Privacy Policy
Effective date: 15 July 2026 Last updated: 15 July 2026
This policy explains how AlgoSweden collects and uses personal data when you visit algosweden.se or use AlgoSweden Studio at app.algosweden.se. It is written to comply with the EU General Data Protection Regulation (GDPR) and supplementary Swedish data protection law (dataskyddslagen). It is provided in English and Swedish; if the versions differ, the English version prevails to the extent permitted by mandatory law.
1. Who is responsible (data controller)
The controller of the personal data described in this policy is Majed Tamim, the private individual who operates the service under the trading name AlgoSweden (see the Terms of Service, section 1).
- Controller: Majed Tamim, trading as AlgoSweden
- Location: Stockholm, Sweden
- Contact for all privacy matters: majed.tamim@algosweden.se
No data protection officer has been appointed; one is not required at our current scale. This will be reassessed as the business grows.
2. What this policy covers
- The public website at algosweden.se
- The AlgoSweden Studio application at app.algosweden.se
- Email and support communication with us
It does not cover third-party sites we link to, or the applications our customers build and operate with Studio (for those, the customer is responsible for their own users' data).
3. Data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Name, email address, authentication identifiers, profile settings | You, via our authentication provider (Clerk) |
| Billing data | Subscription plan, invoices, payment status. Card details are collected and stored by Stripe, not by us | You / Stripe |
| Content data | Prompts you submit, project files, and code generated in Studio | You / the service |
| Usage telemetry | Feature usage, generation counts, error logs, approximate device and browser information, IP address in server logs | Automatically |
| Enquiries | The details you submit through the contact form (type of enquiry, name, email, message) | You |
| Communications | Support emails and messages you send us | You |
We do not intentionally collect special categories of personal data (e.g. health, political opinions). Please do not include such data in prompts.
4. Why we process it and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing your account and running Studio (including processing prompts and generating code) | 6(1)(b) — performance of a contract |
| Billing and subscription management | 6(1)(b) — contract; 6(1)(c) — legal obligation (bookkeeping) |
| Responding to enquiries you send through the contact form or by email | 6(1)(b) — steps at your request; 6(1)(f) — legitimate interest |
| Security, abuse prevention, and enforcement of our Acceptable Use Policy | 6(1)(f) — legitimate interest in keeping the service safe |
| Service analytics and product improvement using usage telemetry | 6(1)(f) — legitimate interest in improving the service |
| Complying with accounting, tax, and other legal duties | 6(1)(c) — legal obligation |
| Optional communications such as product news (if we introduce them) | 6(1)(a) — consent, which you can withdraw at any time |
Where we rely on legitimate interest, you can object (see section 9). We do not use your prompts, projects, or generated code to train AI models (see the Studio Licence Terms, section 2).
5. Processors and other recipients
We use a small number of service providers (processors) to run the service:
| Provider | Role |
|---|---|
| Microsoft Azure | Hosting for the website, Studio, and the generation runtime (EU regions) |
| Convex | Application database and backend infrastructure (EU deployment) |
| Clerk | Authentication and account management |
| Stripe | Payment processing and invoicing |
| Daytona | Isolated sandbox environments for running generated code (EU region) |
| Anthropic, routed via Vercel AI Gateway | Processing prompts and producing generated code |
| Resend | Delivery of enquiry and service emails |
A plain-language overview of what data goes to which provider is published in our Data Processing Overview. We do not sell personal data and we do not share it with advertisers.
We may also disclose data where the law requires it (e.g. to authorities on a valid legal order).
6. International transfers
We prefer EU/EEA data residency where our providers offer it: the application database (Convex) runs in an EU deployment, code sandboxes (Daytona) run in the EU region, and our own hosting runs in Microsoft Azure's EU regions (North Europe, with registry, logs, and identities in Sweden Central).
Some of our providers are established in the United States or process data there (including authentication, payments, AI generation, and email delivery). Their published safeguards may include:
- an adequacy decision of the European Commission (including the EU–US Data Privacy Framework for providers certified under it), and/or
- the European Commission's Standard Contractual Clauses (SCCs), together with supplementary measures where needed.
The mechanism that applies depends on the provider and the account-level contract. The Data Processing Overview records verified regions and the current contractual status. Contact majed.tamim@algosweden.se before submitting regulated or sensitive personal data if you need a specific transfer mechanism or copy of contractual safeguards.
7. Retention
| Data | How long |
|---|---|
| Account data | For as long as your account exists, then deleted or anonymised within 90 days |
| Content data (prompts, projects, generated code) | For as long as your account exists; export is available for 30 days after termination (see the Studio Licence Terms), after which it is deleted |
| Billing records | 7 years after the end of the relevant financial year, as required by the Swedish Bookkeeping Act (bokföringslagen) |
| Server and security logs | Up to 90 days, unless a specific incident requires longer preservation |
| Enquiries and support correspondence | Up to 24 months after the matter is closed, so we can follow up on related questions |
| Enquiry rate-limit fingerprints | Expired buckets are removed hourly; only an HMAC fingerprint of the email address is stored, never the address itself (see Rate Limits) |
8. Security
We use industry-standard measures including encryption in transit, access controls, isolated sandbox execution, and the security programmes of the providers listed above. Generated code runs only in isolated sandboxes, never on trusted infrastructure. No system is perfectly secure; if a personal data breach occurs that risks your rights, we will notify the supervisory authority and, where required, you, in line with GDPR Articles 33–34.
9. Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you (Art. 15)
- Rectify inaccurate data (Art. 16)
- Erase your data in certain circumstances (Art. 17)
- Restrict processing in certain circumstances (Art. 18)
- Data portability — receive data you provided in a machine-readable format (Art. 20)
- Object to processing based on legitimate interest, and to any direct marketing (Art. 21)
- Withdraw consent at any time, where processing is based on consent
To exercise a right, contact majed.tamim@algosweden.se. We respond within one month, extendable as the GDPR permits for complex requests. Studio also includes a built-in account data export.
We do not make automated decisions about you that produce legal or similarly significant effects.
10. Complaints
You can lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY) — the Swedish Authority for Privacy Protection, www.imy.se. You can also complain to the supervisory authority in the EU/EEA country where you live or work.
We would appreciate the chance to resolve your concern first, but you are not required to contact us before contacting IMY.
11. Cookies
We take a minimal-cookie approach: strictly necessary cookies only, no advertising trackers, and no cookies at all on the public website. Details are in our Cookie Policy.
12. Children
The service is not directed at children under 16, and we do not knowingly collect their data. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the service evolves. Material changes will be announced on the website or by email before they take effect. The current version is always available at algosweden.se.