Legal

Privacy Policy

Last updated: June 2026.

Translation provided for convenience. In the event of any discrepancy, the Italian version shall prevail.

1. Data controller and contacts

The controller of the processing of personal data within the meaning of Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (hereinafter, the "GDPR") is:

  • DecaRoy AB, a limited liability company under Swedish law (Aktiebolag);
  • Registration number (Org.nr): 559560-4520;
  • VAT number (VAT): SE559560452001;
  • Registered office: Hantverkaregatan 8, 231 44 Trelleborg, Skåne Län, Sweden;
  • Registered in the Swedish companies register (Bolagsverket) since 8 December 2025;
  • Telephone: +46 722 07 39 00.

The processing is carried out under the SveaHost brand and service (sveahost.com). For any matter relating to the protection of personal data and for the exercise of the rights set out in Articles 15 to 22 of the GDPR, the data subject may contact the controller at the following email address: info@sveahost.com.

2. Data Protection Officer (DPO) and privacy point of contact

The controller is not required to appoint a Data Protection Officer within the meaning of Article 37 of the GDPR, as the conditions set out therein are not met, in that the core activities do not consist of processing operations which, by virtue of their nature, scope or purposes, require regular and systematic monitoring of data subjects on a large scale, nor of large-scale processing of special categories of data under Article 9 or of data relating to criminal convictions and offences under Article 10.

A single point of contact for all matters relating to the protection of personal data is nonetheless established, reachable at the address info@sveahost.com.

3. Key definitions

For the purposes of this notice, the definitions set out in Article 4 of the GDPR apply. In particular:

  • Personal data: any information relating to an identified or identifiable natural person (the "data subject");
  • Processing: any operation performed on personal data, such as collection, recording, storage, use, disclosure or erasure;
  • Controller: the entity which determines the purposes and means of the processing, namely DecaRoy AB;
  • Processor: the entity which processes personal data on behalf of the controller (for example the suppliers indicated in Section 7);
  • Sub-processor: the entity engaged by a processor to carry out specific processing activities on behalf of the controller;
  • EEA: European Economic Area;
  • Customer: the natural or legal person who purchases the SveaHost services.

4. Categories of personal data processed and sources

In the provision of the SveaHost services, the controller processes the following categories of personal data:

4.1 Contact and account data

First and last name, email address, telephone number, business name, any pre-existing website and credentials for access to the reserved area.

4.2 Content provided by the customer for the generation of the website

Text, images, business information and any other content transmitted by the customer as part of the brief aimed at the creation of the website. Where such content includes personal data of third parties (for example the customer's collaborators, clients or contacts), the customer acts as an independent controller of the processing of such data and warrants that it has an appropriate legal basis for disclosing it to the controller; the mutual relations are governed by the data processing agreement (DPA).

4.3 Billing and payment data

Personal and tax data necessary for issuing accounting documents (company name, address, VAT number or tax code) and data relating to transactions. Payment card data is processed directly by the payment service provider Stripe and is not stored by the controller.

4.4 Technical browsing data

IP address, device and browser identifiers, log data and information collected through technical cookies, as indicated in the Cookie Policy.

4.5 Communications and support data

The content of communications with the controller (assistance requests, reports, correspondence) and related metadata.

Sources of the data. The data is collected predominantly from the data subject, upon registration, conclusion of the contract, transmission of the brief or request for assistance. Technical data is collected automatically during browsing. On a residual basis, certain data may come from publicly accessible sources (for example the customer's pre-existing website) or from the service providers referred to in Section 7.

5. Purposes of the processing and legal bases

The controller processes personal data for the purposes and on the basis of the grounds of lawfulness indicated below, pursuant to Article 6 of the GDPR.

5.1 Provision of the services and management of the contractual relationship

Creation of the website (generated with the assistance of artificial intelligence and human supervision), hosting, maintenance, SEO optimization, periodic publication of content and, where requested, registration and management of the domain; management of the account, of support and of service communications.

Legal basis: performance of the contract to which the data subject is party or the taking of pre-contractual steps at the data subject's request, Article 6(1)(b) GDPR. For customers constituted as legal persons, the same processing of the data of the relevant natural persons is based on the legitimate interest under point (f) (management of the contractual relationship with the customer).

5.2 Tax, accounting and statutory obligations

Issuance and retention of invoices and accounting documents, tax obligations and any other obligation provided for by applicable law, including the Swedish accounting law (Bokföringslagen).

Legal basis: compliance with a legal obligation to which the controller is subject, Article 6(1)(c) GDPR.

5.3 Management of payments and fraud prevention

Execution and reconciliation of payments through the provider Stripe; prevention, detection and combating of fraud and abuse.

