Privacy Policy / Integritetspolicy
Gäller från / Effective date: 30. 4. 2026
Version: 1.0
EasyEnskildFirma Effective date / Gäller från: [DATE TO BE INSERTED ON LAUNCH] Version: 1.0
This document is bilingual. Swedish (legally binding) version comes first, English (for convenience) follows. In case of any conflict between the two, the Swedish version prevails.
🇸🇪 SVENSKA VERSIONEN
1. Personuppgiftsansvarig
Personuppgiftsansvarig för behandling av personuppgifter enligt denna Integritetspolicy är:
Milos Tintor (enskild näringsverksamhet) Personnummer/Org.nr: 911010-6276 Adress: Östra Förstadsgatan 9A 211 31 Malmö E-post: support@easyenskildfirma.se
I denna policy benämns ovannämnda som “Leverantören”, “vi” eller “oss”. Den person vars personuppgifter behandlas benämns “du”, “dig” eller “Användaren”.
2. Två roller — viktig distinktion
Leverantören har två olika roller i förhållande till personuppgifter:
2.1 Personuppgiftsansvarig (denna policy)
Vi är personuppgiftsansvariga för:
- Personuppgifter om dig som registrerar och använder ett konto i Tjänsten (t.ex. namn, e-post, betalningsuppgifter)
- Personuppgifter om besökare på vår webbplats
- Personuppgifter om personer som kontaktar vår support
Denna Integritetspolicy reglerar denna behandling.
2.2 Personuppgiftsbiträde (regleras i separat DPA)
Vi är personuppgiftsbiträde när du som Användare matar in personuppgifter om dina egna kunder, leverantörer eller affärskontakter i Tjänsten. För denna behandling är du personuppgiftsansvarig och vi behandlar uppgifterna enligt dina instruktioner.
Denna behandling regleras i ett separat Personuppgiftsbiträdesavtal (DPA) som du accepterar tillsammans med Användarvillkoren.
3. Vilka personuppgifter behandlar vi?
3.1 Uppgifter du lämnar vid registrering och användning
| Kategori | Exempel | Källa |
|---|---|---|
| Identitet | Namn, e-postadress | Direkt från dig |
| Företagsuppgifter | Företagsnamn, org.nr, VAT-nr, adress | Direkt från dig och VIES (EU-kommissionens VAT-databas) |
| Inloggningsuppgifter | E-post, hashat lösenord | Direkt från dig |
| Betalningsuppgifter | Stripe-kund-ID, faktureringshistorik (kortuppgifter lagras hos Stripe, inte hos oss) | Stripe |
| Användardata | Bokföringshändelser, fakturor, utgifter — innehåller information om dig som näringsidkare | Direkt från dig |
| Tekniska uppgifter | IP-adress, webbläsartyp, enhetsinformation, åtkomsttider | Automatiskt vid användning |
| Supportkommunikation | Korrespondens med vår support | Direkt från dig |
3.2 Cookies och liknande tekniker
Se vår separata Cookiepolicy för detaljerad information om cookies och liknande spårningstekniker. Vi använder Umami Analytics för anonym webbstatistik på vår marknadsföringssajt. Umami sätter inga cookies, samlar inga personuppgifter och ingen data delas med tredje part.
