Privacy Policy
Effective date: 2026-07-17
Effective date: 2026-07-17
This Privacy Policy explains how Trädkungen Skåne AB (org. no. 559468-7872), Vintergatan 16, 243 34 Höör, Sweden ("we", "us", "our") collects, uses, and protects personal data when you use Frejmwork (the "Service"). It is written to comply with the EU General Data Protection Regulation (GDPR) and applicable Swedish law.
This policy should be read together with our Terms and Conditions. By registering for Frejmwork, you confirm you have read and understood this Privacy Policy.
1. Who We Are
Trädkungen Skåne AB is the data controller responsible for your personal data.
- Company: Trädkungen Skåne AB
- Org. no.: 559468-7872
- Address: Vintergatan 16, 243 34 Höör, Sweden
- Contact: hello@frejmwork.dev
If you have any questions about this policy or how your data is handled, contact us at the email address above.
2. What Data We Collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, hashed password/auth identifier, display name, avatar | You, at signup (via Supabase Auth) |
| Profile & preferences | Theme, accent color, notification preferences, changelog view state, onboarding progress | You, via account settings |
| Billing data | Subscription plan, Stripe customer reference, purchase/invoice history | You (via Stripe at checkout) and Stripe |
| Project content | Projects, breakdowns, and planning content you create in the Service, including any third-party information you choose to enter (e.g., client or team names) | You |
| AI interaction data | Prompts you submit to AI-powered features and the resulting outputs | You, processed via Anthropic's Claude API |
| Usage & technical data | Recent project activity, login timestamps, IP address, device/browser information, error logs | Automatically, via the Service and our monitoring tools |
We do not collect special categories of data (e.g., health, biometric, or political data) as part of normal Service operation. Please do not enter such data into project content unless it is strictly necessary for your own purposes, and note that you are responsible for having a lawful basis to do so if it concerns third parties.
3. How We Use Your Data and Why (Legal Bases)
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and managing your account | Performance of a contract |
| Providing the Service, including AI-powered project planning features | Performance of a contract |
| Processing payments and managing your subscription/credits | Performance of a contract |
| Sending essential service emails (billing, credit balance, invites you trigger) | Performance of a contract / legitimate interest |
| Sending optional product updates (only if you opt in) | Consent |
| Detecting fraud, abuse, and securing the Service | Legitimate interest |
| Responding to support requests | Legitimate interest / contract |
| Complying with accounting and tax obligations | Legal obligation (Swedish Bookkeeping Act, see Section 6) |
| Complying with other legal obligations, or establishing/defending legal claims | Legal obligation / legitimate interest |
You can control optional communications at any time from your account notification settings.
4. AI Processing Disclosure
Frejmwork uses artificial intelligence — specifically Claude, provided by Anthropic, PBC — to power project-planning features such as generating suggestions and breakdowns.
- When you use an AI-powered feature, the relevant prompt and related project content is sent to Anthropic's API to generate a response.
- You are interacting with an automated system, not a human, when using these features.
- Anthropic processes this data as our sub-processor, under its own commercial data protection terms, and does not use API data to train its models.
- Data retention with Anthropic: Anthropic automatically deletes API inputs and outputs within 30 days of receipt or generation. We do not currently have a Zero Data Retention (ZDR) agreement with Anthropic. Content flagged by Anthropic's automated safety systems as a Usage Policy violation may be retained by Anthropic for up to 2 years (with related classification data retained up to 7 years). See Anthropic's Privacy Center for further detail.
- Do not submit sensitive personal data about third parties into AI-powered features unless it is necessary for your own legitimate purpose and you have a lawful basis to do so.
5. Who We Share Data With (Sub-processors)
We share personal data only with service providers who help us operate Frejmwork, each bound by a Data Processing Agreement (DPA). We do not sell your personal data.
| Sub-processor | Purpose | Location / transfer mechanism |
|---|---|---|
| Supabase | Database, authentication, storage | EU region (confirm project region) |
| Anthropic, PBC | AI processing (Claude API) | US — Standard Contractual Clauses (SCCs) |
| Stripe | Payment processing | US/EU — SCCs where applicable |
| Resend | Transactional email delivery | US — SCCs where applicable |
| Sentry | Error monitoring | US/EU — SCCs where applicable |
| Upstash | Rate limiting (Redis) | Confirm region — SCCs where applicable |
| Vercel | Application hosting | Global CDN — SCCs where applicable |
We may update this list as our infrastructure evolves; material changes will be reflected here and, where required, communicated to you directly.
We may also disclose personal data where required by law, to protect our legal rights, or in connection with a merger, acquisition, or sale of assets (subject to the protections described in this policy carrying over).
6. How Long We Keep Your Data
| Data | Retention period |
|---|---|
| Account data | For as long as your account is active, plus a limited grace period after deletion to allow recovery |
| Project content | For as long as your account is active, or per your own project archival choices |
| Billing and accounting records | 7 years, as required by the Swedish Bookkeeping Act (Bokföringslagen). This applies specifically to invoices, payment records, and related accounting data — it does not extend to your wider account or project data, which is deleted on request as normal. |
| AI prompts and outputs (held by Anthropic) | 30 days (see Section 4) |
| Support communications | Up to 24 months |
| Error/monitoring logs | Up to 90 days |
Where you request deletion of your account, we delete or anonymize your personal data other than what we are legally required to retain (in particular, billing records under the Bookkeeping Act, as noted above).
7. Your Rights
Under GDPR, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten"), subject to our legal retention obligations (see Section 6).
- Restrict processing in certain circumstances.
- Port your data to another service in a structured, machine-readable format.
- Object to processing based on legitimate interest, including direct marketing.
- Withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at hello@frejmwork.dev. We will respond within one month, as required by GDPR (extendable by a further two months for complex requests, with notice to you).
If you believe your data has been processed unlawfully, you have the right to lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
Website: imy.se
8. Cookies and Similar Technologies
Frejmwork uses strictly necessary cookies/local storage to keep you signed in and to operate the Service (e.g., authentication session tokens set by Supabase Auth). These do not require consent under applicable law, as they are essential to providing the Service you've requested.
If we introduce analytics, marketing, or other non-essential cookies in the future, we will update this section and request your consent where required.
9. Security
We apply technical and organizational measures to protect your data, including encryption in transit and at rest, access controls (including row-level security on our database), restricted administrative access, and server-side handling of all third-party API credentials. No system is completely secure, and we cannot guarantee absolute security, but we work to minimize risk and respond promptly to any issues.
In the event of a personal data breach likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by law, and notify you directly where the risk is high.
10. International Data Transfers
Some of our sub-processors are located outside the EU/EEA (see Section 5). Where this is the case, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses (SCCs) to ensure your data receives an equivalent level of protection.
11. Age Requirement
Frejmwork is intended for users 18 years of age or older. We do not knowingly collect personal data from individuals under 18. If we become aware that we have done so, we will delete that data promptly.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you (e.g., by email or in-app notice) before the changes take effect. The "Effective date" at the top of this page reflects the latest version.
13. Contact Us
Trädkungen Skåne AB
Vintergatan 16, 243 34 Höör, Sweden
Email: hello@frejmwork.dev