Weissr

Privacy Policy

Last updated: 29 September 2026. This policy applies to weissr.com and to the personal data we handle when you contact us, sign up for our content, or meet us at events. Personal data we process inside the Weissr platform on behalf of our customers is governed by the data processing agreement with each customer, not by this policy.

The short version

Weissr AB is the controller of the personal data described here. We collect the contact details you give us through forms and email, and technical data about how the website is used. We use it to answer you, to run our business relationship with your company, to send you marketing you have agreed to or can opt out of, and to understand and improve the website.

We do not sell your data. We share it only with the service providers who run our website, CRM, email and analytics, and with authorities when the law requires it. Some providers are based in the United States and we only transfer data there under an approved safeguard.

You can ask us at any time to see, correct or delete your data, or to stop marketing. Write to info@weissr.com. You also have the right to complain to the Swedish Authority for Privacy Protection (IMY).

Who we are

Weissr AB (company registration number 556661-2585), Masthamnsgatan 5, 413 29 Göteborg, Sweden, is the controller of the personal data described in this policy. Weissr AB owns and operates weissr.com.

For any question about your personal data or this policy, contact us at info@weissr.com or by post to the address above, marked “Privacy”. Phone: +46 31 93 47 77.

What we collect, why, and on what legal basis

We only collect personal data that you give us or that your browser sends when you use the website. We do not buy personal data from third parties and we do not build profiles of you beyond what is described under Cookies below.

PurposePersonal dataLegal basis (GDPR Art. 6)Retention
Answering enquiries and demo requests sent through forms or emailName, email, phone, company, job title, the content of your messageLegitimate interest in responding to you (Art. 6.1.f), or steps taken at your request before entering a contract (Art. 6.1.b)12 months after our last contact, unless a customer relationship follows
Managing our relationship with customer and partner companiesBusiness contact details, role, meeting notes, correspondence, contract documentsPerformance of the contract with your company (Art. 6.1.b) and our legitimate interest in managing the relationship (Art. 6.1.f)For the life of the contract plus 24 months, or longer where accounting law requires (7 years for accounting records under the Swedish Accounting Act)
Handling support requests from users of the Weissr platformName, email, company, the content of the request and the ticket historyPerformance of the contract with your company (Art. 6.1.b)3 years after the request is closed
Sending newsletters, invitations and other marketing by emailName, email, company, job title, which emails you open and which links you clickConsent (Art. 6.1.a) when you subscribe, or our legitimate interest in marketing to existing customers and to people in relevant professional roles (Art. 6.1.f). You can object or unsubscribe at any timeUntil you unsubscribe, or 24 months after your last interaction with our emails
Registering you for webinars, events and downloadable contentName, email, company, job title, dietary or accessibility needs where you provide themSteps taken at your request (Art. 6.1.b) and legitimate interest in following up after the event (Art. 6.1.f)12 months after the event, unless you have also subscribed to marketing
Recruitment, when you apply for a role through the website or by emailCV, cover letter, contact details, references, interview notesSteps taken at your request (Art. 6.1.b) and legitimate interest in evaluating candidates (Art. 6.1.f)24 months after the process closes, to defend against discrimination claims under Swedish law. Longer only with your consent
Website analytics and improvementIP address (shortened), browser and device type, pages visited, referring page, approximate location, cookie identifiersConsent given through the cookie banner (Art. 6.1.a)See the cookie table for each cookie’s lifetime
Showing you Weissr advertising on other websites (remarketing)Cookie or pixel identifiers, pages visited on weissr.comConsent given through the cookie banner (Art. 6.1.a)See the cookie table for each cookie’s lifetime
Keeping the website secure and detecting abuseIP address, request logs, timestampsLegitimate interest in security (Art. 6.1.f)Up to 12 months
Meeting legal obligations and defending legal claimsWhatever data is relevant to the obligation or claimLegal obligation (Art. 6.1.c) or legitimate interest (Art. 6.1.f)As long as the obligation or limitation period lasts

Where we rely on legitimate interest, we have assessed that our interest does not override your rights and freedoms, and you can ask for a summary of that assessment. Where we rely on consent, you can withdraw it at any time without affecting processing that has already taken place.

You are not obliged to give us your personal data. If you choose not to, we may not be able to answer your enquiry or provide the content or service you asked for.

We do not make decisions about you based solely on automated processing, and we do not use your data to train AI models.

Cookies and similar technologies

We use cookies and tracking pixels on weissr.com. A cookie is a small text file stored in your browser. A pixel is a small piece of code that reports a page view or an action to a provider.

Strictly necessary cookies are set without asking, because the website does not work without them. All other cookies and pixels are set only after you accept them in the cookie banner shown on your first visit. Declining is as easy as accepting, and you can change your choice at any time through the “Cookie settings” link in the website footer. The website works without the optional cookies.

CategoryProviderPurposeLifetimeRequires consent
Strictly necessaryWeissr (website platform), cookie consent toolKeep the site working, remember your cookie choice, protect forms against abuseSession to 12 monthsNo
AnalyticsGoogle Analytics 4Count visits, see which pages are read and where visitors come from. IP addresses are shortened before storageUp to 14 monthsYes
Marketing and CRMHubSpotRecognise returning visitors, connect form submissions to your contact record, measure email and page engagementUp to 6 monthsYes
AdvertisingLinkedIn Insight Tag, Google AdsShow Weissr ads to people who have visited our site and measure whether ads lead to visitsUp to 13 monthsYes
Embedded contentLinkedIn, YouTubeShow social buttons and video players. The provider may set its own cookies when the content loadsSet by the providerYes

The consent banner lists every individual cookie with its exact name and lifetime. The list is kept current by our consent tool and is the authoritative version if it differs from the table above.

