Tillbaka

Privacy Policy

Last updated: August 23, 2026

AI Company Nordic AB ("we") respects your privacy. This policy explains what we collect, why, and your rights under the EU General Data Protection Regulation (GDPR).

Data controller

Data we collect

Special categories of personal data (Art. 9 GDPR)

The optional personal section may include information about your health, sleep, stress or energy levels. Such data constitutes a special category of personal data. It is collected only where you volunteer it, on the basis of your explicit consent (Art. 9(2)(a) GDPR), and used solely to adapt how the Service paces and prioritises your work. Every such question is individually skippable.

These entries are stored separately from ordinary business data, in records readable only by your own account. They are never shared with your organisation, team members, administrators or other users, and are not used for profiling, marketing or automated decisions with legal effect. You can review, edit or delete each entry at any time under Executive Memory, and withdrawing consent by deleting the entry stops all further processing of it.

Why we process it

To operate the Service, personalize AI responses, and meet legal obligations. Legal bases: contract (Art. 6(1)(b) GDPR), legitimate interests (Art. 6(1)(f)), and legal obligation (Art. 6(1)(c)) for accounting records.

Subprocessors

ProcessorPurposeLocation
SupabaseApplication hosting, database, authenticationEU
Lovable AI GatewayRouting of AI model requestsEU
AnthropicClaude language models powering the agentsUSA
TwilioTelephony for executive calls (when enabled)USA / EU
StripeSubscription billing and payment processingUSA / EU
ResendTransactional and notification email deliveryEU / USA
GoogleWorkspace data you explicitly connectUSA / EU
MicrosoftMicrosoft 365 data you explicitly connectEU / USA

Providers you connect yourself (Google, Microsoft) only receive data when you authorize them.

Transfers outside the EU/EEA

Some processors are established in the United States — in particular Anthropic (AI models), Twilio (telephony) and Stripe (payments). Those transfers rely on the European Commission's Standard Contractual Clauses (SCC, Art. 46(2)(c) GDPR), supplemented by encryption in transit and at rest and by data minimisation before any content is sent to a model. Where a provider offers EU-region processing, we use it.

Retention

Data typeRetention period
Account data (email, name, preferences)Until you delete your account
Content you create (tasks, notes, decisions, memories)Until you delete it, or account deletion
Conversations with the agents24 months, then deleted
Call transcripts and summaries12 months, then deleted
Connected-account tokensUntil you disconnect the integration
Email send logs12 months
Security and audit logs12 months
Billing records (invoices)7 years (Swedish Bookkeeping Act)
BackupsRotated within 30 days

Your rights

Access, rectification, erasure, portability, restriction, objection. Use Account & Privacy to export or delete your data, or email privacy@myagents.se. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Known gaps

Contact

privacy@myagents.se