Privacy Policy
Effective date: 31.08.2026
How we process your personal data under the EU General Data Protection Regulation (GDPR).
1. Data Controller
Your personal data is processed by Cloud Solutions for Business Sweden AB, a company established in Sweden (Box 4004, 169 04 Solna, Stockholm, Sweden; VAT no SE559056482801), as data controller. The single contact address for all requests: info@gndlf.io.
2. Personal Data We Process
Website visitors / leads: name, company, email, phone, message, request type, and booking preferences (from the contact, quote, demo, and booking forms).
Account users: name, company, work email, password (hashed), role, and login records.
Data uploaded to the product: SAP exports may contain user IDs, usernames, and activity data — i.e. personal data of the customer's employees. For this data GNDLF acts as processor and the customer as controller.
Technical data: IP address, browser/session info, and — only with your consent — analytics cookies (see the Cookie Policy).
3. Purposes & Legal Bases
We process data to: provide and operate the Service; respond to your requests and run sales/support; manage accounts and security; meet legal obligations; improve the Service; and — with your consent — send informational/marketing messages.
Legal bases (GDPR Art. 6): performance of a contract (6(1)(b)); legal obligation (6(1)(c)); legitimate interest — service security and improvement (6(1)(f)); and, where required, explicit consent — e.g. marketing emails, analytics cookies (6(1)(a)).
4. Processing of SAP Data
We process SAP data uploaded to the product solely to produce the analysis, on your instructions. In an on-premises deployment the data never leaves your own server. In a cloud deployment it is kept in an isolated customer tenant and never shared with other customers.
Where SAP data includes personal data, we enter into a separate Data Processing Agreement (DPA) on request and share the sub-processor list.
5. Sharing & Sub-processors
We do not sell your data. To provide the Service we use a limited set of sub-processors: Brevo for email; Hostinger (website) and Hetzner (application) for hosting; and AI provider(s) for the website chat assistant. The in-product (dashboard) AI runs in an on-prem/controlled model; run data is not sent to a third-party cloud model for that purpose.
Sub-processors access only the data needed to provide the Service, under contractual confidentiality obligations.
6. Retention
We keep personal data for as long as the purpose requires and the law prescribes. Lead/contact records are kept through the sales process and applicable limitation periods; account data while the account is active; product-uploaded data for the retention window set in the contract or until you request deletion. When the period ends, data is deleted or anonymized.
7. Security
We apply reasonable technical and organizational measures: TLS in transit, hashed passwords (scrypt), role/access control, tenant isolation, and read-only SAP access. No method is 100% secure, but we will notify you of a breach as required by law.
8. Cookies
The site uses essential cookies and — only with your consent — analytics cookies (Google Analytics). See the Cookie Policy for details and preferences.
9. Your Rights
Under the GDPR you have rights of access, rectification, erasure ("right to be forgotten"), restriction, portability, objection, and to withdraw consent.
To exercise your rights, contact info@gndlf.io; we respond within the periods set by law. You also have the right to lodge a complaint with a supervisory authority (in Sweden, the data protection authority IMY).
10. International Transfers
If sub-processors use servers outside the EU/EEA, your data may be transferred internationally. For such transfers we seek the safeguards required by the GDPR (adequacy decision or standard contractual clauses — SCCs).
11. Changes & Contact
We may update this Policy; we will notify you of material changes by reasonable means. For questions and data requests: info@gndlf.io.