Privacy Policy / Integritetspolicy

Gäller från / Effective date: 30. 4. 2026

Version: 1.0

EasyEnskildFirma Effective date / Gäller från: [DATE TO BE INSERTED ON LAUNCH] Version: 1.0


This document is bilingual. Swedish (legally binding) version comes first, English (for convenience) follows. In case of any conflict between the two, the Swedish version prevails.


🇸🇪 SVENSKA VERSIONEN

1. Personuppgiftsansvarig

Personuppgiftsansvarig för behandling av personuppgifter enligt denna Integritetspolicy är:

Milos Tintor (enskild näringsverksamhet) Personnummer/Org.nr: 911010-6276 Adress: Östra Förstadsgatan 9A 211 31 Malmö E-post: support@easyenskildfirma.se

I denna policy benämns ovannämnda som “Leverantören”, “vi” eller “oss”. Den person vars personuppgifter behandlas benämns “du”, “dig” eller “Användaren”.

2. Två roller — viktig distinktion

Leverantören har två olika roller i förhållande till personuppgifter:

2.1 Personuppgiftsansvarig (denna policy)

Vi är personuppgiftsansvariga för:

  • Personuppgifter om dig som registrerar och använder ett konto i Tjänsten (t.ex. namn, e-post, betalningsuppgifter)
  • Personuppgifter om besökare på vår webbplats
  • Personuppgifter om personer som kontaktar vår support

Denna Integritetspolicy reglerar denna behandling.

2.2 Personuppgiftsbiträde (regleras i separat DPA)

Vi är personuppgiftsbiträde när du som Användare matar in personuppgifter om dina egna kunder, leverantörer eller affärskontakter i Tjänsten. För denna behandling är du personuppgiftsansvarig och vi behandlar uppgifterna enligt dina instruktioner.

Denna behandling regleras i ett separat Personuppgiftsbiträdesavtal (DPA) som du accepterar tillsammans med Användarvillkoren.

3. Vilka personuppgifter behandlar vi?

3.1 Uppgifter du lämnar vid registrering och användning

KategoriExempelKälla
IdentitetNamn, e-postadressDirekt från dig
FöretagsuppgifterFöretagsnamn, org.nr, VAT-nr, adressDirekt från dig och VIES (EU-kommissionens VAT-databas)
InloggningsuppgifterE-post, hashat lösenordDirekt från dig
BetalningsuppgifterStripe-kund-ID, faktureringshistorik (kortuppgifter lagras hos Stripe, inte hos oss)Stripe
AnvändardataBokföringshändelser, fakturor, utgifter — innehåller information om dig som näringsidkareDirekt från dig
Tekniska uppgifterIP-adress, webbläsartyp, enhetsinformation, åtkomsttiderAutomatiskt vid användning
SupportkommunikationKorrespondens med vår supportDirekt från dig

3.2 Cookies och liknande tekniker

Se vår separata Cookiepolicy för detaljerad information om cookies och liknande spårningstekniker. Vi använder Umami Analytics för anonym webbstatistik på vår marknadsföringssajt. Umami sätter inga cookies, samlar inga personuppgifter och ingen data delas med tredje part.

4. Ändamål och rättslig grund för behandlingen

ÄndamålRättslig grundLagringsperiod
Tillhandahålla Tjänsten (skapa konto, autentisering, drift)Fullgörande av avtal (art. 6.1.b GDPR)Under avtalstiden
Hantera betalning och faktureringFullgörande av avtal (art. 6.1.b GDPR) + rättslig förpliktelse (bokföringslagen)7 år enligt 7 kap. bokföringslagen
Användarsupport och hantering av reklamationerBerättigat intresse (art. 6.1.f GDPR)Under avtalstiden + 3 år
Säkerhet (loggning, intrångsdetektering, kontoskydd)Berättigat intresse (art. 6.1.f GDPR)Maximalt 12 månader för loggar
Utveckling och förbättring av Tjänsten (anonymiserad analys)Berättigat intresse (art. 6.1.f GDPR)Aggregerad data — obegränsat
Information till Användare (väsentliga uppdateringar, säkerhetsmeddelanden)Berättigat intresse (art. 6.1.f GDPR)Under avtalstiden
Marknadsföring av egna tjänster till befintliga AnvändareBerättigat intresse (art. 6.1.f GDPR) — Användaren kan när som helst invända3 år efter avtalets upphörande eller tills invändning
Hantering av rättsliga anspråkBerättigat intresse (art. 6.1.f GDPR)10 år enligt preskriptionslagen

4.1 Berättigat intresse — närmare förklaring

För behandlingar som baseras på berättigat intresse har vi gjort en intresseavvägning där vi bedömt att vårt intresse av att tillhandahålla, säkra och förbättra Tjänsten väger tyngre än Användarens intresse av att uppgifterna inte behandlas. Du har alltid rätt att invända mot sådan behandling — se avsnitt 9.

