531 40 Lidköping, Sweden

10.3 Response Timeline

  • Acknowledgment: Within 3 business days
  • Response: Within 30 days
  • Complex requests: May extend to 90 days total (we’ll inform you of delays)

10.4 Right to Complain

If you’re not satisfied with our response, you have the right to complain to:

Integritetsskyddsmyndigheten (IMY)

Swedish Data Protection Authority

11. COOKIES AND SIMILAR TECHNOLOGIES

11.1 What Are Cookies

Cookies are small text files stored on your device when you visit our website. They help us provide you with a better experience and allow certain features to work.

11.2 Types of Cookies We Use

Essential Cookies (Always Active):

  • Required for website functionality
  • Enable security features

Analytics Cookies (With Consent):

  • Google Analytics: Track website usage and visitor patterns
  • Help us improve our website and services

Marketing Cookies (With Consent):

  • Track advertising campaign effectiveness
  • Enable targeted advertising

11.3 Managing Cookies

You can control cookies through:

  • Our cookie consent banner when you first visit
  • Your browser settings (all browsers allow cookie blocking)
  • Contacting us to update your preferences

12. THIRD-PARTY LINKS

Our website may contain links to third-party websites. We are not responsible for the privacy practices of these external sites. We encourage you to read their privacy policies when you leave our site.

13. CHILDREN’S PRIVACY

Our services are intended for business-to-business purposes and are not directed at children under 16. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.

14. CHANGES TO THIS PRIVACY POLICY

We may update this privacy policy from time to time to reflect changes in our practices or legal requirements. When we make material changes:

  • We will update the “Last Updated” date at the top
  • We will post a notice on our website
  • We will notify you by email (for significant changes)

15. CONTACT INFORMATION

15.1 General Inquiries

Thingsatweb Sweden AB

15.2 Data Protection Inquiries

Data Protection Officer

15.3 Supervisory Authority

Integritetsskyddsmyndigheten (IMY)

16. GLOSSARY

Personal Data: Information relating to an identified or identifiable person

Processing: Any operation on personal data (collection, storage, use, deletion, etc.)

Controller: Organization determining purposes and means of processing

Processor: Organization processing data on controller’s behalf

Data Subject: Individual whose personal data is processed

GDPR: General Data Protection Regulation (EU) 2016/679

DPA: Data Processing Agreement

EEA: European Economic Area

SCCs: Standard Contractual Clauses for international data transfers

END OF PRIVACY POLICY

Thank you for trusting Thingsatweb Sweden AB with your data.

For questions or concerns about this Privacy Policy, please contact:

dpo@thingsatweb.se


Effective date: 2021-08-01

1. Introduction

Welcome to Thingsatweb Sweden AB.

Thingsatweb Sweden AB (“us”, “we”, or “our”) operates https://thingsatweb.se (hereinafter referred to as “Service”).

Our Privacy Policy governs your visit to https://thingsatweb.se and explains how we collect, safeguard and disclose information that results from your use of our Service.

We use your data to provide and improve Service. By using Service, you agree to the collection and use of information in accordance with this policy. Unless otherwise defined in this Privacy Policy, the terms used in this Privacy Policy have the same meanings as in our Terms and Conditions.

Our Terms and Conditions (“Terms”) govern all use of our Service and together with the Privacy Policy constitute your agreement with us (“Agreement”).

2. Definitions

SERVICE means the https://thingsatweb.se website operated by Thingsatweb Sweden AB.

PERSONAL DATA means data about a living individual who can be identified from those data (or from those and other information either in our possession or likely to come into our possession).

USAGE DATA is data collected automatically either generated by the use of Service or from the Service infrastructure itself (for example, the duration of a page visit).

COOKIES are small files stored on your device (computer or mobile device).

DATA CONTROLLER means a natural or legal person who (either alone or jointly or in common with other persons) determines the purposes for which and the manner in which any personal data are, or are to be, processed. For the purpose of this Privacy Policy, we are a Data Controller of your data.

