Skip to content
Legal

Privacy Policy

How we process personal data as a controller.

LAST UPDATED: 2026-08-05 · Version 1

1. Who we are

This Privacy Policy explains how Henrik Hellbe, Enskild firma, org.nr 950809-XXXX, Sandelsgatan 14, 115 34 Stockholm, Sweden, trading as SVARA (https://svara.social) (“SVARA”, “we”, “us”), processes personal data. SVARA is the data controller for the processing described in this policy.

For any privacy question or to exercise your rights, contact us via our contact page.

2. Scope — controller and processor roles

SVARA processes personal data in two distinct roles. It is important to understand which role applies:

  • As a controller — for the personal data of our business customers and their users (account, contact, usage and billing data), for the credentials our customers connect, and for visitors to our website. This Privacy Policy governs that processing.
  • As a processor — for the content of messages exchanged between our business customer and its own end-customers (the messages the Service drafts replies to). For that content, the business customer is the controller and SVARA is the processor. That processing is governed by the Data Processing Agreement (DPA), not by this Privacy Policy. If you are an end-customer of one of our business customers, please contact that business to exercise your rights.

3. What personal data we process

Data categoryNotesOur role
Business name, contact email, account & usage dataCollected at signup and during use of the ServiceController
Payment / billing dataProcessed via Stripe; SVARA never receives full card numbersController
Connected-account credentials / tokensMetricool brand connection; Gmail address + app password + Google OAuth gmail.send token; Slack bot token. Stored encrypted, scoped per instanceController (custodian)
Message content (DMs, comments, emails)Processed to generate drafts and automatically purged within 30 days; drafts kept only while awaiting approval; not used to train AI models; not kept as a long-term archiveProcessor (Customer is controller)
Brand knowledge (tone, uploaded docs, links)Uploaded / provided by the CustomerProcessor / Controller

We do not intentionally collect special categories of personal data (Article 9 GDPR) about our business customers as part of the account relationship.

4. Purposes and legal bases (Article 6 GDPR)

We process personal data (in our controller capacity) for the following purposes and on the following legal bases:

PurposeLegal basis
Provide, operate, maintain and support the Service; manage the account and SubscriptionPerformance of a contract — Art. 6(1)(b)
Process payments, issue invoices, and keep accounting recordsLegal obligation — Art. 6(1)(c) (incl. bokföringslagen); and Art. 6(1)(b)
Secure the Service, prevent fraud and abuse, and improve and develop the ServiceLegitimate interests — Art. 6(1)(f)
Communicate about the Service and manage the business relationshipLegitimate interests — Art. 6(1)(f); or Art. 6(1)(b)
Send marketing communicationsConsent — Art. 6(1)(a) (or legitimate interests / soft opt-in for existing customers under marknadsföringslagen (2008:486))
Comply with law and establish, exercise or defend legal claimsLegal obligation — Art. 6(1)(c); and legitimate interests — Art. 6(1)(f)

Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing (see Section 11).

5. Connected-account credentials

To operate the Service, we store the connection details the Customer provides for its Connected Accounts — the Metricool brand connection; the Gmail address, app password and Google OAuth gmail.send token; and the Slack bot token. These are stored encrypted and scoped per instance, and are used only as a custodian, solely to operate the Service on the Customer’s behalf. We do not use them for any other purpose. Each customer runs in an isolated instance with its own compute, storage and encryption key; credentials and tokens are held within that instance environment (encrypted) and are never stored in SVARA’s central database.

6. Google API Services and Limited Use

SVARA requests only the gmail.send scope from Google. This scope is used only to send replies that the Customer has approved, from the Customer’s own email address. The gmail.send scope is send-only and cannot read mail. SVARA does not read, modify or delete mail through a Google API scope; incoming email is read via the Customer’s own IMAP app password, not through a Google API. Incoming mail is read over IMAP in read-only mode — SVARA cannot modify, move or delete mail — and can be scoped to a dedicated support folder/label so that unrelated mail is never accessed.

SVARA’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7. AI processing (Anthropic)

Draft Replies are generated using Anthropic’s Claude API. The relevant message and Brand Knowledge content is sent to Anthropic solely to produce the draft. This content is not used to train models and is processed transiently. Anthropic acts as our subprocessor under the DPA where end-customer message content is involved.