5. Vem delar vi uppgifterna med?

5.1 Underleverantörer (personuppgiftsbiträden)

Vi anlitar följande underleverantörer som behandlar personuppgifter för vår räkning:

UnderleverantörTjänstPlats för behandling
Supabase Inc.Databas, autentisering, fillagringEU (eu-west-1, Ireland)
Stripe Payments Europe Ltd.BetalningshanteringIrland (EU) + USA (med SCC)
Resend, Inc.Transaktionella e-postutskickUSA (med SCC och Data Processing Agreement)
Cloudflare, Inc.DNS, hosting, säkerhet, CDNGlobalt CDN, primär region EU (med SCC)
Umami CloudAnonym webbanalys (ingen PII)EU
Frankfurter APIVäxelkurser (ingen PII)Tyskland (EU)

Vi har skriftliga personuppgiftsbiträdesavtal med samtliga av ovanstående underleverantörer.

5.2 Myndigheter

Vi kan komma att lämna ut uppgifter till svenska eller utländska myndigheter om vi är skyldiga enligt lag eller domstolsbeslut.

5.3 Vid överlåtelse av verksamhet

Om vi överlåter vår verksamhet (t.ex. vid ombildning till aktiebolag eller försäljning) kan personuppgifter komma att överföras till förvärvaren. Användaren informeras i sådant fall.

5.4 Ingen försäljning av uppgifter

Vi säljer inte personuppgifter till tredje part och använder inte uppgifterna för riktad reklam från tredje part.

6. Överföring utanför EU/EES

Vissa av våra underleverantörer är etablerade utanför EU/EES (USA). I dessa fall säkerställer vi att lämpliga skyddsåtgärder finns enligt GDPR, exempelvis:

a) EU-kommissionens standardavtalsklausuler (SCC) för överföring till tredje land, b) EU-US Data Privacy Framework där tillämpligt, c) Tekniska skyddsåtgärder som kryptering och pseudonymisering.

Du har rätt att begära en kopia av de skyddsåtgärder som vidtagits för specifik överföring genom att kontakta support@easyenskildfirma.se.

7. Lagringstider

Vi lagrar personuppgifter endast så länge det är nödvändigt för de ändamål för vilka uppgifterna samlats in, eller så länge vi är skyldiga enligt lag.

7.1 Sammanfattning

DatatypLagringstid
Aktiva användarkonton (Premium eller Gratis)Under avtalstiden
Användardata efter kontoraderingRaderas omedelbart efter Kundens bekräftelse; krypterad säkerhetskopia behålls i 14 dagar för återställning vid systemfel
Användardata vid uppsägning från Leverantören30 dagars varsel för export, därefter radering
Faktureringsuppgifter (Leverantörens egen bokföring)7 år enligt bokföringslagen
SäkerhetsloggarMaximalt 12 månader
MarknadsföringspreferenserTills återkallelse
Supportärenden3 år efter avslut

7.2 Anonymisering

Efter att lagringstiden gått ut raderas eller anonymiseras uppgifterna. Anonymiserad data (utan möjlighet att identifiera enskild person) kan behållas på obestämd tid för statistik och produktutveckling.

8. Säkerhetsåtgärder

Vi vidtar lämpliga tekniska och organisatoriska säkerhetsåtgärder för att skydda personuppgifter mot förlust, missbruk och obehörig åtkomst, inklusive:

  • Kryptering av data i vila (databas) och i transit (HTTPS/TLS)
  • Hashning av lösenord (aldrig lagrade i klartext)
  • Row-Level Security (RLS) i databasen för att säkerställa att Användare endast kan komma åt egna data
  • Tvåfaktorsautentisering för administrativ åtkomst
  • Regelbundna säkerhetsuppdateringar av infrastruktur
  • Begränsad åtkomst för administrativ personal — endast vad som krävs för felsökning eller support
  • Loggning av åtkomst till känsliga system

Trots dessa åtgärder kan ingen säkerhet på internet garanteras vara 100% säker. Du använder Tjänsten på egen risk i enlighet med Användarvillkoren.

