Legal information
Privacy Policy
Last updated: 4 August 2026
1. Data controller
AI-AO is the controller for the processing described here. Contact us at info@ai-ao.net or by phone at +46 700 95 83 27.
2. Data we process
- Bookings: name, email address, organization, phone number, selected meeting, and message.
- Member accounts: display name, email address, securely protected password, and account and login information.
- Comments: comment text, account, time, and moderation status.
- Technical data: IP address, timestamps, browser information, and server logs required for operation and security.
- Social sign-in: if enabled, we may receive your name, email address, and a unique identifier from your chosen provider.
3. Purposes and legal basis
- Managing booking requests and communication before a potential engagement: steps prior to a contract and legitimate interests.
- Creating and administering member accounts and providing comments: performance of the Terms of Use.
- Moderating comments and preventing abuse, fraud, and security incidents: legitimate interests.
- Meeting legal obligations such as accounting or authority requirements: legal obligation.
- Social sign-in data is processed when you actively choose a provider and approve its sign-in flow.
We do not use the data for automated decision-making with legal or similarly significant effects.
4. Recipients and providers
Data may be processed by providers that assist with server operation, backups, and email delivery. Email is currently delivered through Google. If social sign-in is enabled, the chosen provider processes data under its own terms. We do not sell personal data.
Some providers may process data outside the EU/EEA. Where this occurs, processing must be supported by an applicable adequacy decision or other GDPR safeguards.
5. Retention
- Booking and contact data is normally retained for no more than 24 months after the latest contact, unless a contract or legal duty requires longer retention.
- Member accounts are retained until you request deletion. Accounts inactive for 36 months may be removed after reasonable notice.
- Approved comments may remain while the article is published. Rejected and pending comments are normally deleted within 12 months.
- Security and server logs are normally retained for no more than 90 days unless an incident requires longer investigation.
7. Your rights
You may have rights to information, access, correction, deletion, restriction, portability, and objection. Contact us by email to exercise your rights. We may need to verify your identity. You may also complain to the Swedish Authority for Privacy Protection (IMY).
8. Security and changes
We use access controls, encrypted HTTPS communication, password hashing, backups, and restricted administrative access. No internet service is entirely risk-free. This policy may be updated when the service or legal requirements change; the date above shows the latest version.
