Disciplines Products Pricing About Platform Start a conversation

Privacy policy.

Plain English, no surprises. What we collect on this site and in the stomwerk apps, why we collect it, where it lives, how long we keep it, and the rights you have over it.

ControllerStomwerk, Sweden
Contactprivacy@stomwerk.com
Supervisory authorityIMY (imy.se)
Last updated21 July 2026

Who we are.

Stomwerk AB is a Swedish company (org number 559591-8755, registered in Stockholm, Sweden). We run the marketing site at stomwerk.com and the stomwerk platform - app.stomwerk.com and its satellite apps for the projekt and scale disciplines.

For the data described on this page, Stomwerk is the controller - except for the worker data and persona content our customers manage inside their own workspaces, where the customer is the controller and we act as processor (see data we process for our customers below). For anything on this page, write to privacy@stomwerk.com.

What we collect on this site.

  • Contact and newsletter forms. When you send an enquiry or subscribe to Baseline or Throughline, we receive your name, email, organisation and message. Submissions are relayed to HubSpot, hosted in the EU (Frankfurt), along with your IP address and, on submission, HubSpot's hubspotutk cookie. We use them to reply to you and to send the newsletters you asked for - nothing else.
  • Analytics, cookie-free. The site uses Plausible, a privacy-first analytics tool hosted in the EU. It sets no cookies, stores no personal data and does not track you across sites, so no consent banner is needed. We only see aggregate counts (page views, referrers, which tools are opened).
  • Server logs. The site is served by Cloudflare's edge network, which processes visitor IP addresses as part of delivering pages and protecting against abuse. Our form relay stores nothing at the edge - it passes your submission straight to HubSpot.

What we collect in the apps.

  • Account data. Your name, email and password. We store only a cryptographic hash of your password (scrypt) - never the password itself - and sign-in sessions are stored as hashes too, expiring after 30 days.
  • Workspace content. The project and marketing data you and your team enter, including file attachments. It lives in our database in Frankfurt, Germany - attachments included. stomwerk content media (uploaded logos, brand imagery, guideline documents and generated media) is stored with Cloudflare R2 in a bucket created in the EU jurisdiction, so it stays in EU data centres too; where R2 is not configured, the same media is held in EU storage in Frankfurt instead.
  • Billing. Payments run through Stripe. Your card details go directly to Stripe and never touch our systems; we keep only the subscription references and billing email needed to run your account.
  • AI features. Depending on the feature, text you submit is processed either by Anthropic (in the United States; kept at most 30 days, never used to train models) or by Amazon Bedrock, which runs the models inside AWS's own infrastructure in the European Union (it does not leave the EU; nothing is stored or used for training). Results are stored back in our EU database.
  • AI image generation. The image prompt - a scene description, not your library content - is processed by Stability models on Amazon Bedrock in the United States. Processing is transient: nothing is stored, trained on, or shared with the model provider. The image is stored back in our EU storage and labelled as AI-generated. Please do not put personal data in image descriptions; a generated photograph never needs it.
  • Transactional email. Password resets and invitations are delivered via Resend, a US provider operating under Standard Contractual Clauses. These emails carry only your address and a short-lived, single-use link.
  • Security logs. We keep short-lived IP-based rate-limiting records to protect the apps from abuse, and audit trails of actions taken inside a workspace.

Where you sign in from.

We record two small things. The approximate country of your account - a two-letter code such as SE or GB, nothing finer. We do not work it out ourselves: the platform hosting our apps tells us the country it has already inferred, so we never read or store your IP address for this. And a limited sign-in history: for each successful sign-in, the time, that same country code, and a coarse browser and operating system such as "Chrome on macOS". No full browser string, no device fingerprint, no city, no coordinates.

Why: to keep accounts secure, since a sign-in from an unexpected country is exactly the signal that something is wrong, and to understand where our users are. The basis is legitimate interest (Art 6(1)(f) GDPR) and you can object at any time. The country code lasts as long as your account; sign-in records are deleted after 12 months. Both are erased with your account and both are included in a copy of your data - see your rights.

Support and help requests.

