Legal
Privacy Policy
Last updated: August 27, 2026
Solvigo respects your privacy. This policy explains what personal data we process — when you visit solvigo.ai, when you contact us, when you apply for a job, and when you work with us as a client — why we process it, and the rights you have. It is written to be read: no legalese where plain words do.
Who is responsible
Solvigo AB (org.nr 559529-3647), Valhallavägen 140, 114 59 Stockholm, Sweden is the data controller for the processing described here.
We have appointed a Data Protection Officer. For any privacy question, request or complaint — or anything else — write to info@solvigo.ai and it reaches them directly.
When you contact us
If you use the contact form we process the details you submit — name, email, and optionally company, company size, phone number and your message — solely to respond to and follow up on your inquiry. The legal basis is taking steps at your request prior to a possible agreement (GDPR art. 6(1)(b)) and our legitimate interest in answering people who contact us (art. 6(1)(f)).
Submissions are stored in our own systems and in Google Workspace, both hosted within the EU, and are accessible only to Solvigo personnel on a need-to-know basis. We keep the correspondence only as long as the dialogue is live and delete it when it no longer serves a purpose.
When you apply for a job
If you apply for a position with us we process your application, CV, interview notes and any other information you choose to send. The legal basis is our legitimate interest in assessing candidates and taking steps prior to a possible employment contract (art. 6(1)(b) and (f)).
We keep recruitment data for two years from the date of application, so we can contact you if a suitable role opens up. Tell us at any time if you would rather we delete it sooner, and we will.
When you are a client or business contact
If you work for one of our clients, or we are in a commercial dialogue with your organisation, we process ordinary business contact details and our correspondence with you. The legal basis is performance of a contract (art. 6(1)(b)) or our legitimate interest in managing the client relationship (art. 6(1)(f)).
Contracts and related records are kept for the duration of the engagement plus ten years, under the Swedish Limitations Act. Invoices and other accounting records are kept for seven years, as the Swedish Bookkeeping Act requires.
When we process data on behalf of a client
Much of our work is building and running systems for our clients. When we do, the client decides what personal data is processed and why. They are the controller and we are the processor, acting only on their documented instructions under a data processing agreement.
If your data is processed in a system we built for your employer or another organisation, that organisation’s privacy policy governs it, not this one. Contact them directly. If you contact us instead, we will forward your request to them and assist them in answering it, but we cannot respond on their behalf.
Cookies and analytics
We use Google Analytics 4 to understand how visitors use the site — which pages are viewed, roughly where traffic comes from — so we can improve it. The legal basis is your consent (art. 6(1)(a)); analytics loads only after you accept in the consent banner. If you decline, nothing is loaded from Google and no cookies are set. The site works exactly the same either way.
Your choice is stored for 12 months, after which we ask again. You can change or withdraw it at any time — withdrawing stops collection immediately and deletes the analytics cookies:
These are all the cookies and similar storage this site can use:
| Name | Set by | Purpose | Duration | Requires consent |
|---|---|---|---|---|
| solvigo-analytics-consent | Solvigo (localStorage) | Remembers your cookie choice | 12 months | No — strictly necessary |
| solvigo-scroll:* | Solvigo (sessionStorage) | Restores your place on a page when you navigate back | Browser session | No — functional, no tracking |
| _ga | Google Analytics | Distinguishes visitors (random ID, not your identity) | 2 years | Yes |
| _ga_* | Google Analytics | Keeps session state for this site | 2 years | Yes |
The map in the footer is a static image served from our own servers (map data © OpenStreetMap contributors) — viewing it sends nothing to anyone. “Get directions” opens Google Maps in a new tab, which involves Google only if and when you click it.
We have configured Google Analytics conservatively: no advertising features, no Google Signals, no audience building, and user-level data retention set to the shortest period Google offers. Google acts as our processor for this data under the Google Ads Data Processing Terms; see Google’s privacy policy. We do not sell your data or use it for advertising.
Server logs
Separately from analytics, our web infrastructure keeps technical logs of requests to the site, including IP address, timestamp, requested page and browser user agent. This happens whether or not you accept cookies, because it is how we keep the site running and secure.
The legal basis is our legitimate interest in the availability and security of our services (art. 6(1)(f)). These logs are not used to profile you and are not combined with analytics data. They are rotated automatically after 30 days.
Who we share data with
We do not sell personal data, and we do not share it for advertising.
We do use service providers who process data on our behalf under a data processing agreement. For the processing described in this policy, these are:
| Provider | What it is used for | Where |
|---|---|---|
| Google Cloud Platform | Cloud infrastructure, compute, storage, databases | EU (Stockholm) |
| Google Workspace | Email, documents, calendar | EU |
We engage further providers in delivering services to our clients. Clients receive an up-to-date sub-processor list on request, and at least 30 days’ notice before we engage a new sub-processor or materially change how an existing one is used.
Beyond this, we share personal data only where we are legally required to.
Where data goes
We process personal data primarily within the European Economic Area.
Analytics data is processed by Google LLC in the United States. Google is certified under the EU–US Data Privacy Framework, the European Commission’s adequacy decision for transfers to certified US companies, complemented by standard contractual clauses.
How long we keep data
| What | How long |
|---|---|
| Contact form submissions and correspondence | While the dialogue is live, then deleted |
| Job applications | 2 years from application |
| Client contracts and agreements | Duration of the engagement + 10 years |
| Invoices and accounting records | 7 years (Swedish Bookkeeping Act) |
| Analytics data | 2 months (Google Analytics user-level data) |
| Server and access logs | 30 days |
| Data in systems we run for clients | Duration of the contract + 30 days, then deleted or returned |
When a retention period expires, data is deleted securely. Data held in automated backup rotations is not individually purged; those backups expire on their own schedule within 30 days.
How we protect your data
We encrypt personal data at rest (AES-256) and in transit (TLS 1.3). Access is role-based and granted on a need-to-know basis, multi-factor authentication is required for remote access, and access to production systems is logged and reviewed periodically. Backups are encrypted.
All personnel are bound by confidentiality obligations and complete data protection training.
Automated decision-making
We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.
Our AI systems are built as decision-support tools. Their output is a recommendation, and a person reviews it before anything is acted on. If that ever changes, we will update this page before it does — including your right to obtain human intervention, express your point of view and contest the decision.
Your rights
Under the GDPR you can ask us to give you access to your personal data, correct it, delete it, restrict how we process it, or provide it in a portable format. You can object to processing based on legitimate interest, and withdraw any consent at any time — through the cookie settings above, or by emailing us.
Write to info@solvigo.ai. We respond within 30 days. If your request is complex or extensive we may need up to a further 60 days, and we will tell you why within the first 30.
We may need to verify your identity before acting, to make sure we do not disclose your data to someone else. If we have to refuse part of a request — for instance where the Bookkeeping Act requires us to keep a record — we will tell you which part and why.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.
If something goes wrong
We maintain an incident response plan. If a personal data breach occurs and it is likely to result in a risk to individuals, we notify the Swedish supervisory authority within 72 hours as required under art. 33, and we notify affected individuals directly where the risk is high (art. 34). Clients are notified without undue delay, within whatever timeframe their agreement with us specifies.
Changes
If we change what we collect or why, we update this page and — where the change affects cookies — ask for your consent again. The date at the top always reflects the latest version.
