Data Processing Overview
Effective date: 15 July 2026 Last updated: 15 July 2026
This page explains, in plain language, which service providers (subprocessors) receive data when you use algosweden.se and AlgoSweden Studio (app.algosweden.se), what they receive, and why.
This is an overview, not a contract. It is provided for transparency and is not a signed Data Processing Agreement (DPA). Before using Studio to process personal data on your organisation's behalf, contact majed.tamim@algosweden.se to confirm the contractual terms required for that use case. Do not treat this page as an Article 28 agreement.
What data flows where
| Provider | What it receives | Why | Region and transfer basis |
|---|---|---|---|
| Microsoft Azure (hosting) | Website and Studio requests, IP addresses, standard server logs, application state of the generation runtime | Runs algosweden.se, app.algosweden.se, and the generation runtime | Verified deployment: North Europe (Ireland) for the applications; container registry, logs, and identities in Sweden Central. Microsoft publishes contractual privacy and transfer safeguards for Azure |
| Convex (database and backend) | Account profile data, projects, prompts, generated code, application state | Stores and serves the data that makes Studio work | Verified EU deployment (eu-west-1). Convex is US-headquartered; its current data-processing terms describe the safeguards available for international transfers |
| Clerk (authentication) | Name, email, authentication identifiers, session data | Sign-up, sign-in, and session management for Studio | US-headquartered provider. Clerk's published data-processing terms describe the available transfer safeguards; the applicable account-level contractual basis must be confirmed |
| Stripe (payments) | Name, email, billing details, payment card data (entered directly with Stripe — we never see full card numbers), transaction history | Subscription billing, invoicing, fraud prevention | Stripe uses European and international entities and service providers. The applicable entity and safeguards depend on the customer location and Stripe's current privacy and data-processing terms |
| Daytona (sandboxes) | Project code and files executed in your sandbox, execution logs | Runs generated code in an isolated environment so you can preview and test it | Verified EU sandbox target (eu). Daytona is US-headquartered; review its current contractual safeguards before processing regulated or sensitive workloads |
| Anthropic via Vercel AI Gateway (AI model) | Your prompts and relevant project context; the model returns generated code | Producing the AI generations that Studio is built on | US-headquartered providers. Prompts are routed through Vercel AI Gateway to Anthropic; their current commercial privacy, retention, and transfer terms govern this processing |
| Resend (email delivery) | Enquiry form contents (name, email, message) and service email addressing | Delivers contact-form enquiries and service emails to our mailbox | US-headquartered provider. Resend's current privacy and data-processing terms govern any international transfer |
Points worth knowing
- We do not sell personal data, and no data goes to advertising networks.
- Prompts leave the platform. To generate code, your prompts and relevant project context are sent to the AI model provider used for that feature. Do not put secrets or other people's personal data in prompts.
- AlgoSweden does not train on your content. We do not use your prompts, projects, or generated code to train models. Production uses commercial provider APIs; provider handling is governed by the terms and account settings in force for those APIs (see the Studio Licence Terms, section 2).
- EU data residency first. Application data (Convex), sandboxes (Daytona), and our own hosting (Azure North Europe / Sweden Central) run in EU regions. Authentication, payments, AI generation, and email delivery involve US-based providers under the safeguards above.
- Transfers outside the EU/EEA: providers publish safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where a provider is certified, the EU–US Data Privacy Framework. The mechanism that actually applies depends on the provider and the account-level terms. Contact us for the current contractual position before submitting regulated or sensitive personal data.
- Subprocessor changes: we update this page before adding or replacing a subprocessor and, for business customers with a DPA, provide the notice the DPA requires.
Related documents
- Privacy Policy — lawful bases, retention, and your rights
- Cookie Policy
- Studio Licence Terms — ownership of your code and the 30-day export window
Questions: majed.tamim@algosweden.se.