Privelos privacy notice
How Privelos processes customer, user and visitor data, both when eVäst AB is controller and when it is processor.
1. Controller and contact
eVäst AB, 556627-3719
Lingäll 230, 451 97 Uddevalla
privacy@privelos.com
Privelos is part of Praestegaard Group AB and is organised, maintained and administered by eVäst AB. eVäst AB is controller for account, contract, billing, website, support and security data. For content placed in a workspace, the customer is normally controller and eVäst AB is processor under the data processing agreement.
2. Data, purposes and legal bases
- Account and membership data: authentication, authorisation and service delivery — contract or pre-contract steps.
- Organisation, plan and billing data: customer administration, manual payment approval and invoicing — contract and legal obligations, including accounting.
- Session, login, IP and security data: abuse prevention, service protection, incident investigation and traceability — legitimate interests in a secure service and, where applicable, legal obligation.
- Contact and support data: answer enquiries and resolve problems — pre-contract steps, contract or legitimate interests in customer support.
- Customer content: processed only on the customer's documented instructions. The customer determines purposes and legal bases.
Consent is not the basis for the core service. Any future optional consent must be withdrawable.
3. Sources and required data
Data is supplied by the user or customer administrator, generated through use, or entered by the customer about other people. Required account, security and billing data is necessary for the contract; without it the service cannot be provided.
4. Recipients, processors and transfers
Authorised personnel, contracted suppliers and lawfully entitled authorities may receive data. Access follows least privilege. Suppliers must be reviewed for processor terms, security, subprocessors, location and transfer basis before production use.
Launch gate: no subprocessors are yet approved in production configuration. A complete and accurate list must be published before a supplier processes production data.
Transfers outside the EU/EEA require a documented assessment and valid GDPR Chapter V mechanism, with supplementary safeguards where needed.
5. Retention and deletion
- Expired sessions are removed at the next maintenance run; login attempts after 30 days.
- Contact enquiries are deleted after no more than 180 days unless needed for a contract or legal claim.
- Expired unused invitations are deleted after 30 days.
- Account and workspace data is normally erased or anonymised within 30 days after contract end, after verification and an export opportunity, unless law or a legal claim requires longer retention.
- Accounting records, contract evidence, security and audit data are retained only for applicable statutory, security, accountability or claims periods.
6. Rights
Depending on the circumstances you may request information, access, rectification, erasure, restriction and portability, object, and invoke rights relating to certain automated decisions. Contact privacy@privelos.com. Identity is verified and responses are normally provided within one month. For customer-controlled content we assist the customer under the processing agreement.
You may complain to IMY or another competent supervisory authority.
7. Automated decisions, security and changes
Privelos makes no solely automated decisions producing legal or similarly significant effects. Safeguards include MFA, role-based access, tenant isolation, encryption of selected secrets, logging, backups and incident procedures. No system is risk-free.
Material changes are versioned and communicated. Recording which version a new administrator read is notice acknowledgment, not consent to contract- or law-based processing.