You can also block or delete cookies in your browser settings.

Who we share your data with

We never sell or rent personal data. We share it with three kinds of recipients.

Service providers (processors) who handle data on our instructions under a data processing agreement. They may only use the data to provide their service to us.

ProviderServiceLocationTransfer safeguard
HubSpot, Inc.CRM, website forms, marketing email, marketing cookiesUSA (EU data hosting available)EU-US Data Privacy Framework certification and Standard Contractual Clauses
Google Ireland Ltd / Google LLCWebsite analytics, advertisingIreland and USAEU-US Data Privacy Framework certification
LinkedIn Ireland Unlimited CompanyAdvertising, Insight Tag, social featuresIreland and USAEU-US Data Privacy Framework certification
Microsoft Ireland Operations LtdEmail, calendar, document storage (Microsoft 365)EU, with support access from other regionsStandard Contractual Clauses and EU Data Boundary
LovableHosting of weissr.comEUEU Standard Contractual Clauses (SCCs) and adequacy decisions, where applicable
CookiebotConsent banner and cookie recordsEUEU Standard Contractual Clauses (SCCs) and/or EU adequacy decisions
ZoomEvent registration and deliveryEUEU–US Data Privacy Framework (DPF) and Standard Contractual Clauses (SCCs), where applicable

Independent third parties who set their own cookies or receive data for their own purposes when you interact with embedded content or advertising: LinkedIn, Google and any video platform we embed. Their own privacy policies apply to that processing.

Authorities and other parties when the law requires it. We disclose personal data to courts, the police or supervisory authorities when we are legally obliged to, or when it is necessary to establish, exercise or defend a legal claim. If Weissr AB is merged, acquired or sells its business, personal data may be transferred to the new owner under the same purposes and safeguards, and we will inform you before that happens.

Transfers outside the EU/EEA

Some of our providers are based in, or have support staff in, the United States. We transfer personal data there only where the provider is certified under the EU-US Data Privacy Framework, or where we have signed the European Commission’s Standard Contractual Clauses and carried out a transfer impact assessment. You can ask us for a copy of the relevant safeguard at info@weissr.com.

How long we keep your data

We keep personal data only as long as needed for the purpose it was collected for. The retention periods for each purpose are set out in the table above. When a period ends we delete the data or anonymise it so that it can no longer be linked to you.

Contact records in our CRM (HubSpot) are also subject to an accuracy rule. As soon as we learn that a record is no longer correct, for example because you have changed company, your email address no longer works or your details are otherwise out of date, we mark the record as inactive and stop using it for marketing and sales contact. Inactive records are deleted or anonymised automatically after 6 months, unless there is a specific reason to keep them, such as an ongoing customer relationship, deal history we need for the contract, or a legal requirement.

Three rules override the standard periods. Accounting records, including invoices and contracts with customer companies, are kept for seven years under the Swedish Accounting Act. Data needed for an ongoing dispute or legal claim is kept until the matter is closed. If you unsubscribe from marketing, we keep your email address on a suppression list so that we do not contact you again by mistake.

Deletion in our systems does not remove data from encrypted backups immediately. Backups are overwritten within 180 days, and records deleted in our CRM stay in its recycle bin for up to 90 days before they are permanently removed. Deleted data is not restored to active use during that time.

Your rights

Under the GDPR you have the following rights over your personal data. They are free to use, and we answer within one month. If a request is complex we may extend this by up to two further months and will tell you why.

RightWhat it means
AccessGet a copy of the personal data we hold about you and information about how we use it
RectificationHave inaccurate or incomplete data corrected
ErasureHave your data deleted when it is no longer needed, when you withdraw consent, or when you object and we have no overriding reason to keep it
RestrictionAsk us to pause processing while a dispute about accuracy or lawfulness is resolved
PortabilityReceive the data you gave us in a machine-readable format, or have it sent to another provider, where processing is based on consent or contract
ObjectionObject to processing based on legitimate interest. For direct marketing we stop immediately and without exception
Withdraw consentWithdraw any consent you have given, at any time, with effect from that point onward

To use any of these rights, email info@weissr.com or write to the postal address above. To stop marketing emails you can also use the unsubscribe link in every email we send. We may ask you to confirm your identity before acting, so that we do not disclose your data to someone else.

If you believe we handle your personal data unlawfully, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, www.imy.se. If you live in another EU/EEA country you may instead contact the supervisory authority there. We would appreciate the chance to resolve your concern first.

Security

We protect personal data with technical and organisational measures appropriate to the risk. These include encryption of data in transit (TLS) and at rest, access restricted to staff who need it for their work, multi-factor authentication on our systems, logging of access, and contractual security requirements on every processor. If a personal data breach is likely to result in a high risk to you, we will inform you and the IMY as the GDPR requires.

Children

Our website and services are aimed at businesses and professionals. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us personal data, contact us and we will delete it.

Links to other websites

Our website links to other sites, including LinkedIn and partner websites. This policy does not cover them. Read their privacy policies before you share personal data there.

Changes to this policy

We review this policy at least once a year and whenever our processing changes. The date at the top shows when it was last updated. If a change materially affects how we use your data, we will tell you in advance by email where we have your address, or by a clear notice on the website. We will not use data collected under this policy for a new, incompatible purpose without informing you and, where required, asking for your consent.

Contact

Weissr AB, Masthamnsgatan 5, 413 29 Göteborg, Sweden. Email info@weissr.com. Phone +46 31 93 47 77.