4. Ändamål och rättslig grund för behandlingen
| Ändamål | Rättslig grund | Lagringsperiod |
|---|---|---|
| Tillhandahålla Tjänsten (skapa konto, autentisering, drift) | Fullgörande av avtal (art. 6.1.b GDPR) | Under avtalstiden |
| Hantera betalning och fakturering | Fullgörande av avtal (art. 6.1.b GDPR) + rättslig förpliktelse (bokföringslagen) | 7 år enligt 7 kap. bokföringslagen |
| Användarsupport och hantering av reklamationer | Berättigat intresse (art. 6.1.f GDPR) | Under avtalstiden + 3 år |
| Säkerhet (loggning, intrångsdetektering, kontoskydd) | Berättigat intresse (art. 6.1.f GDPR) | Maximalt 12 månader för loggar |
| Utveckling och förbättring av Tjänsten (anonymiserad analys) | Berättigat intresse (art. 6.1.f GDPR) | Aggregerad data — obegränsat |
| Information till Användare (väsentliga uppdateringar, säkerhetsmeddelanden) | Berättigat intresse (art. 6.1.f GDPR) | Under avtalstiden |
| Marknadsföring av egna tjänster till befintliga Användare | Berättigat intresse (art. 6.1.f GDPR) — Användaren kan när som helst invända | 3 år efter avtalets upphörande eller tills invändning |
| Hantering av rättsliga anspråk | Berättigat intresse (art. 6.1.f GDPR) | 10 år enligt preskriptionslagen |
4.1 Berättigat intresse — närmare förklaring
För behandlingar som baseras på berättigat intresse har vi gjort en intresseavvägning där vi bedömt att vårt intresse av att tillhandahålla, säkra och förbättra Tjänsten väger tyngre än Användarens intresse av att uppgifterna inte behandlas. Du har alltid rätt att invända mot sådan behandling — se avsnitt 9.
5. Vem delar vi uppgifterna med?
5.1 Underleverantörer (personuppgiftsbiträden)
Vi anlitar följande underleverantörer som behandlar personuppgifter för vår räkning:
| Underleverantör | Tjänst | Plats för behandling |
|---|---|---|
| Supabase Inc. | Databas, autentisering, fillagring | EU (eu-west-1, Ireland) |
| Stripe Payments Europe Ltd. | Betalningshantering | Irland (EU) + USA (med SCC) |
| Resend, Inc. | Transaktionella e-postutskick | USA (med SCC och Data Processing Agreement) |
| Cloudflare, Inc. | DNS, hosting, säkerhet, CDN | Globalt CDN, primär region EU (med SCC) |
| Umami Cloud | Anonym webbanalys (ingen PII) | EU |
| Frankfurter API | Växelkurser (ingen PII) | Tyskland (EU) |
Vi har skriftliga personuppgiftsbiträdesavtal med samtliga av ovanstående underleverantörer.
5.2 Myndigheter
Vi kan komma att lämna ut uppgifter till svenska eller utländska myndigheter om vi är skyldiga enligt lag eller domstolsbeslut.
5.3 Vid överlåtelse av verksamhet
Om vi överlåter vår verksamhet (t.ex. vid ombildning till aktiebolag eller försäljning) kan personuppgifter komma att överföras till förvärvaren. Användaren informeras i sådant fall.
5.4 Ingen försäljning av uppgifter
Vi säljer inte personuppgifter till tredje part och använder inte uppgifterna för riktad reklam från tredje part.
6. Överföring utanför EU/EES
Vissa av våra underleverantörer är etablerade utanför EU/EES (USA). I dessa fall säkerställer vi att lämpliga skyddsåtgärder finns enligt GDPR, exempelvis:
a) EU-kommissionens standardavtalsklausuler (SCC) för överföring till tredje land, b) EU-US Data Privacy Framework där tillämpligt, c) Tekniska skyddsåtgärder som kryptering och pseudonymisering.
Du har rätt att begära en kopia av de skyddsåtgärder som vidtagits för specifik överföring genom att kontakta support@easyenskildfirma.se.
7. Lagringstider
Vi lagrar personuppgifter endast så länge det är nödvändigt för de ändamål för vilka uppgifterna samlats in, eller så länge vi är skyldiga enligt lag.