DATA PROCESSORS (OR SERVICE PROVIDERS) means any natural or legal person who processes the data on behalf of the Data Controller. We may use the services of various Service Providers in order to process your data more effectively.

DATA SUBJECT is any living individual who is the subject of Personal Data.

THE USER is the individual using our Service. The User corresponds to the Data Subject, who is the subject of Personal Data.

3. Information Collection and Use

We collect several different types of information for various purposes to provide and improve our Service to you.

4. Types of Data Collected

Personal Data

While using our Service, we may ask you to provide us with certain personally identifiable information that can be used to contact or identify you (“Personal Data”). Personally, identifiable information may include, but is not limited to:

0.1. Email address

0.2. First name and last name

0.3. Phone number

0.4. Address, Country, State, Province, ZIP/Postal code, City

0.5. Cookies and Usage Data

We may use your Personal Data to contact you with newsletters, marketing or promotional materials, and other information that may be of interest to you. You may opt-out of receiving any, or all, of these communications from us by following the unsubscribe link.

Usage Data

We may also collect information that your browser sends whenever you visit our Service or when you access Service by or through any device (“Usage Data”).

This Usage Data may include information such as your computer’s Internet Protocol address (e.g. IP address), browser type, browser version, the pages of our Service that you visit, the time and date of your visit, the time spent on those pages, unique device identifiers and other diagnostic data.

When you access Service with a device, this Usage Data may include information such as the type of device you use, your device unique ID, the IP address of your device, your device operating system, the type of Internet browser you use, unique device identifiers and other diagnostic data.

Tracking Cookies Data

We use cookies and similar tracking technologies to track the activity on our Service and we hold certain information.

Cookies are files with a small amount of data which may include an anonymous unique identifier. Cookies are sent to your browser from a website and stored on your device. Other tracking technologies are also used such as beacons, tags, and scripts to collect and track information and to improve and analyze our Service.

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our Service.

Examples of Cookies we use:
0.1. Session Cookies:

We use Session Cookies to operate our Service.

0.2. Preference Cookies:

We use Preference Cookies to remember your preferences and various settings.

0.3. Security Cookies:

We use Security Cookies for security purposes.

0.4. Advertising Cookies:

Advertising Cookies are used to serve you with advertisements that may be relevant to you and your interests.

Other Data

While using our Service, we may also collect the following information: sex, age, date of birth, place of birth, passport details, citizenship, registration at the place of residence and actual address, telephone number (work, mobile), details of documents on education, qualification, professional training, employment agreements, NDA agreements, information on bonuses and compensation, information on marital status, family members, social security (or other taxpayer identification) number, office location, and other data.

5. Use of Data

Thingsatweb Sweden AB uses the collected data for various purposes:

0.1. To provide and maintain our Service;

0.2. To notify you about changes to our Service;

0.3. To allow you to participate in interactive features of our Service when you choose to do so;

0.4. To provide customer support;

0.5. To gather analysis or valuable information so that we can improve our Service;

00.6. To monitor the usage of our Service;

0.7. To detect, prevent and address technical issues;

0.8. To fulfill any other purpose for which you provide it;

0.9. To carry out our obligations and enforce our rights arising from any contracts entered into between you and us, including for billing and collection;

0.10. To provide you with notices about your account and/or subscription, including expiration and renewal notices, email instructions, etc.

0.11. To provide you with news, special offers, and general information about other goods, services, and events which we offer that are similar to those that you have already purchased or enquired about unless you have opted not to receive such information;

0.12. In any other way, we may describe when you provide the information;

0.13. For any other purpose with your consent.

6. Retention of Data

We will retain your Personal Data only for as long as is necessary for the purposes set out in this Privacy Policy. We will retain and use your Personal Data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies.

We will also retain Usage Data for internal analysis purposes. Usage Data is generally retained for a shorter period, except when this data is used to strengthen the security or to improve the functionality of our Service, or we are legally obligated to retain this data for longer time periods.

