Last Updated: July 15, 2026
Introduction
Kristensson i Skåne AB (“we“, “us” or “our“) respects your privacy and is committed to protecting your personal data. This Privacy Notice explains how we collect, use, and safeguard personal information when you visit our website or engage with our services. We adhere to the EU General Data Protection Regulation (GDPR) and applicable Swedish data protection laws in all our data processing activities.
By using our website, you acknowledge that you have read this Privacy Notice. If you do not agree with its terms, please refrain from using our site or providing personal information.
We are committed to making our privacy information accessible. If you require this notice in another format due to a disability, please contact us.
Data Controller and Contact Information
Kristensson i Skåne AB, a company registered in Sweden (Org. No. 556963-2317), is the data controller for the personal data we process. Our contact details are provided in the “Contact Us” section below.
Personal Data We Collect
Depending on how you interact with us, we may collect and process the following categories of personal data.
- Contact Information: If you contact us (for example, via phone, email or a contact form), we may collect your name, email address, phone number, job title, or other information you provide. If you contact us by email, your message and any attachments will be processed via Microsoft 365.
- Inquiry or Service Data: Details related to your inquiries or requests, such as the content of messages you send us or information about the services you inquire about.
- Job Application Data: If you apply for a job or express interest in employment with us (for instance, by sending a CV or cover letter), we will collect the personal data you include in your application. This typically includes contact details, professional qualifications, employment history, and any other information you choose to provide about yourself in the context of recruitment. We will use this data only for recruitment and hiring purposes. If you send us job applications by email, your message and any attachments will be processed via Microsoft 365.
- Website Usage Data: When you visit our website, we gather basic analytics data through our analytics tools. This may include your IP address (which we do not store in identifiable form), general geographic region (e.g. country or city), device type, browser type, operating system, referring website, pages viewed, and the dates/times of access. This information is collected in an aggregated or anonymized format and does not directly identify you.
- Advertising Data: If you have consented to our advertising cookies, we may collect data about how you interact with our ads. This could include whether you arrived at our site by clicking an advertisement, and technical data captured via advertising pixels/tags (as described in the Processing overview table and under “Cookies and Tracking Technologies”).
We do not intentionally collect any sensitive personal data (such as information about health, political opinions, or religious beliefs) through our website. We also do not knowingly collect personal data from children under 16 years of age; our website and services are aimed at business and professional audiences.
Processing Overview (Purposes, Legal Bases, Recipients, Transfers, Retention)
The table below summarises how we process personal data, including the purposes of processing, categories of data involved, legal bases under the GDPR, recipients or processors, information about international transfers, and applicable retention periods.
| Processing activity | Categories of personal data | Purpose | Legal basis (as described in this notice) | Key recipients / processors (as described in this notice) | International transfers & safeguards (as described in this notice) | Retention / storage period (as described in this notice) |
|---|---|---|---|---|---|---|
| Handling enquiries and contact requests (phone, email, contact form) | Name, email, phone number, job title, and other information you provide; message content and attachments | Respond to enquiries; provide requested information/services; communicate with you; improve offerings and user experience | Legitimate interests (and/or performance of a contract where discussions lead to a client relationship) | Microsoft 365 (email, message content and attachments); Amazon SES (transmission of contact-form notification emails) | Microsoft 365 is configured to store and process customer data within the EU/EEA where available for our tenant. Where processing occurs outside the EEA (e.g., certain support/operations scenarios), transfers are safeguarded as described in ‘International Data Transfers’ and our contractual safeguards. | If you do not become a client: generally up to 12 months after we respond, then delete/anonymise unless a longer retention is required |
| Delivering consulting services and managing client relationships | Contact details and project information; business communications; (where applicable) invoicing/contact details on financial records | Enter into and fulfil the contract; deliver services | Performance of a contract | Microsoft 365 (email, document storage and collaboration) | Microsoft 365 is configured to store and process customer data within the EU/EEA where available for our tenant. Where processing occurs outside the EEA (e.g., certain support/operations scenarios), transfers are safeguarded as described in ‘International Data Transfers’ and our contractual safeguards. | Duration of contractual relationship + thereafter as needed; accounting records may be kept 7 years as required by Swedish accounting/tax laws |