Legal basis: performance of the contract, Article 6(1)(b) GDPR, as regards the execution of the payment; legitimate interest of the controller in the security of transactions and the prevention of fraud, Article 6(1)(f) GDPR.

5.4 Security of systems and infrastructure

Ensuring the security, integrity and availability of IT systems, hosted websites and data, by means of technical logs, protection tools and technical cookies.

Legal basis: legitimate interest of the controller in protecting network and information security, Article 6(1)(f) GDPR, read also in the light of Recital 49. Following the balancing test, such interest is not overridden by the fundamental rights and freedoms of the data subjects, as the data is limited and necessary and processed with minimization measures.

5.5 Service communications and support

Sending of transactional and service communications (confirmations, technical notifications, deadlines, renewals) and handling of support requests.

Legal basis: performance of the contract, Article 6(1)(b) GDPR.

5.6 Direct marketing to customers

Sending, where carried out, of informational and promotional communications relating to services similar to those already purchased by the customer, with the possibility of objecting at any time.

Legal basis: legitimate interest of the controller in carrying out direct marketing activities, Article 6(1)(f) GDPR (Recital 47), without prejudice to the right to object under Article 21(2). Where required by applicable law, the sending of promotional communications to non-customers takes place exclusively upon prior consent, Article 6(1)(a) GDPR.

5.7 Establishment, exercise or defence of a legal claim

Handling of litigation, complaints and disputes.

Legal basis: legitimate interest of the controller in protecting its rights, Article 6(1)(f) GDPR.

6. Nature of the provision of data

The provision of the data indicated in Sections 4.1, 4.2 and 4.3 is necessary for the conclusion and performance of the contract: any refusal entails the impossibility of providing the services. The provision of data processed for legal obligations is mandatory. The provision of data for marketing purposes based on consent is optional and any refusal does not prejudice the use of the services.

7. Recipients and processors

Personal data is processed by the controller's authorized personnel and may be disclosed to third parties acting as processors within the meaning of Article 28 of the GDPR, on the basis of specific agreements governing their obligations and safeguards. The data may also be disclosed to public authorities and judicial bodies in compliance with legal obligations. The controller does not disseminate personal data and does not transfer it to third parties for their own purposes except within the limits permitted by law.

The main suppliers acting as processors or sub-processors are indicated in the following table.

SupplierPurposeLocationSafeguard for the transfer
StripePayment processingEU / USAEU Standard Contractual Clauses (SCC)
CloudflareDNS, CDN, email routingEU / USAEU Standard Contractual Clauses (SCC)
DreamHostHosting of customers' websitesUSAEU Standard Contractual Clauses (SCC)
HetznerInfrastructure and servers (VPS)Germany (EU)Processing within the EEA
ResendSending of transactional emailsUSAEU Standard Contractual Clauses (SCC)
OpenSRS / TucowsDomain registration and managementCanada / USAEU Standard Contractual Clauses (SCC)
HighLevel (GoHighLevel)CRM and customer relationship managementUSAEU Standard Contractual Clauses (SCC)
AnthropicAI generation of website textUSAEU Standard Contractual Clauses (SCC)
ReplicateAI generation of website imagesUSAEU Standard Contractual Clauses (SCC)

The updated list of processors is available on request by writing to info@sveahost.com. The conditions for processing data on behalf of the customer are governed by the data processing agreement (DPA).

8. Transfers of data to third countries

Certain suppliers indicated in Section 7 process personal data outside the European Union and the European Economic Area. In such cases, the transfer takes place in compliance with Articles 44 to 49 of the GDPR and, in the absence of an adequacy decision of the European Commission under Article 45, is supported by appropriate safeguards under Article 46, consisting in particular of the Standard Contractual Clauses (SCC) adopted by the European Commission by Implementing Decision (EU) 2021/914, supplemented, where necessary, by additional measures of a technical, organizational and contractual nature.

The data subject may obtain information on the safeguards adopted and, where available, a copy thereof, by writing to info@sveahost.com.

9. Retention periods

Personal data is retained for the time strictly necessary to achieve the purposes for which it is processed and, in any event, for the duration of the contractual relationship and for the periods provided for by law. Upon expiry of such periods, the data is erased or irreversibly anonymized.

