Privacy policy.
Plain English, no surprises. What we collect on this site and in the stomwerk apps, why we collect it, where it lives, how long we keep it, and the rights you have over it.
Who we are.
Stomwerk AB is a Swedish company (org number 559591-8755, registered in Stockholm, Sweden). We run the marketing site at stomwerk.com and the stomwerk platform - app.stomwerk.com and its satellite apps for the projekt and scale disciplines.
For the data described on this page, Stomwerk is the controller - except for the worker data our customers manage inside Work Permit Intelligence and the persona content that stomwerk content drafts for customers, where our customer is the controller and we act as processor (see worker data and persona content below). For anything on this page, write to [email protected].
What we collect on this site.
- Contact and newsletter forms. When you send an enquiry or subscribe to Baseline or Throughline, we receive your name, email, organisation and message. Submissions are relayed to HubSpot, hosted in the EU (Frankfurt), along with your IP address and, on submission, HubSpot's
hubspotutkcookie. We use them to reply to you and to send the newsletters you asked for - nothing else. - Analytics, cookie-free. The site uses Plausible, a privacy-first analytics tool hosted in the EU. It sets no cookies, stores no personal data and does not track you across sites, so no consent banner is needed. We only see aggregate counts (page views, referrers, which tools are opened).
- Server logs. The site is served by Cloudflare's edge network, which processes visitor IP addresses as part of delivering pages and protecting against abuse. Our form relay stores nothing at the edge - it passes your submission straight to HubSpot.
What we collect in the apps.
- Account data. Your name, email and password. We store only a cryptographic hash of your password (scrypt) - never the password itself - and sign-in sessions are stored as hashes too, expiring after 30 days.
- Workspace content. The project and marketing data you and your team enter, including file attachments. It lives in our database in Frankfurt, Germany - attachments included. stomwerk content media (uploaded logos, brand imagery, guideline documents and generated media) is stored with Cloudflare R2 in a bucket created in the EU jurisdiction, so it stays in EU data centres too; where R2 is not configured, the same media is held in EU storage in Frankfurt instead.
- Billing. Payments run through Stripe. Your card details go directly to Stripe and never touch our systems; we keep only the subscription references and billing email needed to run your account.
- AI features. When you use an AI feature, the text you submit is processed by one of two providers. Anthropic (the Claude API) processes in the United States under EU Standard Contractual Clauses, retains AI inputs and outputs for a maximum of 30 days and never uses them to train AI models. Amazon Web Services (Bedrock) processes stomwerk content text generation in Stockholm, Sweden - it does not leave the EU - and does not store prompts or outputs or use them for training. The results are stored back in our EU database.
- AI image generation. When you generate an image in stomwerk content, the image prompt (a scene description - not your library content) is processed by Stability image models on Amazon Web Services (Bedrock) in the United States, under the EU-US Data Privacy Framework and EU Standard Contractual Clauses. Processing is transient: AWS does not store the prompt or the image, use them for training, or share them with the model provider. The generated image is stored back in our EU storage and is labelled as AI-generated. Please do not put personal data in image descriptions - a generated photograph never needs it.
- Transactional email. Password resets and invitations are delivered via Resend, a US provider operating under Standard Contractual Clauses. These emails carry only your address and a short-lived, single-use link.
- Security logs. We keep short-lived IP-based rate-limiting records to protect the apps from abuse, and audit trails of actions taken inside a workspace.
Support and help requests.
When you raise a support ticket inside the apps, we collect the subject, category and priority you choose, the message you write, and a reference to your account so we can reply. Tickets and their messages live in our EU database in Frankfurt - the same system of record as the rest of your account - and do not leave it. Notification emails carry only the subject, your workspace and a link back to the ticket, never the content of the message. The legal basis is contract (Art 6(1)(b) GDPR): answering a request from a paying customer is part of delivering the service. We rely on legitimate interests (Art 6(1)(f)) only for ancillary uses such as defending a claim, keeping the service secure and improving the quality of our support.