7.1 Sammanfattning
| Datatyp | Lagringstid |
|---|---|
| Aktiva användarkonton (Premium eller Gratis) | Under avtalstiden |
| Användardata efter kontoradering | Raderas omedelbart efter Kundens bekräftelse; krypterad säkerhetskopia behålls i 14 dagar för återställning vid systemfel |
| Användardata vid uppsägning från Leverantören | 30 dagars varsel för export, därefter radering |
| Faktureringsuppgifter (Leverantörens egen bokföring) | 7 år enligt bokföringslagen |
| Säkerhetsloggar | Maximalt 12 månader |
| Marknadsföringspreferenser | Tills återkallelse |
| Supportärenden | 3 år efter avslut |
7.2 Anonymisering
Efter att lagringstiden gått ut raderas eller anonymiseras uppgifterna. Anonymiserad data (utan möjlighet att identifiera enskild person) kan behållas på obestämd tid för statistik och produktutveckling.
8. Säkerhetsåtgärder
Vi vidtar lämpliga tekniska och organisatoriska säkerhetsåtgärder för att skydda personuppgifter mot förlust, missbruk och obehörig åtkomst, inklusive:
- Kryptering av data i vila (databas) och i transit (HTTPS/TLS)
- Hashning av lösenord (aldrig lagrade i klartext)
- Row-Level Security (RLS) i databasen för att säkerställa att Användare endast kan komma åt egna data
- Tvåfaktorsautentisering för administrativ åtkomst
- Regelbundna säkerhetsuppdateringar av infrastruktur
- Begränsad åtkomst för administrativ personal — endast vad som krävs för felsökning eller support
- Loggning av åtkomst till känsliga system
Trots dessa åtgärder kan ingen säkerhet på internet garanteras vara 100% säker. Du använder Tjänsten på egen risk i enlighet med Användarvillkoren.
8.1 Personuppgiftsincident (data breach)
Vid en bekräftad personuppgiftsincident som sannolikt leder till risk för rättigheter och friheter för fysiska personer kommer vi att:
a) anmäla incidenten till Integritetsskyddsmyndigheten (IMY) inom 72 timmar, b) informera berörda Användare utan onödigt dröjsmål om risken är hög.
9. Dina rättigheter enligt GDPR
Som registrerad har du följande rättigheter:
9.1 Rätt till tillgång (art. 15)
Du har rätt att få bekräftelse på huruvida vi behandlar personuppgifter om dig och, om så är fallet, få tillgång till uppgifterna och information om behandlingen.
9.2 Rätt till rättelse (art. 16)
Du har rätt att få felaktiga eller ofullständiga personuppgifter rättade. Mycket av denna rättelse kan du göra själv genom inställningarna i Tjänsten.
9.3 Rätt till radering / “rätt att bli glömd” (art. 17)
Du har rätt att få dina personuppgifter raderade, om uppgifterna inte längre behövs eller om du återkallar samtycke. Notera att vi har skyldighet att behålla viss information enligt bokföringslagen i 7 år (t.ex. faktureringsuppgifter), och denna skyldighet begränsar din rätt till radering för dessa specifika uppgifter.
9.4 Rätt till begränsning av behandling (art. 18)
Du har rätt att begära att behandlingen av dina uppgifter begränsas, t.ex. medan en invändning behandlas.
9.5 Rätt till dataportabilitet (art. 20)
Du har rätt att få ut de personuppgifter du lämnat till oss i ett strukturerat, allmänt använt och maskinläsbart format. Tjänsten innehåller exportfunktioner som ger dig denna möjlighet (t.ex. CSV-export).
9.6 Rätt att invända (art. 21)
Du har rätt att invända mot behandling som baseras på berättigat intresse (inklusive marknadsföring). Om du invänder mot direktmarknadsföring upphör vi omedelbart med sådan behandling.
9.7 Rätt att inte vara föremål för automatiserat beslutsfattande (art. 22)
Vi använder inte automatiserat beslutsfattande som har rättsliga eller liknande betydande effekter på dig.
9.8 Hur du utövar dina rättigheter
Skicka begäran till support@easyenskildfirma.se. Vi besvarar din begäran inom en (1) månad, eller informerar dig om att vi behöver längre tid (max ytterligare två månader vid komplexa ärenden).
