Privacy policy
What we collect when you use this site or write to us, why we are allowed to, how long we keep it, and what you can ask us to do about it.
Who is responsible
Noemo Sverige is the controller of the personal data described in this policy. That means we decide why it is collected and what happens to it. The business is in the process of being registered in Sweden; its organisation number and VAT number are in process and will be published here once issued.
Postal address: Hovslagargatan 29, 194 31 Upplands Väsby, Sweden. For anything in this document, write to doc@noemo.se.
What we collect
Three things, and nothing else.
What you send us
If you start a project through a form on this site, we receive what you type into it: a description of the work, the options you picked, a budget range, a timeline, your name, your email address and, where you give one, a company name. Sent with it are the page the form was opened from, your IP address and the approximate country it resolves to, and the browser and device your software reports. If you write to us by email instead, we receive whatever your message contains.
What the site records
Our hosting provider keeps standard server logs of requests to noemo.se: the address the request came from, the page asked for, the time, and the software that asked. Every web server does this, and it is how one is operated and defended. We do not use it to build a profile of you.
What we store on your device
One cookie by default, which remembers the answer you gave the cookie bar. If you allow analytics, the counter described in cookie policy sets its own — and nothing is set before you have said yes. cookie policy is the full account.
What we do not do
- We do not buy contact lists, and we will not have got your address from one.
- We do not sell or trade personal data.
- We do not advertise on this site, and nothing here measures an advertisement.
- We do not profile you, and we make no decision about you by automated means alone.
- We do not ask for special categories of data — health, beliefs, union membership and the rest of Article 9. Please do not send them to us in a brief.
Why we use it
Every use has a purpose and a legal basis under Article 6 of the GDPR. These are ours.
| Purpose | What is used | Legal basis |
|---|---|---|
| Answering an enquiry and preparing a proposal | What you sent us | Steps taken at your request before a contract, Art. 6(1)(b). Where you write on behalf of a company, our legitimate interest in replying to a business enquiry, Art. 6(1)(f) |
| Running a project we have been engaged for | Contact details and project material | Performance of the contract, Art. 6(1)(b) |
| Keeping the site available and defending it against abuse | Server logs, and the technical details sent with an enquiry | Our legitimate interest in a site that works and is not misused, Art. 6(1)(f) |
| Remembering your cookie answer | The consent cookie | Storage necessary for a service you asked for, ch. 9 § 28 of the Electronic Communications Act (2022:482) |
| Understanding how the site is used | Analytics cookies and what the counter records about your visit | Your consent, Art. 6(1)(a) — given in the cookie bar and withdrawable there at any time |
| Invoicing and bookkeeping | Billing details | Legal obligation, Art. 6(1)(c), under the Bookkeeping Act (1999:1078) |
Where we rely on legitimate interest we have weighed it against your own interests, and you can object to it — see your rights below.
Where it is processed
The site itself is served from Stockholm and our correspondence is held in Sweden, so the processing described above stays inside the EU/EEA unless you are told otherwise here.
Two things leave it. An enquiry sent through a form is delivered to us through a messaging service that processes it outside the EEA. And if you allow analytics, the counter is Yandex Metrica, which processes what it records in Russia.
Russia has no adequacy decision from the European Commission, which means the protection there is not equivalent to the protection you have in the EEA, and a public authority could reach data held in it. That is why analytics is never switched on for you until you have said yes: your consent is what permits the transfer, you are giving it having been told the risk, and withdrawing it in the cookie bar stops any further transfer. The enquiry route is described in cookie policy and in the terms Yandex publishes at yandex.com/legal/metrica_termsofuse.
Ask us and we will tell you where a particular piece of your data sits and what covers it.
How long we keep it
We keep things for as long as the reason we collected them lasts, and then we delete them — not longer because they might one day be useful.
| What | How long |
|---|---|
| An enquiry that did not become a project | 12 months from our last exchange, then deleted |
| The notification carrying an enquiry in the messaging service | 6 months, then deleted |
| Records of a project we ran | The engagement, plus three years, for reference and for any claim arising from the work |
| Invoices and accounting material | Seven years, because the Bookkeeping Act requires it |
| Server logs | The short technical period our hosting provider keeps them for |
| What the analytics counter records | Held by Yandex under their own retention, not ours. The cookies it sets expire on your device as listed in cookie policy |
| The cookie consent cookie | 12 months, then we ask again |
Your rights
The GDPR gives you these, and they cost nothing to use.
- Access — a copy of the personal data we hold about you, and an account of what we do with it.
- Rectification — anything wrong about you put right.
- Erasure — your data deleted, where we have no remaining basis to keep it. Accounting records are the usual exception, because the law obliges us to hold them.
- Restriction — processing paused while a dispute about it is settled.
- Portability — what you gave us, back in a machine-readable form, where we hold it on consent or on a contract.
- Objection — to any processing we base on legitimate interest. We stop unless we can show compelling grounds that override yours.
- Withdrawing consent — at any time, for anything you consented to. It does not unpick what was lawful before you withdrew it.
Write to doc@noemo.se and we will answer within one month. Where a request is unusually complex we may need longer, and we will tell you so within that first month rather than after it. We may need to confirm who you are before handing over data about you.
You also have the right to lodge a complaint with a data protection supervisory authority. In Sweden that is Integritetsskyddsmyndigheten.
How it is kept
Traffic to this site runs over an encrypted connection, and access to enquiries and project material is limited to the people who need it for the work.
If a personal data breach occurs and it is likely to result in a risk to your rights, we report it to the supervisory authority within 72 hours of becoming aware of it, and we tell you directly where the risk to you is high.
Changes to this policy
This policy changes when what we do changes — a new tool, a new kind of data, a new reason. The date at the top of this page is always the date of the version you are reading.
Where a change materially affects you, we will say so on the site rather than leave you to notice the date.
Contact
Questions and requests about this policy go to doc@noemo.se, or by post to Noemo Sverige, Hovslagargatan 29, 194 31 Upplands Väsby, Sweden.
Something here unclear? Write to hej@noemo.se and a person will answer.