8.1 Personuppgiftsincident (data breach)

Vid en bekräftad personuppgiftsincident som sannolikt leder till risk för rättigheter och friheter för fysiska personer kommer vi att:

a) anmäla incidenten till Integritetsskyddsmyndigheten (IMY) inom 72 timmar, b) informera berörda Användare utan onödigt dröjsmål om risken är hög.

9. Dina rättigheter enligt GDPR

Som registrerad har du följande rättigheter:

9.1 Rätt till tillgång (art. 15)

Du har rätt att få bekräftelse på huruvida vi behandlar personuppgifter om dig och, om så är fallet, få tillgång till uppgifterna och information om behandlingen.

9.2 Rätt till rättelse (art. 16)

Du har rätt att få felaktiga eller ofullständiga personuppgifter rättade. Mycket av denna rättelse kan du göra själv genom inställningarna i Tjänsten.

9.3 Rätt till radering / “rätt att bli glömd” (art. 17)

Du har rätt att få dina personuppgifter raderade, om uppgifterna inte längre behövs eller om du återkallar samtycke. Notera att vi har skyldighet att behålla viss information enligt bokföringslagen i 7 år (t.ex. faktureringsuppgifter), och denna skyldighet begränsar din rätt till radering för dessa specifika uppgifter.

9.4 Rätt till begränsning av behandling (art. 18)

Du har rätt att begära att behandlingen av dina uppgifter begränsas, t.ex. medan en invändning behandlas.

9.5 Rätt till dataportabilitet (art. 20)

Du har rätt att få ut de personuppgifter du lämnat till oss i ett strukturerat, allmänt använt och maskinläsbart format. Tjänsten innehåller exportfunktioner som ger dig denna möjlighet (t.ex. CSV-export).

9.6 Rätt att invända (art. 21)

Du har rätt att invända mot behandling som baseras på berättigat intresse (inklusive marknadsföring). Om du invänder mot direktmarknadsföring upphör vi omedelbart med sådan behandling.

9.7 Rätt att inte vara föremål för automatiserat beslutsfattande (art. 22)

Vi använder inte automatiserat beslutsfattande som har rättsliga eller liknande betydande effekter på dig.

9.8 Hur du utövar dina rättigheter

Skicka begäran till support@easyenskildfirma.se. Vi besvarar din begäran inom en (1) månad, eller informerar dig om att vi behöver längre tid (max ytterligare två månader vid komplexa ärenden).

Det är kostnadsfritt att utöva dina rättigheter. Vid uppenbart ogrundade eller orimligt repetitiva förfrågningar kan vi dock ta ut en rimlig avgift eller vägra att efterkomma begäran.

För att skydda din integritet kan vi behöva verifiera din identitet innan vi behandlar din begäran.

10. Klagomål till tillsynsmyndighet

Om du anser att vår behandling av dina personuppgifter strider mot GDPR har du rätt att lämna in klagomål till tillsynsmyndigheten:

Integritetsskyddsmyndigheten (IMY) Box 8114, 104 20 Stockholm Telefon: 08-657 61 00 E-post: imy@imy.se Webbplats: https://www.imy.se

Vi uppskattar dock om du kontaktar oss först så att vi får möjlighet att åtgärda eventuella problem direkt.

11. Cookies och spårning

Vi använder cookies och liknande tekniker. Detaljerad information finns i vår separata Cookiepolicy.

12. Ändringar av Integritetspolicyn

Vi kan komma att uppdatera denna Integritetspolicy. Vid väsentliga ändringar informerar vi dig:

a) via e-post till den e-postadress vi har registrerad, och/eller b) via meddelande i Tjänsten,

minst trettio (30) dagar före ändringen träder i kraft.

Mindre ändringar (t.ex. språkliga förtydliganden) kan göras utan föregående varsel. Vi rekommenderar att du regelbundet ser över denna policy.

13. Kontakt

Vid frågor om denna Integritetspolicy eller vår behandling av personuppgifter, kontakta:

E-post: support@easyenskildfirma.se Postadress: Se avsnitt 1

Vi har inget krav på att ha ett dataskyddsombud (DPO) enligt GDPR art. 37 eftersom vår verksamhet inte involverar storskalig systematisk övervakning eller storskalig behandling av särskilda kategorier av personuppgifter.


🇬🇧 ENGLISH VERSION (for convenience only)

Note: This English translation is provided for convenience only. In case of any conflict between the Swedish and English version, the Swedish version prevails.