Det är kostnadsfritt att utöva dina rättigheter. Vid uppenbart ogrundade eller orimligt repetitiva förfrågningar kan vi dock ta ut en rimlig avgift eller vägra att efterkomma begäran.
För att skydda din integritet kan vi behöva verifiera din identitet innan vi behandlar din begäran.
10. Klagomål till tillsynsmyndighet
Om du anser att vår behandling av dina personuppgifter strider mot GDPR har du rätt att lämna in klagomål till tillsynsmyndigheten:
Integritetsskyddsmyndigheten (IMY) Box 8114, 104 20 Stockholm Telefon: 08-657 61 00 E-post: imy@imy.se Webbplats: https://www.imy.se
Vi uppskattar dock om du kontaktar oss först så att vi får möjlighet att åtgärda eventuella problem direkt.
11. Cookies och spårning
Vi använder cookies och liknande tekniker. Detaljerad information finns i vår separata Cookiepolicy.
12. Ändringar av Integritetspolicyn
Vi kan komma att uppdatera denna Integritetspolicy. Vid väsentliga ändringar informerar vi dig:
a) via e-post till den e-postadress vi har registrerad, och/eller b) via meddelande i Tjänsten,
minst trettio (30) dagar före ändringen träder i kraft.
Mindre ändringar (t.ex. språkliga förtydliganden) kan göras utan föregående varsel. Vi rekommenderar att du regelbundet ser över denna policy.
13. Kontakt
Vid frågor om denna Integritetspolicy eller vår behandling av personuppgifter, kontakta:
E-post: support@easyenskildfirma.se Postadress: Se avsnitt 1
Vi har inget krav på att ha ett dataskyddsombud (DPO) enligt GDPR art. 37 eftersom vår verksamhet inte involverar storskalig systematisk övervakning eller storskalig behandling av särskilda kategorier av personuppgifter.
🇬🇧 ENGLISH VERSION (for convenience only)
Note: This English translation is provided for convenience only. In case of any conflict between the Swedish and English version, the Swedish version prevails.
1. Data Controller
The data controller for the processing of personal data under this Privacy Policy is:
Milos TIntor (sole proprietorship / enskild näringsverksamhet) Personal ID/Business Registration Number: 911010-6276 Address: [ADDRESS] Email: support@easyenskildfirma.se
In this policy, the above is referred to as the “Provider”, “we” or “us”. The person whose personal data is processed is referred to as “you” or the “User”.
2. Two Roles — Important Distinction
The Provider has two different roles in relation to personal data:
2.1 Data Controller (this policy)
We are the data controller for:
- Personal data about you who register and use an account in the Service (e.g., name, email, payment information)
- Personal data about visitors to our website
- Personal data about people who contact our support
This Privacy Policy regulates this processing.
2.2 Data Processor (regulated in separate DPA)
We act as a data processor when you as a User enter personal data about your own customers, suppliers, or business contacts into the Service. For this processing, you are the data controller and we process the data according to your instructions.
This processing is regulated in a separate Data Processing Agreement (DPA) that you accept together with the Terms of Service.
3. What Personal Data We Process
3.1 Information you provide at registration and use
| Category | Examples | Source |
|---|---|---|
| Identity | Name, email address | Directly from you |
| Company information | Company name, org. number, VAT number, address | Directly from you and VIES (EU Commission’s VAT database) |
| Login credentials | Email, hashed password | Directly from you |
| Payment information | Stripe customer ID, billing history (card details stored at Stripe, not with us) | Stripe |
| User data | Bookkeeping events, invoices, expenses — contains information about you as a sole proprietor | Directly from you |
| Technical information | IP address, browser type, device information, access times | Automatically at use |
| Support communication | Correspondence with our support | Directly from you |
3.2 Cookies and similar technologies
See our separate Cookie Policy for detailed information about cookies and similar tracking technologies. We use Umami Analytics for anonymous web statistics on our marketing site. Umami sets no cookies, collects no personal data, and no data is shared with third parties.