7. Transfer of Data

Your information, including Personal Data, may be transferred to – and maintained on – computers located outside of your state, province, country, or other governmental jurisdiction where the data protection laws may differ from those of your jurisdiction.

If you are located outside Sweden and choose to provide information to us, please note that we transfer the data, including Personal Data, to Sweden and process it there.

Your consent to this Privacy Policy followed by your submission of such information represents your agreement to that transfer.

Thingsatweb Sweden AB will take all the steps reasonably necessary to ensure that your data is treated securely and in accordance with this Privacy Policy and no transfer of your Personal Data will take place to an organization or a country unless there are adequate controls in place including the security of your data and other personal information.

8. Disclosure of Data

We may disclose personal information that we collect, or you provide:

0.1. Disclosure for Law Enforcement.

Under certain circumstances, we may be required to disclose your Personal Data if required to do so by law or in response to valid requests by public authorities.

0.2. Business Transaction.

If we or our subsidiaries are involved in a merger, acquisition, or asset sale, your Personal Data may be transferred.

0.3. Other cases. We may disclose your information also:

0.3.1. To our subsidiaries and affiliates;

0.3.2. To contractors, service providers, and other third parties we use to support our business;

0.3.3. To fulfill the purpose for which you provide it;

0.3.4. for the purpose of including your company’s logo on our website;

0.3.5. for any other purpose disclosed by us when you provide the information;

0.3.6. with your consent in any other cases;

0.3.7. If we believe disclosure is necessary or appropriate to protect the rights, property, or safety of the Company, our customers, or others.

9. Security of Data

The security of your data is important to us but remember that no method of transmission over the Internet or method of electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your Personal Data, we cannot guarantee its absolute security.

10. Your Data Protection Rights Under General Data Protection Regulation (GDPR)

If you are a resident of the European Union (EU) and European Economic Area (EEA), you have certain data protection rights, covered by GDPR.

We aim to take reasonable steps to allow you to correct, amend, delete, or limit the use of your Personal Data.

If you wish to be informed what Personal Data we hold about you and if you want it to be removed from our systems, please email us at kontakt@thingsatweb.se

In certain circumstances, you have the following data protection rights:

0.1. The right to access, update, or delete the information we have on you;

0.2. The right of rectification. You have the right to have your information rectified if that information is inaccurate or incomplete;

0.3. The right to object. You have the right to object to our processing of your Personal Data;

0.4. The right of restriction. You have the right to request that we restrict the processing of your personal information;

0.5. The right to data portability. You have the right to be provided with a copy of your Personal Data in a structured, machine-readable, and commonly used format;

0.6. The right to withdraw consent. You also have the right to withdraw your consent at any time where we rely on your consent to process your personal information;

Please note that we may ask you to verify your identity before responding to such requests.

Please note, we may not able to provide Service without some necessary data.

You have the right to complain to a Data Protection Authority about our collection and use of your Personal Data. For more information, please contact your local data protection authority in the European Economic Area (EEA).

Your Data Protection Rights under the California Privacy Protection Act (CalOPPA)

CalOPPA is the first state law in the nation to require commercial websites and online services to post a privacy policy. The law’s reach stretches well beyond California to require a person or company in the United States (and conceivable the world) that operates websites collecting personally identifiable information from California consumers to post a conspicuous privacy policy on its website stating exactly the information being collected and those individuals with whom it is being shared and to comply with this policy.

According to CalOPPA, we agree to the following:

0.1. Users can visit our site anonymously;

0.2. Our Privacy Policy link includes the word “Privacy”, and can easily be found on the home page of our website;

0.3. Users will be notified of any privacy policy changes on our Privacy Policy Page;

0.4. Users are able to change their personal information by emailing us at kontakt@thingsatweb.se

Our Policy on “Do Not Track” Signals: We honour Do Not Track signals and do not track plant cookies, or use advertising when a Do Not Track browser mechanism is in place. Do Not Track is a preference you can set in your web browser to inform websites that you do not want to be tracked.

