This policy explains how Darlana (“we”) processes personal data under the General Data Protection Regulation (EU) 2016/679 (GDPR) and the supplementary Swedish Data Protection Act (lag 2018:218).
1. Controller
| Item | Details |
|---|---|
| Controller | Bonita Daniella Tóth |
| Registration number (organisationsnummer) | 0002081867 |
| Address | Smedmästarebyn 3A 1603 lgh, 218 41 Bunkeflostrand, Sweden |
| Email (data protection matters) | hello@darlana.co |
| Data protection officer | Not required and therefore not appointed |
2. What we process, why, and on what legal basis
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Responding to contact form enquiries and issuing proposals | Name, email, phone, company name, website, service of interest, message content, timestamp | Art. 6(1)(b) GDPR — steps prior to entering a contract; and Art. 6(1)(f) — legitimate interest in handling business enquiries | If no contract results: 12 months from last contact |
| Email and other business correspondence | Name, email address, signature block details, correspondence content | Art. 6(1)(b) and (f) GDPR | 2 years from the end of the client relationship |
| Performing the service agreement (audit, mentoring, consultancy, ad management) | Contact details, access permissions, data held in advertising accounts, project documentation, correspondence | Art. 6(1)(b) GDPR — performance of a contract | 10 years from the end of the agreement (Swedish limitation periods) |
| Invoicing and accounting | Name, company name, billing address, VAT number, invoice details, payment data | Art. 6(1)(c) GDPR — legal obligation (Swedish Bookkeeping Act, bokföringslagen 1999:1078) | 7 years from the end of the financial year |
| Website operation and security (server logs) | IP address, browser and device data, request timestamp, referring page | Art. 6(1)(f) GDPR — legitimate interest in secure operation and abuse prevention | 30 days |
| Website analytics (Google Analytics 4) | Pseudonymous identifier, approximate location, device and browser data, pages viewed and events | Art. 6(1)(a) GDPR — consent (cookie banner) | 14 months, or until consent is withdrawn |
| Measuring on-site visitor behaviour to improve the user experience | Session identifier, active time, scroll data, clicks | Art. 6(1)(a) GDPR — consent (cookie banner) | 12 months, or until consent is withdrawn |
| Advertising measurement and remarketing (Google Ads) | Cookie identifiers, click and conversion data | Art. 6(1)(a) GDPR — consent (cookie banner) | Up to 24 months, or until consent is withdrawn |
| Booking consultancy and mentoring appointments | Name, email address, time zone, appointment time, answers given on the booking form | Art. 6(1)(b) GDPR — steps prior to entering a contract | 24 months, or until the calendar entry is deleted |
3. Source of the data
We obtain personal data primarily directly from the data subject (contact form, email, phone or video calls, contracting). Some data is generated automatically when you use the website (server logs, cookies). We may also collect business contact details from public sources such as company registers or a company's own website for the purpose of targeted business outreach, on the basis of legitimate interest.
4. Recipients and processors
We do not sell personal data and do not share it with third parties for their own marketing. The following providers may access data on our behalf under data processing agreements:
| Provider | Role | Location |
|---|---|---|
| Google Ireland Limited | Google Workspace (email), Google Analytics 4, Google Tag Manager, Google Ads | Ireland (EU); parent company in the USA |
| Hetzner Online GmbH | Server hosting, storage of the website and submitted form data | Germany (EU) |
| Spiris (Visma Group) | Invoicing and bookkeeping software, storage of billing data | Sweden (EU) |
| VB Redovisning & Rådgivning | Bookkeeping within the Spiris system | Sweden (EU) |
| Calendly, LLC | Online appointment booking, processing of the booker's data | United States |
We may also disclose data to public authorities where required by law, and to our legal advisers for the establishment, exercise or defence of legal claims.
5. Transfers outside the European Economic Area
We aim to keep processing within the EEA. Some of our providers (in particular Google and Calendly) may nevertheless transfer data to the United States. Such transfers rely on the European Commission's adequacy decision for the EU–US Data Privacy Framework, or on the Commission's Standard Contractual Clauses together with supplementary safeguards. We will provide details of the safeguards applied on request.
6. Automated decision-making
We do not carry out automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
7. Security
We apply appropriate technical and organisational measures, including encrypted transmission (HTTPS/TLS), two-factor authentication on critical accounts, use of a password manager, access restricted to what is necessary, regular backups and prompt software updates. In the event of a personal data breach we will notify the Swedish supervisory authority without undue delay and within 72 hours, and will inform affected individuals where the breach poses a high risk.
8. Your rights
Under the GDPR you have the following rights:
- Access — to be told whether we process personal data about you and to receive a copy.
- Rectification — to have inaccurate data corrected and incomplete data completed.
- Erasure — to have your data deleted where there is no longer a lawful basis for processing. This right is limited where we must retain data under law, for example accounting rules.
- Restriction — in certain circumstances, to require that we store but not otherwise use your data.
- Portability — to receive data you provided, processed on the basis of consent or contract, in a machine-readable format.
- Objection — to object to processing based on legitimate interest; where the processing is for direct marketing, your objection applies unconditionally.
- Withdrawal of consent — where processing is based on consent (for example analytics and advertising cookies), you may withdraw it at any time with effect for the future.
Requests can be sent to hello@darlana.co. We respond without undue delay and within one month. Handling a request is free of charge; for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse to act.
9. Complaints
If you believe our processing infringes your rights, you may lodge a complaint with the Swedish supervisory authority:
imy@imy.se | www.imy.se
You may also lodge a complaint with the supervisory authority in the EU Member State of your habitual residence or place of work, which will forward it to the competent lead authority. You are also entitled to seek a judicial remedy.
10. Changes to this policy
We may update this policy from time to time. The current version is always available on our website together with its effective date. Ongoing clients will be notified separately of material changes.