Please keep tickets free of sensitive detail. The form asks you not to include health data, government identity numbers, passwords or other people's personal data - a support request never needs them. To reduce the risk if something slips through, we also strip obvious high-liability identifiers - for example Swedish personnummer, payment-card numbers, IBANs and secret tokens - from customer messages before they are stored, so the raw identifier is never kept. Notes our operators add to a ticket for their own reference are internal and are never shown to you.
Resolved or closed tickets are deleted 24 months after they are resolved, unless a specific ticket is placed on a short, logged legal hold because it relates to a live claim or an accounting record. Your tickets are covered by the same rights as the rest of your account (see your rights): they are included automatically when you ask us to export or erase your workspace data.
How our team accesses the service.
To operate, support and secure the service, a small number of Stomwerk operators can reach account data through an operator-only admin console: service metrics, access management, and an audited "View as" that lets an operator open a customer workspace read-only to investigate a problem. Every "View as" session is limited to 30 minutes, can be revoked at any time, blocks all changes while it is active, and is recorded in an append-only audit trail with its start and end. This reads existing data already held under the bases above - the console collects no new personal data - and it stays in our EU database. The basis is our legitimate interest (Art 6(1)(f)) in running, supporting and securing the service, balanced by operator-only access, read-only viewing and full audit logging.
Worker data we process for customers.
Work Permit Intelligence (wpi.stomwerk.com) lets our customers run permit-to-work processes. In doing so, customers upload data about their own workers and contractors: competency cards, signatures, isolation records and safety documents such as RAMS and certificates.
For this data the customer is the controller and Stomwerk is the processor: we store and process it only on the customer's instructions, under a data processing agreement. It is held in our EU database in Frankfurt, access is restricted to the customer's own workspace members, the public QR permit page shows no worker names, and worker names are never included in AI prompts by design.
If you are a worker whose data appears in a customer's workspace, your employer or the site operator running the permit system is the right first contact for access, correction or deletion. If you write to us instead, we will forward your request to them without undue delay.
Persona content we draft for customers.
stomwerk content (engine.stomwerk.com) includes an optional persona amplification feature. A customer can configure a persona of one of their own people - a named executive or specialist - with a voice profile, example posts, and a private brief describing that person's long-term positioning goals. When the customer approves a piece of marketing content, the engine drafts supporting social posts in that person's voice and angle, which the person or their nominated managers review, edit and publish.
For this data the customer is the controller and Stomwerk is the processor: we store and process it only on the customer's instructions, under a data processing agreement. It is held in our EU database in Frankfurt; the private brief is readable only by the managers the customer explicitly grants and is never included in notification emails; participation is opt-in for each person and a persona cannot be switched on without a consent record; and every draft is reviewed by a person before anything is published - nothing is posted automatically.
If you are an employee represented by a persona, taking part is voluntary, there is no detriment for declining, and you can withdraw your consent at any time, after which the persona and its private brief are deleted. Your employer is the right first contact for access, correction or deletion; if you write to us instead, we will forward your request to them without undue delay.
The legal bases we rely on.
- Contract (Art 6(1)(b) GDPR) - running your account, workspaces, billing and transactional email, the AI features you invoke, and answering your support requests.
- Consent (Art 6(1)(a)) - the newsletters. You can withdraw at any time using the unsubscribe link in any newsletter. Site analytics are cookie-free and collect no personal data, so they do not rely on consent.
- Legitimate interests (Art 6(1)(f)) - answering your enquiries, operating and supporting the service (including audited operator access), keeping the services secure (rate limiting, audit trails), and preventing abuse.
- Legal obligation (Art 6(1)(c)) - keeping billing records for as long as bookkeeping law requires.
How long we keep data.
- Sign-in sessions expire after 30 days; reset and invitation links are single-use and short-lived.
- AI inputs and outputs are kept by Anthropic for a maximum of 30 days; AWS Bedrock keeps none (transient processing only); transactional email content is kept by Resend for around 30 days.
- Account and workspace data is kept for the life of your account or workspace.
- Support tickets are deleted 24 months after they are resolved or closed, unless a specific ticket is on a short, logged legal hold.
