Skip to content
Legal

Privacy policy

We collect as little as we can. This page says what the site actually does with information about you, why, and what you can ask of us.

Who is responsible

Softsyde AB, registration number 559598-7354, Bremergatan 11, 392 33 Kalmar, is the controller of the personal data processed here. That means we decide why and how it is processed, and that we are the ones you come to with questions.

Write to info@softsyde.se. The people who build the site are the people who answer.

What this policy covers

It covers softsyde.se, the pages you are reading now.

  • Fidova at fidova.se is a separate service with its own information about personal data.
  • In client projects we process data on the client’s behalf, as their processor. Their policy applies there, and the agreement we have with them governs it.

What you send us

The contact form asks for a name, an email address, a topic and a message. Company is optional. What you send lands in our inbox and is read by us.

We use it to answer you and to carry the conversation forward. The legal basis is steps taken prior to a contract when you ask about a project (Article 6(1)(b) GDPR), and otherwise our legitimate interest in replying to people who get in touch (Article 6(1)(f)).

We do not add you to any mailing list, do not pass your details on for marketing, and never sell them.

What the server logs

Like every web server, ours notes which page was requested, when, from which IP address, with which browser and where you arrived from. The logs are used to run the site and keep it safe, for example to find faults and stop abuse. The legal basis is our legitimate interest in keeping the site up (Article 6(1)(f)).

We do not tie the logs to individual visitors, we build no profiles, and we make no automated decisions about you.

Cookies and browser storage

The site has no analytics and no advertising, so there is no cookie banner to click away. This is what gets stored:

  • SOFTSYDE_LOCALE: a cookie that remembers whether you read Swedish or English, so you land in the right place next time. It holds nothing but sv or en and lasts a year.
  • softsyde-theme: your choice of light or dark mode, kept in the browser’s local storage. It is not a cookie, is never sent to us, and never leaves your device.

What your browser loads

Everything on these pages comes from our own address. The fonts are hosted by us rather than fetched from Google, and we embed no maps, videos, share buttons or tracking pixels. Your browser tells nobody else that you are reading here.

Who else can see your data

We use as few suppliers as we can. Those who process data for us do so on our instructions and under a data processing agreement. Where data reaches a country outside the EU and the EEA, the transfer rests on the European Commission’s standard contractual clauses or another valid safeguard.

These are the ones who may come into contact with data:

  • Vercel Inc., which hosts the site and therefore handles the server logs.
  • Our email provider, which handles messages from the form the way it handles ordinary email.
  • Advisers and authorities, to the extent the law requires it, for example for bookkeeping and audit.

How long we keep things

We keep nothing longer than we need to:

  • Messages and email: as long as the conversation is live, and up to 24 months after that in case there is a follow up.
  • If it becomes a project: for as long as the agreement runs, and for seven years for anything that counts as accounting information under the Swedish Bookkeeping Act.
  • Server logs: a short time at our hosting provider, which deletes them automatically.
  • The language cookie: one year, or until you clear it in your browser.

Your rights

The GDPR gives you rights over your data. Email info@softsyde.se and we will sort it out, free of charge and normally within a month. You can:

  • Find out what data we hold about you and get a copy.
  • Have inaccurate data corrected and incomplete data completed.
  • Have data erased once we no longer have a reason to keep it.
  • Ask us to restrict processing while something is being sorted out.
  • Object to processing that rests on legitimate interest.
  • Get the data you gave us in a machine readable format, or moved to someone else.
  • Complain to the Swedish Authority for Privacy Protection, imy.se, if you think we are getting it wrong. Tell us first if you like, and we will try to put it right.

Security

All traffic is encrypted over HTTPS, and access to our inbox and our hosting is limited to the people who work in the company.

If a personal data breach happens anyway, we report it to the Swedish Authority for Privacy Protection within 72 hours where the rules require it, and tell you about it if it puts you at high risk.

Changes

If we change how the site handles data, we update this page and the date in the margin. What stands here is the version that applies.

Questions about this policy?

Write a line and we will answer. What applies to the site itself is in the terms of service.