4. Purposes and Legal Basis for Processing
| Purpose | Legal basis | Retention period |
|---|---|---|
| Provide the Service (account creation, authentication, operation) | Contract (art. 6.1.b GDPR) | During the term |
| Manage payment and billing | Contract (art. 6.1.b GDPR) + legal obligation (Bookkeeping Act) | 7 years per Chapter 7 of the Bookkeeping Act |
| User support and handling of complaints | Legitimate interest (art. 6.1.f GDPR) | During the term + 3 years |
| Security (logging, intrusion detection, account protection) | Legitimate interest (art. 6.1.f GDPR) | Maximum 12 months for logs |
| Development and improvement of the Service (anonymized analysis) | Legitimate interest (art. 6.1.f GDPR) | Aggregated data — indefinite |
| Information to Users (material updates, security notices) | Legitimate interest (art. 6.1.f GDPR) | During the term |
| Marketing of own services to existing Users | Legitimate interest (art. 6.1.f GDPR) — User can object at any time | 3 years after termination of agreement or until objection |
| Handling of legal claims | Legitimate interest (art. 6.1.f GDPR) | 10 years per the Statute of Limitations |
4.1 Legitimate interest — further explanation
For processing based on legitimate interest, we have made a balancing test where we have determined that our interest in providing, securing, and improving the Service outweighs the User’s interest in not having the data processed. You always have the right to object to such processing — see section 9.
5. Who We Share the Data With
5.1 Subprocessors (data processors)
We engage the following subprocessors who process personal data on our behalf:
| Subprocessor | Service | Location of processing |
|---|---|---|
| Supabase Inc. | Database, authentication, file storage | EU (eu-west-1, Ireland) |
| Stripe Payments Europe Ltd. | Payment processing | Ireland (EU) + USA (with SCC) |
| Resend, Inc. | Transactional email | USA (with SCC and Data Processing Agreement) |
| Cloudflare, Inc. | DNS, hosting, security, CDN | Global CDN, primary region EU (with SCC) |
| Umami Cloud | Anonymous web analytics (no PII) | EU |
| Frankfurter API | Exchange rates (no PII) | Germany (EU) |
We have written data processing agreements with all of the above subprocessors.
5.2 Authorities
We may disclose data to Swedish or foreign authorities if we are required to do so by law or court order.
5.3 In case of business transfer
If we transfer our business (e.g., upon conversion to a limited liability company or sale), personal data may be transferred to the acquirer. The User is informed in such case.
5.4 No sale of data
We do not sell personal data to third parties and we do not use the data for targeted advertising from third parties.
6. Transfer Outside the EU/EEA
Some of our subprocessors are established outside the EU/EEA (USA). In these cases, we ensure that appropriate safeguards are in place under the GDPR, such as:
a) EU Commission Standard Contractual Clauses (SCC) for transfers to third countries, b) EU-US Data Privacy Framework where applicable, c) Technical safeguards such as encryption and pseudonymization.
You have the right to request a copy of the safeguards taken for a specific transfer by contacting support@easyenskildfirma.se.
7. Retention Periods
We store personal data only as long as it is necessary for the purposes for which the data was collected, or as long as we are required by law.
7.1 Summary
| Data type | Retention period |
|---|---|
| Active user accounts (Premium or Free) | During the term |
| User data after account deletion | Deleted immediately upon Customer confirmation; encrypted backup retained for 14 days for restoration in case of system failure |
| User data upon termination by the Provider | 30 days’ notice for export, then deletion |
| Billing data (Provider’s own bookkeeping) | 7 years per the Bookkeeping Act |
| Security logs | Maximum 12 months |
| Marketing preferences | Until withdrawal |
| Support cases | 3 years after closure |
7.2 Anonymization
After the retention period has expired, the data is deleted or anonymized. Anonymized data (without the possibility to identify an individual person) may be retained indefinitely for statistics and product development.