When you raise a support ticket inside the apps, we collect the subject, category and priority you choose, the message you write, and a reference to your account so we can reply. Tickets and their messages live in our EU database in Frankfurt - the same system of record as the rest of your account. Notification emails we send you carry only the subject, your workspace and a link back to the ticket, never the content of the message. The legal basis is contract (Art 6(1)(b) GDPR): answering a request from a paying customer is part of delivering the service. We rely on legitimate interests (Art 6(1)(f)) only for ancillary uses such as defending a claim, keeping the service secure and improving the quality of our support.

If you email us instead. You can also reach us by email, at the addresses published on this site. Email is different from the in-app form in two ways we want to be straightforward about. First, the message arrives in our business mailbox, which is hosted by Google Workspace, so a copy of what you send rests there as well as in our own EU database - unlike the in-app form, where it only ever reaches our database. Second, when you reply to one of our notification emails, we attach your reply to your ticket using a signed code in the reply address, not by trusting the address your mail appears to come from, because an email sender can be forged. If a message reaches us without that code - for example the first time you ever write to us - we do not attach it to any account automatically; a person reads it and decides. We do not create an account or a ticket from an unverified email.

Please keep tickets free of sensitive detail. The form asks you not to include health data, government identity numbers, passwords or other people's personal data - a support request never needs them. To reduce the risk if something slips through, we also strip obvious high-liability identifiers - for example Swedish personnummer, payment-card numbers, IBANs and secret tokens - from customer messages before they are stored in our database. Please note that if you email us, that stripping applies to the copy in our database, and the message as you sent it still sits in our mailbox until it is deleted - which is one reason we would rather you used the in-app form for anything sensitive. Notes our operators add to a ticket for their own reference are internal and are never shown to you.

Resolved or closed tickets are deleted 24 months after they are resolved, unless a specific ticket is placed on a short, logged legal hold because it relates to a live claim or an accounting record. Your tickets are covered by the same rights as the rest of your account (see your rights): they are included automatically when you ask us to export or erase your workspace data. Where you emailed us, an erasure covers the mailbox copy as well: when a workspace or account is deleted we also remove the original emails from our mailbox, automatically.

How our team accesses the service.

To operate, support and secure the service, a small number of Stomwerk operators can reach account data through an operator-only admin console: service metrics, access management, and an audited "View as" that lets an operator open a customer workspace read-only to investigate a problem. Every "View as" session is limited to 30 minutes, can be revoked at any time, blocks all changes while it is active, and is recorded in an append-only audit trail with its start and end. This reads existing data already held under the bases above - the console collects no new personal data - and it stays in our EU database. The basis is our legitimate interest (Art 6(1)(f)) in running, supporting and securing the service, balanced by operator-only access, read-only viewing and full audit logging.

Data we process for our customers.

In two places we hold personal data that belongs to a customer's own people rather than to you as a Stomwerk user. For both, the customer is the controller and Stomwerk is the processor: we store and process it only on their instructions, under a data processing agreement, in our EU database in Frankfurt.

  • Worker data in Work Permit Intelligence (wpi.stomwerk.com). Customers running permit-to-work processes upload data about their own workers and contractors: competency cards, signatures, isolation records and safety documents such as RAMS and certificates. Access is restricted to the customer's own workspace members, the public QR permit page shows no worker names, and worker names are never included in AI prompts by design.
  • Persona content in stomwerk content (engine.stomwerk.com). A customer can configure a persona of one of their own people, with a voice profile, example posts and a private brief describing that person's positioning goals, and the engine drafts supporting social posts in that voice for review. The private brief is readable only by managers the customer explicitly grants and never appears in notification emails; participation is opt-in per person with a consent record; and every draft is reviewed by a person before anything is published. Nothing is posted automatically. Taking part is voluntary, there is no detriment for declining, and consent can be withdrawn at any time, after which the persona and its brief are deleted.

If your data appears in a customer's workspace, your employer or the site operator is the right first contact for access, correction or deletion. If you write to us instead, we will forward your request to them without undue delay.