1. Data Controller

The data controller for the processing of personal data under this Privacy Policy is:

Milos TIntor (sole proprietorship / enskild näringsverksamhet) Personal ID/Business Registration Number: 911010-6276 Address: [ADDRESS] Email: support@easyenskildfirma.se

In this policy, the above is referred to as the “Provider”, “we” or “us”. The person whose personal data is processed is referred to as “you” or the “User”.

2. Two Roles — Important Distinction

The Provider has two different roles in relation to personal data:

2.1 Data Controller (this policy)

We are the data controller for:

  • Personal data about you who register and use an account in the Service (e.g., name, email, payment information)
  • Personal data about visitors to our website
  • Personal data about people who contact our support

This Privacy Policy regulates this processing.

2.2 Data Processor (regulated in separate DPA)

We act as a data processor when you as a User enter personal data about your own customers, suppliers, or business contacts into the Service. For this processing, you are the data controller and we process the data according to your instructions.

This processing is regulated in a separate Data Processing Agreement (DPA) that you accept together with the Terms of Service.

3. What Personal Data We Process

3.1 Information you provide at registration and use

CategoryExamplesSource
IdentityName, email addressDirectly from you
Company informationCompany name, org. number, VAT number, addressDirectly from you and VIES (EU Commission’s VAT database)
Login credentialsEmail, hashed passwordDirectly from you
Payment informationStripe customer ID, billing history (card details stored at Stripe, not with us)Stripe
User dataBookkeeping events, invoices, expenses — contains information about you as a sole proprietorDirectly from you
Technical informationIP address, browser type, device information, access timesAutomatically at use
Support communicationCorrespondence with our supportDirectly from you

3.2 Cookies and similar technologies

See our separate Cookie Policy for detailed information about cookies and similar tracking technologies. We use Umami Analytics for anonymous web statistics on our marketing site. Umami sets no cookies, collects no personal data, and no data is shared with third parties.

PurposeLegal basisRetention period
Provide the Service (account creation, authentication, operation)Contract (art. 6.1.b GDPR)During the term
Manage payment and billingContract (art. 6.1.b GDPR) + legal obligation (Bookkeeping Act)7 years per Chapter 7 of the Bookkeeping Act
User support and handling of complaintsLegitimate interest (art. 6.1.f GDPR)During the term + 3 years
Security (logging, intrusion detection, account protection)Legitimate interest (art. 6.1.f GDPR)Maximum 12 months for logs
Development and improvement of the Service (anonymized analysis)Legitimate interest (art. 6.1.f GDPR)Aggregated data — indefinite
Information to Users (material updates, security notices)Legitimate interest (art. 6.1.f GDPR)During the term
Marketing of own services to existing UsersLegitimate interest (art. 6.1.f GDPR) — User can object at any time3 years after termination of agreement or until objection
Handling of legal claimsLegitimate interest (art. 6.1.f GDPR)10 years per the Statute of Limitations

4.1 Legitimate interest — further explanation

For processing based on legitimate interest, we have made a balancing test where we have determined that our interest in providing, securing, and improving the Service outweighs the User’s interest in not having the data processed. You always have the right to object to such processing — see section 9.

5. Who We Share the Data With

5.1 Subprocessors (data processors)

We engage the following subprocessors who process personal data on our behalf:

SubprocessorServiceLocation of processing
Supabase Inc.Database, authentication, file storageEU (eu-west-1, Ireland)
Stripe Payments Europe Ltd.Payment processingIreland (EU) + USA (with SCC)
Resend, Inc.Transactional emailUSA (with SCC and Data Processing Agreement)
Cloudflare, Inc.DNS, hosting, security, CDNGlobal CDN, primary region EU (with SCC)
Umami CloudAnonymous web analytics (no PII)EU
Frankfurter APIExchange rates (no PII)Germany (EU)

We have written data processing agreements with all of the above subprocessors.

5.2 Authorities

We may disclose data to Swedish or foreign authorities if we are required to do so by law or court order.

5.3 In case of business transfer

If we transfer our business (e.g., upon conversion to a limited liability company or sale), personal data may be transferred to the acquirer. The User is informed in such case.

5.4 No sale of data

We do not sell personal data to third parties and we do not use the data for targeted advertising from third parties.

6. Transfer Outside the EU/EEA

Some of our subprocessors are established outside the EU/EEA (USA). In these cases, we ensure that appropriate safeguards are in place under the GDPR, such as:

a) EU Commission Standard Contractual Clauses (SCC) for transfers to third countries, b) EU-US Data Privacy Framework where applicable, c) Technical safeguards such as encryption and pseudonymization.