8. Security Measures
We take appropriate technical and organizational security measures to protect personal data against loss, misuse, and unauthorized access, including:
- Encryption of data at rest (database) and in transit (HTTPS/TLS)
- Hashing of passwords (never stored in plaintext)
- Row-Level Security (RLS) in the database to ensure Users can only access their own data
- Two-factor authentication for administrative access
- Regular security updates of infrastructure
- Limited access for administrative personnel — only what is required for troubleshooting or support
- Logging of access to sensitive systems
Despite these measures, no security on the internet can be guaranteed to be 100% secure. You use the Service at your own risk in accordance with the Terms of Service.
8.1 Personal data breach
In the event of a confirmed personal data breach likely to result in a risk to the rights and freedoms of natural persons, we will:
a) report the incident to the Swedish Authority for Privacy Protection (IMY) within 72 hours, b) inform affected Users without undue delay if the risk is high.
9. Your Rights Under GDPR
As a data subject, you have the following rights:
9.1 Right of access (art. 15)
You have the right to obtain confirmation as to whether we are processing personal data about you and, if so, access to the data and information about the processing.
9.2 Right to rectification (art. 16)
You have the right to have incorrect or incomplete personal data corrected. Much of this correction can be done by you through the settings in the Service.
9.3 Right to erasure / “right to be forgotten” (art. 17)
You have the right to have your personal data erased if the data is no longer needed or if you withdraw consent. Note that we have an obligation to retain certain information under the Bookkeeping Act for 7 years (e.g., billing data), and this obligation limits your right to erasure for that specific data.
9.4 Right to restriction of processing (art. 18)
You have the right to request that the processing of your data be restricted, e.g., while an objection is being processed.
9.5 Right to data portability (art. 20)
You have the right to receive the personal data you have provided to us in a structured, commonly used, and machine-readable format. The Service includes export functions that give you this opportunity (e.g., CSV export).
9.6 Right to object (art. 21)
You have the right to object to processing based on legitimate interest (including marketing). If you object to direct marketing, we immediately cease such processing.
9.7 Right not to be subject to automated decision-making (art. 22)
We do not use automated decision-making that has legal or similar significant effects on you.
9.8 How to exercise your rights
Send your request to support@easyenskildfirma.se. We will respond to your request within one (1) month, or inform you that we need longer time (maximum two additional months for complex cases).
It is free of charge to exercise your rights. However, in the case of manifestly unfounded or unreasonably repetitive requests, we may charge a reasonable fee or refuse to comply with the request.
To protect your privacy, we may need to verify your identity before processing your request.
10. Complaint to Supervisory Authority
If you believe our processing of your personal data is contrary to the GDPR, you have the right to lodge a complaint with the supervisory authority:
Swedish Authority for Privacy Protection (IMY) Box 8114, 104 20 Stockholm Phone: +46 8-657 61 00 Email: imy@imy.se Website: https://www.imy.se
We do, however, appreciate if you contact us first so that we have the opportunity to address any issues directly.
11. Cookies and Tracking
We use cookies and similar technologies. Detailed information is available in our separate Cookie Policy.
12. Changes to the Privacy Policy
We may update this Privacy Policy. In case of material changes, we will inform you:
a) via email to the email address we have registered, and/or b) via notification in the Service,
at least thirty (30) days before the change takes effect.
Minor changes (e.g., language clarifications) may be made without prior notice. We recommend that you regularly review this policy.
13. Contact
For questions about this Privacy Policy or our processing of personal data, contact:
Email: support@easyenskildfirma.se Postal address: See section 1
We are not required to have a Data Protection Officer (DPO) under GDPR art. 37 because our operations do not involve large-scale systematic monitoring or large-scale processing of special categories of personal data.
Document version: 1.0 Last updated: 30. 4. 2026. Contact: support@easyenskildfirma.se