Privacy Policy

How Regenmmsweepis collects, uses, and protects your personal information.

1. Introduction and Data Controller

This Privacy Policy describes how Regenmmsweepis ("we," "us," or "our") processes personal data when you visit our website at regenmmsweepis.world, use our contact form, purchase our educational products or consulting services, or otherwise interact with us. We are committed to protecting your privacy in accordance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Swedish Data Protection Act (SFS 2018:218), and other applicable data protection legislation.

The data controller responsible for your personal data is:

Regenmmsweepis
Hamngatan 18–20
111 47 Stockholm
Sweden
Email: assist@regenmmsweepis.world
Phone: +46 8 762 80 00

If you have questions about this Privacy Policy or wish to exercise your data protection rights, please contact us using the details above.

2. Scope of This Policy

This Privacy Policy applies to all personal data we process in connection with our website, workplace movement guidance services, educational products, consulting engagements, and related communications. It does not apply to third-party websites or services that may be linked from our site. We encourage you to review the privacy policies of any external sites you visit.

Our services provide general informational content about workplace movement and activity routines. We do not process special categories of personal data related to health conditions as part of our standard service delivery, unless you voluntarily provide such information in a communication with us.

3. Personal Data We Collect

3.1 Data You Provide Directly

When you contact us through our website form, email, or telephone, we may collect:

  • Your name
  • Email address
  • Telephone number (if provided)
  • Company or organization name (if provided)
  • Content of your message or inquiry
  • GDPR consent confirmation

When you purchase our educational products or consulting services, we may additionally collect:

  • Billing address
  • Payment-related information (processed by our payment service provider; we do not store full card details)
  • Invoice and purchase history
  • Service delivery preferences

3.2 Data Collected Automatically

When you visit our website, we may automatically collect certain technical information, including:

  • IP address (anonymized where possible)
  • Browser type and version
  • Operating system
  • Referring URL
  • Pages visited and time spent on each page
  • Date and time of access
  • Device type and screen resolution

This data is collected through cookies and similar technologies as described in our Cookie Policy. Non-essential cookies are only activated with your consent.

4. Purposes and Legal Bases for Processing

We process your personal data only when we have a valid legal basis under GDPR. The following table summarizes our primary processing activities:

  • Responding to inquiries: To read, evaluate, and respond to messages submitted through our contact form or email. Legal basis: Legitimate interest (Article 6(1)(f) GDPR) in communicating with prospective and existing clients, or consent where required.
  • Service delivery: To provide consulting services, educational products, and programs you have requested or purchased. Legal basis: Performance of a contract (Article 6(1)(b) GDPR).
  • Billing and accounting: To issue invoices, process payments, and maintain financial records as required by Swedish law. Legal basis: Legal obligation (Article 6(1)(c) GDPR) and performance of a contract.
  • Website functionality: To ensure our website operates correctly, securely, and efficiently. Legal basis: Legitimate interest (Article 6(1)(f) GDPR).
  • Analytics: To understand how visitors use our website and improve content and user experience. Legal basis: Consent (Article 6(1)(a) GDPR), obtained through our cookie banner.
  • Marketing communications: To send promotional information about our services where you have opted in. Legal basis: Consent (Article 6(1)(a) GDPR).

5. Data Retention Periods

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, or as required by applicable law:

  • Contact form inquiries: Up to twenty-four (24) months from the date of submission, unless an ongoing business relationship develops.
  • Client and contract data: For the duration of the service relationship plus seven (7) years thereafter, in accordance with Swedish accounting and commercial record-keeping requirements.
  • Marketing consent records: Until consent is withdrawn, plus a reasonable period to demonstrate compliance.
  • Website analytics data: Up to twenty-six (26) months, subject to anonymization where applicable.
  • Cookie consent preferences: Stored locally on your device until cleared or until consent is renewed.

When retention periods expire, we securely delete or anonymize personal data so it can no longer be associated with you.

6. Data Sharing and Recipients

We do not sell your personal data to third parties. We may share data with the following categories of recipients where necessary:

  • Service providers: Hosting providers, email delivery services, payment processors, and analytics platforms that assist us in operating our website and delivering services. These providers act as data processors under written agreements that require GDPR-compliant handling.
  • Professional advisors: Accountants, auditors, and legal counsel where disclosure is necessary for compliance or dispute resolution.
  • Public authorities: Where required by law, court order, or regulatory request.

Some service providers may be located outside the European Economic Area (EEA). Where data is transferred internationally, we ensure appropriate safeguards are in place, such as Standard Contractual Clauses approved by the European Commission or adequacy decisions.

7. Security Measures

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, disclosure, or destruction. These measures include:

  • HTTPS encryption for all website communications
  • Access controls limiting personal data access to authorized personnel
  • Regular review of security practices and vendor compliance
  • Secure storage of physical and digital records
  • Staff awareness of data protection obligations
  • Incident response procedures for suspected data breaches

While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security but commit to notifying relevant authorities and affected individuals of breaches where required by GDPR Article 34.

8. Your Rights Under GDPR

As a data subject, you have the following rights regarding your personal data:

  • Right of access (Article 15): Request confirmation of whether we process your data and obtain a copy.
  • Right to rectification (Article 16): Request correction of inaccurate or incomplete data.
  • Right to erasure (Article 17): Request deletion of your data where no compelling reason exists for continued processing.
  • Right to restriction (Article 18): Request that we limit processing in certain circumstances.
  • Right to data portability (Article 20): Receive your data in a structured, machine-readable format where processing is based on consent or contract.
  • Right to object (Article 21): Object to processing based on legitimate interests, including direct marketing.
  • Right to withdraw consent (Article 7(3)): Withdraw consent at any time without affecting the lawfulness of prior processing.

To exercise any of these rights, contact us at assist@regenmmsweepis.world. We will respond within one month, extendable by two further months for complex requests. We may request identity verification before processing your request.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se if you believe our processing violates applicable data protection law.

9. Children

Our website and services are directed at adults in professional workplace contexts. We do not knowingly collect personal data from individuals under sixteen (16) years of age. If we become aware that we have collected data from a child without appropriate consent, we will take steps to delete it promptly.

10. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices, services, or legal requirements. The "Last updated" date at the top of this page indicates when the policy was most recently revised. Material changes will be communicated through a notice on our website or, where appropriate, by direct communication to affected individuals.

We encourage you to review this page regularly to stay informed about how we protect your information.

11. Contact Information

For privacy-related inquiries, data subject requests, or concerns about our data handling practices, please contact:

Regenmmsweepis
Hamngatan 18–20, 111 47 Stockholm, Sweden
Email: assist@regenmmsweepis.world
Phone: +46 8 762 80 00