Kvorrum

Legal

Privacy Policy for Kvorrum

Last updated: October 2026

1. Data Controller

Conjunction Sverige AB, company registration number 559477-1312, is the data controller for the processing of your personal data when you visit kvorrum.se or use our services. For questions about our data processing, please contact us at kontakt@conjunction.se or +46 730-709019.

2. What data we collect and why

Expressions of interest (kvorrum.se)

  • •Data: Name, company, email address and message.
  • •Purpose: Handling sales and business development enquiries.
  • •Legal basis: Legitimate interest (GDPR Art. 6.1 f).
  • •Stored in our own infrastructure (Google Firebase), not shared with third parties.

Support and contact form (app)

  • •Data: Name, email address, organisation, subject and message.
  • •Purpose: Handling support and service cases.
  • •Legal basis: Legitimate interest (GDPR Art. 6.1 f).
  • •Stored in our own infrastructure (Google Firebase), not shared with third parties.

Account and identity (Application)

  • •Data: Email address, display name, role, team membership and account status.
  • •Purpose: To provide the service and administer your account.
  • •Legal basis: Performance of a contract (GDPR Art. 6.1 b).

Security and login data

  • •Data: Timestamp and IP address at login, as well as information about trusted devices.
  • •Purpose: To protect against unauthorised access and ensure the integrity of the service.
  • •Legal basis: Legitimate interest (GDPR Art. 6.1 f).

Troubleshooting and error logging (app)

  • •Data: User ID, organisation, timestamp, technical error information, page in the app, app version and browser type. IP addresses are not stored.
  • •Purpose: To troubleshoot technical errors and be able to help you when you give an error code to our support.
  • •Legal basis: Legitimate interest (GDPR Art. 6.1 f).

3. Cookies and local storage

The website and the app only store information in your browser (cookies, local storage and session storage) when it is necessary for a service you have chosen to use. Under the Swedish Electronic Communications Act, no consent is required for this, which is why we do not show a cookie banner. We do not use any analytics, tracking or marketing tools (such as Google Analytics).

  • •Website: your language choice.
  • •App – sign-in and security: sign-in session (Firebase Authentication), inactivity timeout and a random device ID used for trusted devices.
  • •App – crisis preparedness: a copy of your organisation’s crisis plan (contacts and procedures) so that it displays instantly. The copy is deleted when you sign out.
  • •App – preferences: your language choice and the room and organisation you last worked in.
  • •App – abuse protection: the app uses Google reCAPTCHA Enterprise (via Firebase App Check) to verify that requests come from our app and not from automated programs. Google then receives technical information about your browser and device.

You can delete stored information at any time in your browser settings. Doing so signs you out and resets your choices.

4. Retention periods

  • •Expressions of interest: Deleted 1 year after the case is marked as closed.
  • •Support cases: Deleted 2 years after the case is marked as closed or resolved.
  • •Login IP addresses and login timestamps: Reset immediately when an account is deactivated.
  • •Error logs: Deleted automatically 90 days after the error occurred.
  • •Account data: Deleted within 30 days of the customer agreement ending, provided no statutory retention obligation applies.
  • •Accounting data: Information constituting accounting records is retained for 7 years in accordance with the Swedish Bookkeeping Act.

5. Where your data is processed

Kvorrum app data is stored in Google Cloud/Firebase using data centre regions in the Nordics/EU — primarily Stockholm and Finland. IP addresses collected for security purposes are fetched and processed exclusively within our own Firebase infrastructure without being exposed to external services. Google LLC acts as data processor for storage and compute, with Standard Contractual Clauses (SCCs) and Firebase Data Processing Terms in place.

Two services may process data outside the EU/EEA. Abuse protection in the app (Google reCAPTCHA Enterprise, see section 3) is a global service, and the technical information about the browser and device may be processed by Google, including in the USA. Such transfers rely on the European Commission's Standard Contractual Clauses (SCCs) under Google Cloud's Data Processing Addendum. Emails from the app (invitations and reminders) are sent via Resend from its EU region in Ireland. Resend is a US company and may process the recipient's email address and the message content in the USA. Such transfers rely on the EU–US Data Privacy Framework and Standard Contractual Clauses (SCCs). We do not use Resend's open or click tracking features.

ServicePurposeLocation
Firebase / Google CloudHosting, database and computeEU (Stockholm, Finland)
Google reCAPTCHA EnterpriseAbuse protection in the appGlobal, incl. USA (SCCs)
ResendEmail delivery from the appSent from the EU (Ireland), may be processed in the USA (DPF/SCCs)

6. Your rights

Under GDPR you have the following rights regarding your data:

  • •Access: The right to obtain a copy of the data we process about you.
  • •Rectification: The right to correct inaccurate data.
  • •Erasure: The right to be forgotten under certain conditions.
  • •Restriction: The right to request that processing be restricted.
  • •Objection: The right to object to processing based on legitimate interest.
  • •Data portability: The right to receive your data in a machine-readable format to transfer to another service (applies to data processed on the basis of a contract).
  • •Complaint: You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Contact us at kontakt@conjunction.se to exercise your rights. We will respond within 30 days.

7. Security

The platform supports multi-factor authentication (MFA). All data is encrypted at rest and in transit (TLS/SSL).

8. Conjunction Sverige AB as Data Processor

For data collected directly by Conjunction Sverige AB — such as expressions of interest and support cases — the company acts as data controller as described in section 2.

For content that customer organisations store in the platform (contracts, minutes, documents, etc.), Conjunction Sverige AB acts solely as a data processor, governed by a separate Data Processing Agreement (DPA) in accordance with GDPR Art. 28.

9. Changes

We may update this policy from time to time. Registered users will be notified by email in the event of material changes.