Customer-sendable privacy notice covering controller and processor posture, purposes, legal bases, transfers, AI handling, retention, and rights information.
Version 1.3 · Effective July 7, 2026
Status: Customer-facing information
Contact: info@sefira.se
This Privacy Notice explains how Sefira handles personal data when people use the service, collaborate inside workspaces, upload documents, use AI-assisted features, connect integrations, receive communications, or interact with support, billing, security, and compliance functions.
This notice is intended to describe Sefira’s data-handling posture transparently. It should be read together with the Data Processing Addendum, the Subprocessor List, and the Security White Paper.
Sefira acts as controller for personal data processed for:
For Customer Workspace Content, Sefira normally acts as processor where it processes personal data on behalf of a customer under that customer’s instructions.
Some product flows may involve both roles. In those cases, the applicable role is described in the customer agreement, the DPA, product documentation, or the relevant feature path.
For privacy questions, requests, or complaints, contact info@sefira.se.
If Sefira acts only as processor for the relevant data, Sefira may need to refer the request to the relevant customer organization as controller.
Sefira may collect personal data:
Depending on the feature used, Sefira may process:
Sefira processes personal data to:
For EU and EEA-facing processing, Sefira may rely on one or more of the following legal bases depending on the relevant processing activity:
| Processing purpose | Typical data categories | Typical legal basis | Notes |
|---|---|---|---|
| Account creation, login, authentication, and workspace access | identity, account, authentication data | Contract | Required to provide the service |
| Workspace collaboration and customer-configured workflows | workspace content, assignments, comments, files, document data | Contract and/or processor role under customer instructions | Customer may be controller for workspace content |
| Security, abuse prevention, fraud detection, and service reliability | session artifacts, logs, device/security signals, operational records | Legitimate interests | Used to secure accounts, protect the service, and investigate misuse |
| Billing, subscription administration, and invoicing | billing contact data, provider customer IDs, commercial records | Contract and legal obligation | Accounting and tax retention may apply |
| Support and service-response handling | support correspondence, account context, troubleshooting data | Contract and legitimate interests | Used to resolve issues and maintain the service |
| AI-assisted features where enabled | prompts, selected context, outputs, run metadata | Contract, processor role, and/or customer-enabled feature choice | Depends on the relevant feature path and customer configuration |
| Optional communications where consent is specifically requested | contact data, preference data | Consent | Consent may be withdrawn at any time |
| Legal compliance, auditability, and accountability records | compliance logs, billing records, audit events, legal response records | Legal obligation and legitimate interests | Used to meet legal duties and defend legal claims |
Where Sefira relies on legitimate interests, those interests may include securing accounts, preventing misuse, maintaining audit trails, protecting the service and its users, responding to support requests, improving reliability, enforcing terms, and protecting legal claims.
Individuals may have the right to object where Sefira relies on legitimate interests.
Some personal data is required to create an account, authenticate users, provide the service, maintain security, administer billing, or comply with legal obligations.
If required data is not provided, Sefira may not be able to provide the relevant account, feature, support, billing, or compliance function.
Optional features, integrations, and AI-assisted workflows may be disabled or not used if the relevant data is not provided.
Personal data may be processed with or through service providers involved in:
Sefira maintains a public Subprocessor List at /subprocessors. The exact provider path can vary depending on enabled features, configured providers, active integrations, and deployment environment.
Some provider paths may involve processing outside Sweden or the EEA.
Where personal data is transferred outside the EEA to a country without an adequacy decision, Sefira uses appropriate safeguards such as the EU Standard Contractual Clauses or another valid transfer mechanism under applicable data protection law.
More detailed provider-path information is available through the Subprocessor List and, where needed, customer-specific diligence materials.
Sefira does not treat every deletion event as immediate erasure of all historical service records.
The retention model distinguishes between:
Typical retention criteria include:
This means deletion and access requests are handled against the specific data class, legal context, and applicable role, not against a blanket "delete everything instantly" promise.
Sefira applies layered access control, protected token and secret handling, signed external callback patterns where relevant, authentication abuse protections such as throttling and temporary lockouts, logging and auditability measures, and service-security controls appropriate to the product environment.
Further detail is available in the Security White Paper.
Some Sefira features use AI to assist with drafting, analysis, process-building, and document-related tasks.
Public handling principles:
Unless expressly agreed otherwise in writing, Sefira does not use Customer Workspace Content to train general-purpose AI models for its own independent purposes.
Sefira does not use personal data for solely automated decisions that produce legal or similarly significant effects on individuals, unless expressly stated in feature-specific terms.
Sefira may use strictly necessary cookies, authentication/session technologies, and similar service-operation mechanisms required to provide secure access and maintain product functionality.
If analytics, telemetry, or other optional tracking mechanisms are used, they are disclosed through the relevant product or customer-facing notice for that implementation path.
Sefira may send:
Where marketing or optional communications rely on consent, consent may be withdrawn at any time. Individuals may also have opt-out rights where applicable.
The service is intended for business and organizational use and is not directed to children.
Customers remain responsible for determining whether they may lawfully submit special category personal data or data relating to children into the service. Unless otherwise expressly agreed, the service is not described as a general-purpose repository for sensitive personal data without customer-side legal assessment and appropriate controls.
Depending on applicable law, individuals may have rights including:
Requests can be sent to info@sefira.se.
Sefira may need to verify identity before acting on a request. Where Sefira acts only as processor for the relevant data, Sefira may need to refer the request to the relevant customer controller.
Individuals who believe their personal data has been handled unlawfully may have the right to complain to a supervisory authority.
In Sweden, this is normally IMY.