Our security page lists which controls exist today — and what is in progress.Learn more

Legal

Privacy policy

What we process, why, where it sits and what you can ask for. Written to be read.

Last changed: TODO_DATE

1. Controller

For data about visitors to this site and people who contact us, TODO_LEGAL_ENTITY_NAME, company number TODO_ORG_NUMBER, is the controller.

For personal data inside a customer's agreements the customer is the controller and Legarch is the processor. That processing is governed by the data processing agreement.

Data protection questions: TODO_EMAIL_DPO.

2. What we process and why

Contact details you give when you write to us or book a walkthrough: name, work email, company and what you write. The purpose is to reply and to prepare the walkthrough.

Account details for users at a customer: name, email address and the actions the user performs. The purpose is to run the service and to show who did what.

Details about counterparties: name, email address, role and in some cases a personal identity number. The purpose is to identify who submitted details and who signed.

Technical data at signing: timestamp, IP address and user agent string. The purpose is to tie the signature to an occasion.

3. Legal basis

Contact and walkthroughs: legitimate interest in answering a request you sent us.

Accounts and running the service: performance of the contract with the customer.

Data in agreements and signature evidence: the customer's basis as controller, usually performance of a contract or a legal obligation.

Accounting records: legal obligation.

4. Personal identity numbers

A personal identity number is collected only where a purpose actually requires it, for example when the counterparty's choice creates an invoicing relationship. “Good to have” is not a purpose.

If the question is not asked, no identity number is stored.

5. Personal data is kept separate

Personal data is stored apart from agreement data, in its own table other queries may not join against. All reads pass through a single function.

Every access is written to an append-only log in the same database transaction as the access, so the log and the access cannot diverge.

6. Where data is stored

Agreement data is stored in Stockholm, Sweden, on AWS eu-north-1.

That covers agreement data. Email delivery and site hosting run with other providers and are not covered by that statement. The sub-processor list states where each processing takes place.

7. How long

Contact requests: TODO_RETENTION.

Account details: for the subscription term and then TODO_RETENTION.

Agreements and signature evidence: TODO_RETENTION, taking limitation periods and bookkeeping law into account.

The personal data access log: TODO_RETENTION.

8. Who processes on our behalf

We use sub-processors for hosting, storage and email delivery. The current list is on the sub-processors page.

Every sub-processor is bound by contract to the same obligations we carry.

9. Your rights

You can request access, rectification of inaccurate data, erasure, restriction of processing and portability. You can object to processing based on legitimate interest.

If a request concerns data inside a customer's agreement we pass it to that customer, who is the controller.

Write to TODO_EMAIL_DPO. You can also complain to the Swedish Authority for Privacy Protection, IMY, at imy.se.

TODO_LEGAL_ENTITY_NAME · TODO_ORG_NUMBER