Policy Overview
Encuro processes only the minimum personal data needed to operate the service and meet legal obligations. We do not use tracking cookies, analytics, advertising tools, or third-party trackers. The only cookie used is an essential session cookie that keeps you logged in while administering your account.
Who We Are (Data Controller)
Encuro AB
Company number: 559546-2960
Address:
Encuro AB
Kivra: 559546-2960
Stockholm
SE
Email: info@encuro.se
What Data We Process
- Account data: account name, email address, remaining time, and hashed password.
- Support communications: your email messages if you contact support.
- Payment data: payment records handled by our payment processor (Stripe).
- Service operation data: emails stored on our mail server as part of normal service operation.
Purposes and Legal Bases
- Provide and maintain the service (create and manage your account, authenticate users, operate the mail service) — Contractual necessity (GDPR Art. 6(1)(b)).
- Process payments and keep accounts — Legal obligation (Art. 6(1)(c)) and contractual necessity (Art. 6(1)(b)).
- Support and customer service (respond to your requests) — Legitimate interest (Art. 6(1)(f)).
- Security and abuse prevention (protect accounts and systems) — Legitimate interest (Art. 6(1)(f)).
Data Retention
- Account data: kept for the duration of your account and deleted within [3 months] after closure.
- Payment records: retained by Stripe as required by accounting and tax laws (typically up to 7 years).
- Support emails: deleted within approximately 3 months.
- Emails stored by the service: retained until you delete them or your account is closed, subject to legal obligations and system backups.
Sharing and Processors
We do not sell or share your personal data with third parties for their own marketing purposes. We use carefully selected service providers (processors) to operate our service:
- Stripe for payment processing.
These providers process data on our instructions and under appropriate data protection terms.
International Transfers
Some processors (such as Stripe) may transfer personal data outside the EU/EEA. Where this occurs, we rely on appropriate safeguards, including the European Commission’s Standard Contractual Clauses and supplementary measures as needed.
Your Rights
You have the following rights under the GDPR:
- Access your personal data
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict processing
- Data portability
- Object to processing based on legitimate interests
To exercise your rights, contact us at info@encuro.se. When you request deletion, we will delete or anonymize the data we control, except where we must retain certain records to comply with legal obligations (e.g., accounting or tax requirements).
Right to Complain
You have the right to lodge a complaint with a supervisory authority. In Sweden, this is the Swedish Authority for Privacy Protection (IMY). You can also complain to your local EU supervisory authority.
Security
We use technical and organizational measures appropriate to the risk to protect personal data (including encryption at rest for stored credentials such as hashed passwords).
Cookies
We do not use tracking, analytics, or advertising cookies on our website. The only cookie we set is an essential session cookie used to keep you signed in while managing your account. If you choose to make a payment, our payment provider Stripe may set cookies or use similar technologies as part of their checkout process; please refer to Stripe’s privacy and cookie policies for details.
Updates to This Policy
We may update this policy from time to time. Any changes will be published on this page.