Category of dataRetention period
Contact and account dataFor the duration of the contractual relationship; upon termination, erased or anonymized within 90 days (except for data necessary in accounting documents)
Content of the brief and of the websiteFor the duration of the contractual relationship; upon termination the website is taken offline and the content erased or anonymized within 90 days
Billing data and accounting documents7 years from the close of the financial year, pursuant to the Swedish accounting law (Bokföringslagen)
Technical and log dataAs a rule, up to 12 months, except for security needs or the detection of unlawful acts
Communications and support dataUp to 24 months from the last interaction
Data processed for marketing purposesUntil objection or withdrawal of consent and, in any event, no longer than 24 months from the last contact
Data necessary for the defence of legal claimsFor the duration of the litigation and until the expiry of the relevant limitation periods

10. Automated decision-making and use of artificial intelligence

As part of the service, the customer's website is generated with the assistance of artificial intelligence systems, on the basis of the content and the brief provided by the customer, and always with human supervision before publication. Such use of AI is aimed exclusively at producing the content and materials of the website.

The controller does not carry out solely automated decision-making, including profiling, that produces legal effects on the data subject or that similarly significantly affects them within the meaning of Article 22 of the GDPR. The AI-assisted generation of website content does not constitute a decision of such nature, as it does not produce legal effects nor significantly affect the data subject and remains subject to review and validation by human personnel.

11. Security measures

The controller adopts technical and organizational measures appropriate to ensure a level of security appropriate to the risk, pursuant to Article 32 of the GDPR, including: encryption of data in transit; access control and authentication of authorized personnel; segregation and minimization of data; backup procedures and procedures for restoring availability in the event of an incident; selection of suppliers offering sufficient guarantees in terms of security; as well as procedures for regularly testing and assessing the effectiveness of the measures adopted. In the event of a personal data breach, the controller complies with the obligations to notify the supervisory authority and, where the conditions are met, to communicate to the data subjects, pursuant to Articles 33 and 34 of the GDPR.

12. Rights of the data subject

The data subject has the right to exercise, within the limits and under the conditions provided for by Articles 15 to 22 of the GDPR, the following rights:

  • Access (Art. 15): to obtain confirmation as to the existence of processing and to access their personal data and the related information;
  • Rectification (Art. 16): to obtain the correction of inaccurate data and the completion of incomplete data;
  • Erasure (Art. 17): to obtain the erasure of data in the cases provided for (the so-called "right to be forgotten");
  • Restriction (Art. 18): to obtain the restriction of processing in the cases provided for;
  • Portability (Art. 20): to receive, in a structured, commonly used and machine-readable format, the data provided and to transmit it to another controller, where the processing is based on consent or on the contract and is carried out by automated means;
  • Objection (Art. 21): to object, on grounds relating to their particular situation, to processing based on legitimate interest, as well as to object at any time to processing for direct marketing purposes;
  • Automated decisions (Art. 22): not to be subject to decisions based solely on automated processing which produce legal effects or similarly significantly affect them;
  • Withdrawal of consent (Art. 7(3)): to withdraw at any time any consent given, without this affecting the lawfulness of processing based on the consent given before its withdrawal.

The rights may be exercised by writing to info@sveahost.com. The controller provides a response without undue delay and, in any event, within one month of receipt of the request, pursuant to Article 12(3) of the GDPR; that period may be extended by two further months where necessary, taking into account the complexity and number of the requests, with notice thereof being given to the data subject. The exercise of the rights is as a rule free of charge; the controller may charge a reasonable fee or refuse to act on the request where it is manifestly unfounded or excessive, pursuant to Article 12(5).

13. Right to lodge a complaint with a supervisory authority

Without prejudice to any other administrative or judicial remedy, a data subject who considers that the processing of their personal data infringes the GDPR has the right to lodge a complaint with a supervisory authority, pursuant to Article 77 of the GDPR.

The supervisory authority competent for the controller is the Swedish data protection authority, IMY – Integritetsskyddsmyndigheten (Box 8114, 104 20 Stockholm, Sweden; imy@imy.se). The data subject may nonetheless lodge a complaint with the supervisory authority of the Member State of their habitual residence, place of work or place of the alleged infringement: in Italy, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome; www.garanteprivacy.it).

14. Cookies

The website uses cookies and similar technologies. For detailed information on the types of cookies used, their purposes and how to manage your preferences, please refer to the Cookie Policy.

15. Minors

The SveaHost services are aimed at businesses and professionals and are not intended for minors under the age of 16. The controller does not knowingly collect personal data of minors. Should it become aware of having processed a minor's data in the absence of a valid legal basis, it will erase such data without undue delay.

16. Changes to this notice

The controller reserves the right to amend or update this notice, including as a result of regulatory or organizational changes. The updated version is published on sveahost.com with an indication of the date of the last update. In the event of substantial changes, the controller will provide adequate information to the data subjects by appropriate means. You are invited to consult this page periodically. For contractual relations, reference is also made to the Terms and to the data processing agreement (DPA).