Privacy Policy
Last updated: [DATE]
This privacy policy describes how [COMPANY NAME] ("we", "us", "our") collects, uses, and protects your personal data when you use our website and services.
1. Data Controller
[COMPANY NAME] Organization number: [ORG.NUMBER] Address: [ADDRESS] Email: [EMAIL] Phone: [PHONE]
2. Your Rights Under GDPR
Under the General Data Protection Regulation (GDPR), you have the following rights:
- **Right of access** - You have the right to confirmation of whether we process your personal data and request a copy
- **Right to rectification** - You can request correction of inaccurate data
- **Right to erasure** - You can request deletion of your data ("right to be forgotten")
- **Right to restriction** - You can request restriction of processing your data
- **Right to data portability** - You can request your data in machine-readable format
- **Right to object** - You can object to processing of your data
- **Right not to be subject to automated decision-making** - Including profiling
To exercise your rights, contact us at [EMAIL].
3. What Personal Data Do We Collect?
3.1 Account Information
- Name
- Email address
- Password (encrypted)
- Username
3.2 Usage Data
- IP address
- Browser type and version
- Pages visited
- Time and date of visit
- Referral URL
- Device information
3.3 Payment Information
We do NOT store your card details. Payments are processed by [PAYMENT PROVIDER] which is PCI DSS certified. We only receive payment confirmation and transaction ID.
3.4 Health Data
**IMPORTANT:** Our exercises may involve sharing sensitive personal data (health, mental well-being). This data:
- Is stored locally in your browser (not on our servers)
- Is permanently deleted if you clear browser data
- Is NEVER shared with third parties
- Requires your explicit consent under GDPR Article 9
4. Legal Basis for Processing
- **Performance of contract** - To provide services you requested
- **Consent** - When you have approved our processing of your data
- **Legitimate interest** - To improve our services and security
- **Legal obligation** - To comply with Swedish law (e.g., accounting law)
5. How Do We Use Your Data?
- Provide and maintain our services
- Manage your account and subscription
- Send confirmations and updates
- Process payments
- Communicate with you about support
- Improve our services
- Comply with legal requirements
- Prevent fraud and abuse
6. Do We Share Your Data?
We NEVER sell your personal data. We only share data with:
Service Providers
Companies that help us deliver services:
- Payment provider: [PROVIDER]
- Web hosting: [PROVIDER]
- Email service: [PROVIDER]
- Analytics: [PROVIDER]
All have Data Processing Agreements (DPA) under GDPR.
Legal Requirements
We may share data if required by law or to:
- Comply with legal processes
- Protect our rights
- Prevent fraud
- Protect user safety
7. How Long Do We Keep Your Data?
- **Account data** - While your account is active + 30 days after deletion
- **Payment data** - 7 years (according to accounting law)
- **Support correspondence** - 3 years
- **Marketing data** - Until you unsubscribe
- **Anonymized statistics** - Indefinitely
8. How Do We Protect Your Data?
- **Encryption** - All data transferred via HTTPS (SSL/TLS)
- **Passwords** - Hashed with bcrypt
- **Access control** - Limited access to personal data
- **Backups** - Regular encrypted backups
- **Updates** - Systems kept updated against security threats
- **Monitoring** - Continuous security monitoring
9. Cookies and Tracking
We use cookies to improve your experience. Read our [Cookie Policy](/cookie-settings) for details.
- **Essential cookies** - Required for the site to function
- **Functional cookies** - Save your preferences
- **Analytical cookies** - Help us improve the service
- **Marketing cookies** - Used with your consent
Web analytics
Our web analytics runs on our own servers — no data is shared with Google Analytics or any other third party. We measure which pages are visited, which exercises are completed and where visitors come from, so we can understand what actually helps. Your IP address is truncated before it is stored (192.168.1.55 becomes 192.168.1.0) and therefore cannot be linked back to you. Browser information is kept only as a category, such as "Chrome / Windows". This statistical data is deleted automatically after 90 days. You can turn analytics off at any time in your cookie settings — we then stop both measuring and storing anything in your browser.
10. International Transfers
Your data is primarily stored within the EU/EEA. If data is transferred outside the EU/EEA:
- We use EU Standard Contractual Clauses
- We ensure the recipient has adequate protection
- We inform you about the transfer
11. Children's Privacy
Our services are not directed to persons under 16 years old. We do not knowingly collect data from children under 16. If we discover we have such information, we delete it immediately. Parents/guardians can contact us at [EMAIL].
12. Third-Party Links
Our website may contain links to external sites. We are not responsible for their privacy practices. We recommend reading their privacy policies.
13. Changes to Privacy Policy
We may update this policy. Material changes will be communicated via email or on the website at least 30 days before taking effect. Continued use after changes implies acceptance.
14. Contact Us
For questions about this privacy policy or your personal data:
**Email:** [EMAIL] **Address:** [COMPANY NAME], [ADDRESS] **Data Protection Officer:** [NAME] (if applicable)
15. Complaints to Supervisory Authority
You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe the processing of your personal data violates GDPR.
**Swedish Authority for Privacy Protection (IMY)** Box 8114 104 20 Stockholm, Sweden Phone: +46 8-657 61 00 Email: imy@imy.se Website: www.imy.se