You have the right to request a copy of the safeguards taken for a specific transfer by contacting support@easyenskildfirma.se.

7. Retention Periods

We store personal data only as long as it is necessary for the purposes for which the data was collected, or as long as we are required by law.

7.1 Summary

Data typeRetention period
Active user accounts (Premium or Free)During the term
User data after account deletionDeleted immediately upon Customer confirmation; encrypted backup retained for 14 days for restoration in case of system failure
User data upon termination by the Provider30 days’ notice for export, then deletion
Billing data (Provider’s own bookkeeping)7 years per the Bookkeeping Act
Security logsMaximum 12 months
Marketing preferencesUntil withdrawal
Support cases3 years after closure

7.2 Anonymization

After the retention period has expired, the data is deleted or anonymized. Anonymized data (without the possibility to identify an individual person) may be retained indefinitely for statistics and product development.

8. Security Measures

We take appropriate technical and organizational security measures to protect personal data against loss, misuse, and unauthorized access, including:

  • Encryption of data at rest (database) and in transit (HTTPS/TLS)
  • Hashing of passwords (never stored in plaintext)
  • Row-Level Security (RLS) in the database to ensure Users can only access their own data
  • Two-factor authentication for administrative access
  • Regular security updates of infrastructure
  • Limited access for administrative personnel — only what is required for troubleshooting or support
  • Logging of access to sensitive systems

Despite these measures, no security on the internet can be guaranteed to be 100% secure. You use the Service at your own risk in accordance with the Terms of Service.

8.1 Personal data breach

In the event of a confirmed personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will:

a) report the incident to the Swedish Authority for Privacy Protection (IMY) within 72 hours, b) inform affected Users without undue delay if the risk is high.

9. Your Rights Under GDPR

As a data subject, you have the following rights:

9.1 Right of access (art. 15)

You have the right to obtain confirmation as to whether we are processing personal data about you and, if so, access to the data and information about the processing.

9.2 Right to rectification (art. 16)

You have the right to have incorrect or incomplete personal data corrected. Much of this correction can be done by you through the settings in the Service.

9.3 Right to erasure / “right to be forgotten” (art. 17)

You have the right to have your personal data erased if the data is no longer needed or if you withdraw consent. Note that we have an obligation to retain certain information under the Bookkeeping Act for 7 years (e.g., billing data), and this obligation limits your right to erasure for that specific data.

9.4 Right to restriction of processing (art. 18)

You have the right to request that the processing of your data be restricted, e.g., while an objection is being processed.

9.5 Right to data portability (art. 20)

You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. The Service includes export functions that give you this opportunity (e.g., CSV export).

9.6 Right to object (art. 21)

You have the right to object to processing based on legitimate interest (including marketing). If you object to direct marketing, we immediately cease such processing.

9.7 Right not to be subject to automated decision-making (art. 22)

We do not use automated decision-making that has legal or similar significant effects on you.

9.8 How to exercise your rights

Send your request to support@easyenskildfirma.se. We will respond to your request within one (1) month, or inform you that we need longer time (maximum two additional months for complex cases).

It is free of charge to exercise your rights. However, in the case of manifestly unfounded or unreasonably repetitive requests, we may charge a reasonable fee or refuse to comply with the request.

To protect your privacy, we may need to verify your identity before processing your request.

10. Complaint to Supervisory Authority

If you believe our processing of your personal data is contrary to the GDPR, you have the right to lodge a complaint with the supervisory authority:

Swedish Authority for Privacy Protection (IMY) Box 8114, 104 20 Stockholm Phone: +46 8-657 61 00 Email: imy@imy.se Website: https://www.imy.se

We do, however, appreciate if you contact us first so that we have the opportunity to address any issues directly.

11. Cookies and Tracking

We use cookies and similar technologies. Detailed information is available in our separate Cookie Policy.

12. Changes to the Privacy Policy

We may update this Privacy Policy. In case of material changes, we will inform you:

a) via email to the email address we have registered, and/or b) via notification in the Service,

at least thirty (30) days before the change takes effect.

Minor changes (e.g., language clarifications) may be made without prior notice. We recommend that you regularly review this policy.

13. Contact

For questions about this Privacy Policy or our processing of personal data, contact:

Email: support@easyenskildfirma.se Postal address: See section 1

We are not required to have a Data Protection Officer (DPO) under GDPR art. 37 because our operations do not involve large-scale systematic monitoring or large-scale processing of special categories of personal data.


Document version: 1.0 Last updated: 30. 4. 2026. Contact: support@easyenskildfirma.se