  • Contract (Art 6(1)(b) GDPR) - running your account, workspaces, billing and transactional email, the AI features you invoke, and answering your support requests.
  • Consent (Art 6(1)(a)) - the newsletters. You can withdraw at any time using the unsubscribe link in any newsletter. Site analytics are cookie-free and collect no personal data, so they do not rely on consent.
  • Legitimate interests (Art 6(1)(f)) - answering your enquiries, operating and supporting the service (including audited operator access), keeping the services secure (rate limiting, audit trails, the approximate country and limited sign-in history described above), understanding where our users are, and preventing abuse.
  • Legal obligation (Art 6(1)(c)) - keeping billing records for as long as bookkeeping law requires.

How long we keep data.

  • Sign-in sessions expire after 30 days; reset and invitation links are single-use and short-lived.
  • AI inputs and outputs are kept by Anthropic for a maximum of 30 days; AWS Bedrock keeps none (transient processing only); transactional email content is kept by Resend for around 30 days.
  • Account and workspace data is kept for the life of your account or workspace - including the two-letter country code on your account.
  • Sign-in records (time, country, coarse browser and operating system) are deleted 12 months after the sign-in.
  • Support tickets are deleted 24 months after they are resolved or closed, unless a specific ticket is on a short, logged legal hold. Where you emailed us, the copy in our mailbox is deleted on the same 24-month clock.
  • Billing records are kept for as long as bookkeeping law requires.
  • Data we hold for customers - worker-safety records in WPI, and personas - is retained per that customer's instructions and any statutory duties that apply to them.
  • A persona and its private brief are deleted when the person withdraws consent or the customer erases them; posts already published remain that person's own public content.
  • Rate-limiting records are short-window and cleaned up automatically.
  • Newsletter and CRM records are kept until you unsubscribe or object.

Your rights.

Under the GDPR you can ask us for access to your personal data, correction, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting past processing.

To exercise any of these, email privacy@stomwerk.com. We will respond within one month.

You also have the right to complain to a supervisory authority. Ours is the Swedish Authority for Privacy Protection, IMY - imy.se - and you can equally complain to the authority in the country where you live or work.

International transfers.

Our system of record is a Postgres database in Frankfurt, Germany, our application compute runs in Frankfurt, and stomwerk content media sits in a Cloudflare R2 bucket created in the EU jurisdiction. Some of our providers process data in the United States: where they do, the transfer is covered by the EU-US Data Privacy Framework, EU Standard Contractual Clauses, or both - the mechanism per vendor is in the table below.

Two things happen outside our servers that are worth knowing: routing at the network edge (Vercel middleware, Cloudflare) runs globally as part of delivering the services, and map views in the apps fetch tiles directly from your browser, which exposes your IP address and the requested map area to the tile provider (Esri, MapTiler or OpenStreetMap).

Our subprocessors.

We use providers to host, run and support the services. In categories: database and file hosting, application compute and edge delivery, AI inference, payments, email (both outbound notifications and the mailbox that receives email you send us), CRM and newsletters, analytics, and source-code hosting.

The full register is at stomwerk.com/subprocessors - every provider by name, what it does, where it processes data, and the transfer mechanism, with a dated change log. That page is the single maintained list, and this page deliberately does not repeat it: a second copy would drift out of date, and did. Customers with a Stomwerk DPA receive at least 30 days' notice of changes by email to workspace owners.

Esri, MapTiler and OpenStreetMap serve map tiles directly to your browser as third-party content providers - they are not subprocessors of customer data.

About cookies.

  • Analytics sets none. Our analytics (Plausible) is cookie-free - it sets no cookies at all, which is why the site has no cookie banner.
  • Forms. Submitting a contact or newsletter form sets HubSpot's hubspotutk cookie, which links your submission to your enquiry history.
  • The apps. The platform apps set one essential session cookie to keep you signed in. It is not used for tracking.

This policy was last updated on 25 July 2026. Two changes: support requests sent by email are now explained, including that our mailbox provider holds a copy and how we match your replies; and the list of providers is no longer repeated on this page but maintained in one place at stomwerk.com/subprocessors. If we change this policy materially, we will note it here.