Privacy Policy
Version: 2.0 · Last updated: 2026-08-17 · Effective from: 2026-05-01
Data controller
Verca AB is the data controller for personal data collected in connection with visits to the website, account administration and communication. For personal data that Customers create or upload in the Platform, Verca AB acts as data processor on behalf of the Customer (see our DPA).
Verca AB
Organization number: 559564-2629
Registered office: Malmö
Email: support@verca.se
What personal data we process
Verca AB processes the personal data required to provide the service. The processing covers the following categories:
| Category | Examples | Source |
|---|---|---|
| Contact details | Name, job title, email address, phone number | Customer at registration |
| Account data | Login information, role, permissions | Platform at account creation |
| Technical data | IP address, browser, device, session data | Automatic collection |
| Billing data | Organization number, billing address, payment references | Customer at contract signing |
| Customer data | Documents and files uploaded by Users | Customer during use |
We do not process special categories of personal data (Article 9 GDPR) unless this is expressly required and approved by the Customer.
Data from third parties (Article 14 GDPR). If Verca AB receives personal data about you from sources other than yourself — such as from your employer at account creation, from a partner during collaborations, or from a supplier in the Customer's supply chain — you will be informed of this without undue delay and no later than within 30 days of receipt, in accordance with Article 14 GDPR. Information is provided by email to the registered address or, if no such address exists, at first contact.
Purpose and legal basis
| Purpose | Legal basis | Description |
|---|---|---|
| Providing the service | Contract | Account, login, storage of documents and product information, classification and requirement management |
| Customer support | Legitimate interest | Troubleshooting, system maintenance, communication |
| Platform improvement | Legitimate interest | Analysis of usage patterns in aggregated form, performance optimization |
| Billing and administration | Legal obligation / Contract | Billing, accounting, contract management |
| Security and abuse prevention | Legitimate interest | Logging, incident management, access control |
Verca AB never processes personal data for purposes incompatible with the above. Personal data is not used for marketing to third parties.
Automated decision-making
The Platform contains a rule engine (Requirements Engine) that automatically identifies applicable regulations based on product data. This automation constitutes decision support — not automated decision-making with legal effect within the meaning of Article 22 GDPR. The Customer always makes the final decision.
Profiling. Verca AB does not profile individual Users' classification decisions or product data. Usage patterns are analysed only in aggregated and pseudonymised form for product improvement and performance analysis, never for marketing or sharing with third parties.
Storage period
| Data type | Storage period |
|---|---|
| Customer account data | Contract term |
| Customer data (documents, files) | Contract term + 30 days export window + 30 days deletion |
| Technical data (logs, sessions) | Maximum 12 months |
| Billing and accounting data | 7 years under Swedish accounting law |
| Audit logs | 12 months |
After termination of the Agreement, the Customer has 30 days to export data. Thereafter, Customer data is permanently deleted within an additional 30 days, in accordance with the Data Processing Agreement (DPA) § 8. Data subject to statutory requirements (e.g. Swedish accounting law) is retained in accordance with law.
Sharing with third parties
Verca AB never shares personal data for marketing purposes.
Personal data may be processed by sub-processors within the following categories:
| Category | Purpose | Location |
|---|---|---|
| Infrastructure and operations | Server hosting, data storage | EU |
| Authentication | Login and access control | EU |
| Billing | Payment processing | EU |
| Transactional messages | EU | |
| E-signing | Digital document signing | EU |
| Error tracking | Application monitoring | EU |
| Security | Rate limiting and performance monitoring | EU |
| Web analytics | Analytics on public pages (consent-based) | EU |
| AI services | AI chat, document analysis, and semantic search, only after organization activation | United States |
All processing takes place under data processing agreements in accordance with GDPR. A current list of sub-processors is available in the Data Processing Agreement (DPA).
No transfer of personal data to countries outside the EU/EEA takes place without a legal basis (e.g. EU Commission adequacy decision or standard contractual clauses).
Data security
Verca AB takes technical and organizational measures to protect personal data:
- Encryption at rest and in transit
- Role-based access control
- Tenant isolation — each organization's data is strictly separated at database level
- Complete audit log with timestamp and user
- Secure server environment within the EU
- Continuous security updates and testing
Only authorized personnel with documented need have access to personal data.
Audit log content. Logs record timestamp, user ID, IP address, type of action (creation, edit, deletion) and the resource concerned. Logs are available for the Customer's own internal reviews and may, upon official request, be provided to supervisory authorities (e.g. the Swedish Authority for Privacy Protection or the Swedish Consumer Agency). Logs are not used for marketing or sharing with third parties.
Incident management
In case of suspected personal data incident, Verca AB notifies the Customer without undue delay and no later than within 36 hours, in accordance with the Data Processing Agreement (DPA). Incidents that pose a risk to data subjects' rights and freedoms are reported to the Swedish Authority for Privacy Protection (IMY) within 72 hours in accordance with Article 33 GDPR.
Data subject rights
As a data subject, you have the right to:
- Access your personal data (Article 15)
- Request rectification of incorrect data (Article 16)
- Request erasure of data no longer needed (Article 17)
- Request restriction of processing (Article 18)
- Object to processing based on legitimate interest (Article 21)
- Request data portability in machine-readable format (Article 20)
- Lodge a complaint with the supervisory authority (Article 77) — Swedish Authority for Privacy Protection (IMY), imy.se
Requests are responded to without undue delay and no later than within 30 days.
Contact: support@verca.se
Contact and complaints
Verca AB (reg. no. 559564-2629) is the data controller for the processing described in this policy.
Verca AB
Skomakaregatan 6-8
211 34 Malmö
Sweden
Questions about personal data processing: dataskydd@verca.se
Verca AB does not currently have a designated Data Protection Officer (DPO). Inquiries and complaints concerning personal data processing are answered by Verca AB's data protection function at the email address above.
Complaints to the supervisory authority:
If you believe Verca AB is processing your personal data in violation of the GDPR, you have the right to lodge a complaint with:
Swedish Authority for Privacy Protection (IMY)
Website: imy.se
Changes
Verca AB may update this privacy policy. In case of material changes, Customers are notified at least 30 days in advance. The latest version is always published at verca.se/integritetspolicy.
Previous versions of the privacy policy are retained internally and may be provided upon request.