- Billing records are kept for as long as bookkeeping law requires.
- Worker-safety records in WPI are retained per the customer's instructions and any statutory record-keeping duties that apply to them.
- stomwerk content personas and their private briefs are kept for the life of the persona and deleted when the person withdraws consent or the customer erases them; posts that were already published remain the person's own public content.
- Rate-limiting records are short-window and cleaned up automatically.
- Newsletter and CRM records are kept until you unsubscribe or object.
Your rights.
Under the GDPR you can ask us for access to your personal data, correction, deletion, restriction of processing, a portable copy, and you can object to processing based on legitimate interests. Where processing is based on consent, you can withdraw it at any time without affecting past processing.
To exercise any of these, email [email protected]. We will respond within one month.
You also have the right to complain to a supervisory authority. Ours is the Swedish Authority for Privacy Protection, IMY - imy.se - and you can equally complain to the authority in the country where you live or work.
International transfers.
Our system of record is a Postgres database in Frankfurt, Germany, our application compute runs in Frankfurt, and stomwerk content media sits in a Cloudflare R2 bucket created in the EU jurisdiction. Some of our providers process data in the United States: where they do, the transfer is covered by the EU-US Data Privacy Framework, EU Standard Contractual Clauses, or both - the mechanism per vendor is in the table below.
Two things happen outside our servers that are worth knowing: routing at the network edge (Vercel middleware, Cloudflare) runs globally as part of delivering the services, and map views in the apps fetch tiles directly from your browser, which exposes your IP address and the requested map area to the tile provider (Esri, MapTiler or OpenStreetMap).
Our subprocessors.
The providers that process personal data on our behalf, current as of 13 July 2026. The full register with the dated change log lives at stomwerk.com/subprocessors; customers with a Stomwerk DPA receive at least 30 days' notice of changes by email to workspace owners.
| Vendor | Role | Location | Transfer mechanism |
|---|---|---|---|
| Supabase | Database hosting (including file attachments) | EU - Frankfurt | SCCs (EU-resident infrastructure) |
| Cloudflare R2 | Object storage for stomwerk content media (uploaded logos, brand imagery, guideline PDFs, generated media) | EU - EU-jurisdiction bucket, stored and processed in EU data centres | Data Privacy Framework + SCCs |
| Supabase Storage | Fallback object store for stomwerk content media (only when R2 is not configured) | EU - Frankfurt | SCCs (as Supabase) |
| Vercel | Application hosting and compute | EU - Frankfurt; global edge routing | Data Privacy Framework + SCCs |
| Cloudflare | Marketing-site hosting and form relay | Global edge | Data Privacy Framework + SCCs |
| Anthropic | AI features (Claude API) | United States | SCCs - no training on API data, max 30-day retention |
| Amazon Web Services (Bedrock) | stomwerk content AI: text generation; image generation | Text: EU - Stockholm. Images: United States | Data Privacy Framework + SCCs - no storage of prompts or outputs, no training |
| Stripe | Payments and billing | United States (EU-regulated Irish entities) | Data Privacy Framework + SCCs |
| Resend | Transactional email | United States | SCCs |
| HubSpot | CRM, forms and newsletters | EU - EU1 (Frankfurt) | EU-hosted; Data Privacy Framework |
| GitHub | Source code (no customer personal data) | United States | Data Privacy Framework |
| Plausible Analytics | Site analytics, cookie-free (no personal data) | European Union | EU - no transfer |
Esri, MapTiler and OpenStreetMap serve map tiles directly to your browser as third-party content providers - they are not subprocessors of customer data.
About cookies.
- Analytics sets none. Our analytics (Plausible) is cookie-free - it sets no cookies at all, which is why the site has no cookie banner.
- Forms. Submitting a contact or newsletter form sets HubSpot's
hubspotutkcookie, which links your submission to your enquiry history. - The apps. The platform apps set one essential session cookie to keep you signed in. It is not used for tracking.
This policy was last updated on 13 July 2026. If we change it materially, we will note the change here.