You can enable or disable Do Not Track by visiting the Preferences or Settings page of your web browser.

12. Your Data Protection Rights under the California Consumer Privacy Act (CCPA)

If you are a California resident, you are entitled to learn what data we collect about you, ask to delete your data, and not to sell (share) it. To exercise your data protection rights, you can make certain requests and ask us:

0.1. What personal information we have about you. If you make this request, we will return to you:

0.0.1. The categories of personal information we have collected about you.

0.0.2. The categories of sources from which we collect your personal information.

0.0.3. The business or commercial purpose for collecting or selling your personal information.

0.0.4. The categories of third parties with whom we share personal information.

0.0.5. The specific pieces of personal information we have collected about you.

0.0.6. A list of categories of personal information that we have sold, along with the category of any other company we sold it to. If we have not sold your personal information, we will inform you of that fact.

0.0.7. A list of categories of personal information that we have disclosed for a business purpose, along with the category of any other company we shared it with.

Please note, you are entitled to ask us to provide you with this information up to two times in a rolling twelve-month period. When you make this request, the information provided may be limited to the personal information we collected about you in the previous 12 months.

0.2. To delete your personal information. If you make this request, we will delete the personal information we hold about you as of the date of your request from our records and direct any service providers to do the same. In some cases, deletion may be accomplished through de-identification of the information. If you choose to delete your personal information, you may not be able to use certain functions that require your personal information to operate.

0.3. To stop selling your personal information. We don’t sell or rent your personal information to any third parties for any purpose. We do not sell your personal information for monetary consideration. However, under some circumstances, a transfer of personal information to a third party, or within our family of companies, without monetary consideration may be considered a “sale” under California law. You are the only owner of your Personal Data and can request disclosure or deletion at any time.

If you submit a request to stop selling your personal information, we will stop making such transfers.

Please note, if you ask us to delete or stop selling your data, it may impact your experience with us, and you may not be able to participate in certain programs or membership services that require the usage of your personal information to function. But in no circumstances, we will discriminate against you for exercising your rights. To exercise your California data protection rights described above, please send your request(s) by email: kontakt@thingsatweb.se

Your data protection rights, described above, are covered by the CCPA, short for the California Consumer Privacy Act. To find out more, visit the official California Legislative Information website. The CCPA took effect on 01/01/2020.

13. Service Providers

We may employ third-party companies and individuals to facilitate our Service (“Service Providers”), provide Service on our behalf, perform Service-related services or assist us in analyzing how our Service is used.

These third parties have access to your Personal Data only to perform these tasks on our behalf and are obligated not to disclose or use it for any other purpose.

14. Analytics

We may use third-party Service Providers to monitor and analyze the use of our Service.

15. CI/CD tools

We may use third-party Service Providers to automate the development process of our Service.

16. Behavioural Remarketing

We may use remarketing services to advertise on third-party websites to you after you visited our Service. We and our third-party vendors use cookies to inform, optimize and serve ads based on your past visits to our Service.

17. Links to Other Sites

Our Service may contain links to other sites that are not operated by us. If you click a third-party link, you will be directed to that third party’s site. We strongly advise you to review the Privacy Policy of every site you visit.

We have no control over and assume no responsibility for the content, privacy policies, or practices of any third-party sites or services.

20. Children’s Privacy

Our Services are not intended for use by children under the age of 18 (“Child” or “Children”).

We do not knowingly collect personally identifiable information from children under 18. If you become aware that a child has provided us with Personal Data, please contact us. If we become aware that we have collected Personal Data from children without verification of parental consent, we take steps to remove that information from our servers.

21. Changes to This Privacy Policy

We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page.

We will let you know via email and/or a prominent notice on our Service, prior to the change becoming effective and update “effective date” at the top of this Privacy Policy.

You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

22. Contact Us

If you have any questions about this Privacy Policy, please contact us by email: kontakt@thingsatweb.se