Privacy policy
Last updated: [date]
Draft – to be reviewed by a lawyer and completed with company details before launch.
Controller
What we process
- Account: e-mail address, password (stored only as a one-way hash), language, when the account was created and when you accepted the terms.
- Subscription: plan, status and billing period. Card details are handled only by Stripe – we never see or store them.
- Settings: your chart and alert settings.
- Technical data: IP address and timestamps in server logs and for protection against break-in attempts.
Purposes and legal basis
- Providing the service and your account – contract.
- Charging and bookkeeping – contract and legal obligation (Swedish Bookkeeping Act).
- Security, e.g. blocking after repeated failed logins – legitimate interest.
- Necessary service e-mails (confirmation, password, receipts, payment reminders) – contract. No newsletters without your consent.
Recipients
- Stripe (payments) – may transfer data to the US under the EU-US Data Privacy Framework and standard contractual clauses.
- [E-mail provider] – sends service e-mails.
- [Hosting provider] – the server the service runs on, in [country].
We never sell personal data. Fonts and chart libraries are served from our own server, so no third party sees your visit.
Retention
Account data is kept as long as you have an account and is deleted right away when you delete it. Payment records are kept for seven years as required by bookkeeping law. Server logs are kept for at most [30] days.
Your rights
You have the right to access, correct and delete your data, to restrict or object to processing, and to data portability. You can delete your account yourself under Account. Contact us for anything else. You can also complain to the Swedish Authority for Privacy Protection (IMY), imy.se.