8. Recipients and subprocessors

We share personal data with the following categories of recipients / subprocessors, who process it on our behalf or as independent controllers where required:

SubprocessorPurposeLocation / transfer basis
StripePayment processingUS / EU — SCCs / adequacy (EU-US DPF where applicable)
AnthropicAI draft generation (Claude API)US — SCCs
Metricool (Metricool Software, S.L., Spain)Access to social inbox (Instagram / Facebook DMs & comments)EU / EEA — stored & processed within the EU/EEA; no third-country transfer
Slack (Salesforce)Approval / review interfaceUS — SCCs
RailwayHosting / infrastructureUS — SCCs
GoogleSending approved email replies (gmail.send)US — SCCs / adequacy

We may also disclose personal data to professional advisers, and to authorities or courts where required by law or to protect our rights.

9. International transfers

Some of our subprocessors are located outside the EU/EEA (including in the United States). Where personal data is transferred outside the EU/EEA, we rely on appropriate safeguards, principally the EU Standard Contractual Clauses (SCCs), and on adequacy decisions where applicable (for example the EU-US Data Privacy Framework where the recipient is certified). You may request further information or a copy of the relevant safeguards by contacting us.

10. Retention

  • Account and usage data — for the duration of the customer relationship and for 24 months thereafter, unless a longer period is required or permitted by law.
  • Accounting and billing records — retained for seven (7) years as required by the Swedish Bookkeeping Act (bokföringslagen (1999:1078)).
  • Message content processed on behalf of a customer — used to generate drafts and automatically purged within 30 days; drafts are retained only while awaiting approval. Not retained as a long-term archive and not used to train AI models (see the DPA).
  • Connected-account credentials — retained until the account is disconnected or the Subscription ends, after which they are deleted.
  • On termination — the customer's isolated instance and its unique encryption key are destroyed, rendering any residual data cryptographically unrecoverable (crypto-erasure).

11. Your rights under the GDPR

Subject to the conditions and exceptions in the GDPR, you have the right to: access your personal data; have inaccurate data rectified; have data erased; restrict or object to processing; data portability; and withdraw consent at any time (without affecting prior processing). Where we rely on legitimate interests or process data for direct marketing, you may object.

To exercise these rights, contact us via our contact page. We will respond within the statutory time limits. Please note that where SVARA acts only as a processor (end-customer message content), you should direct your request to the relevant business customer, which is the controller.

12. Complaints

If you have a concern about how we process your personal data, please contact us first. You also have the right to lodge a complaint with the Swedish supervisory authority, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, “IMY”), imy.se.

13. Security

We implement appropriate technical and organisational measures to protect personal data (Article 32 GDPR), including:

  • Encryption at rest of all message content (drafts and conversation history) and the internal audit log, using authenticated symmetric encryption (AES-based, via Fernet), with a unique encryption key per customer instance.
  • Encryption keys held only within the isolated instance environment and never stored in SVARA's central database.
  • Encryption in transit (TLS) for all connections.
  • Per-customer isolation — each customer runs in a separate instance with its own compute, storage, credentials and encryption key.
  • Least-privilege email access — send-only gmail.send scope, and read-only IMAP that can be scoped to a dedicated support folder/label.
  • Data minimisation — message content automatically purged within 30 days; internal identifiers minimised.
  • Secure erasure (crypto-erasure) — the instance and its encryption key are destroyed on termination, rendering residual data cryptographically unrecoverable.
  • Human-in-the-loop by default — no reply is sent without the Customer's approval, except where the Customer explicitly enables the optional automated-message feature (off by default).

No system is completely secure; we cannot guarantee absolute security.

14. Cookies

Our website and application use cookies and similar technologies. For details, see our Cookie Policy.

15. Changes to this Policy

We may update this Privacy Policy from time to time. We will post the updated version with a new “Last updated” date and, where the change is material, provide additional notice.

16. Contact

Henrik Hellbe (SVARA) — Sandelsgatan 14, 115 34 Stockholm, Sweden. Reach us through our contact page.