| Recruitment (job applications) | Contact details; CV/cover letter; professional qualifications; employment history; other information provided in recruitment context; recruitment correspondence | Evaluate candidacy; manage recruitment process; make hiring decisions | Legitimate interests (as described in this notice) | Microsoft 365 (email, attachments, recruitment correspondence) | Microsoft 365 is configured to store and process customer data within the EU/EEA where available for our tenant. Where processing occurs outside the EEA (e.g., certain support/operations scenarios), transfers are safeguarded as described in ‘International Data Transfers’ and our contractual safeguards. | Applications not resulting in employment are deleted within 6 months unless consent is given or legal obligations apply |
| Website analytics (Plausible) | Website usage data in aggregated/anonymised form; includes IP-derived location (IP not stored in identifiable form as described), device type, browser type, operating system, referrer, pages viewed, access times | Understand how visitors use the website; improve user experience and content | Legitimate interests | Plausible Analytics | No transfers outside the EU are expected for this processing. Plausible states that website analytics data for their hosted service does not leave the EU. See “International Data Transfers” for our general approach if this changes. | Aggregated analytics may be retained indefinitely; no set expiration stated; (if Plausible hosted service is used, your notice states data is stored on EU servers) |
| Cookie consent management (CookieYes CMP) | Consent preferences/status; timestamp; country; consent ID; pseudonymised IP in consent log/proof of consent (as stated) | Display cookie banner; store cookie choices; keep proof of consent | Legal obligation (where required to record consent) and/or legitimate interests (consent management) | CookieYes | CookieYes uses hosted infrastructure (including AWS). Where processing involves transfers outside the EEA/UK, transfers are safeguarded using the mechanisms described in “International Data Transfers” and the safeguards described in this notice (e.g., adequacy and/or Standard Contractual Clauses, as applicable). | 1 year (as stated) |
| Language preference (Polylang) | Language preference cookie (commonly “pll_language”) | Provide multilingual content; remember selected language | Legitimate interests (providing language functionality) | Polylang plugin (via your website) | No international transfer is expected. The language preference cookie is stored in your browser to remember your selection. See “International Data Transfers” for our general approach if this changes. | 1 year (as stated) |
| Website hosting and security logs (Amazon Web Services) | Website content; technical logs; contact form data (if submitted); server log data for security/troubleshooting | Operate and secure the website; troubleshooting; security and network management | Legitimate interests (security/operations) | Amazon Web Services | No transfers outside the EEA are expected for this processing as hosting/log storage is described as Sweden/EU/EEA in this notice. See “International Data Transfers” for our general approach if this changes. | Logs generally kept for a limited period (weeks) unless required for security investigations |
| Advertising measurement and marketing (Google Ads) — only if you consent | Online identifiers (IP address, advertising identifiers); device/browser data; interaction data (ad clicks, page visits); conversion events | Advertising; conversion tracking; remarketing; measure campaign effectiveness | Consent | Google (Google Ireland Limited in EU/EEA + Google LLC in the US, as stated) | May involve transfers to the United States. Google may process data via Google Ireland Limited and transfer data to Google LLC in the U.S. Transfers are safeguarded as described in “International Data Transfers” (e.g., EU–U.S. Data Privacy Framework and/or Standard Contractual Clauses, as stated in this notice). | Advertising cookies typically expire within 30 days; aggregated reports retained per Google settings (as stated) |
| Advertising measurement and marketing (LinkedIn Insight Tag) — only if you consent | Online identifiers; LinkedIn user ID (if logged in) or unique visitor identifier; IP address; device/browser data; website interaction data; timestamps and pages visited | Measure effectiveness of LinkedIn ads; obtain aggregated insights; improve ad targeting | Consent | LinkedIn Ireland Unlimited Company (EEA controller, as stated) + LinkedIn Corporation (US processing, as stated) | May involve transfers to the United States. Transfers are safeguarded as described in ‘International Data Transfers’, including Standard Contractual Clauses (SCCs) and other lawful transfer mechanisms, as applicable. | Cookies typically retained up to 6 months; aggregated analytics retained per LinkedIn policies (as stated) |
| Legal compliance, security, dispute handling, enforcement | Data depends on the matter (e.g., necessary correspondence or identifiers) | Comply with legal obligations; respond to lawful requests; prevent fraud; resolve disputes; enforce agreements; detect/prevent security incidents | Legal obligation and/or legitimate interests | Authorities (where required), relevant parties as needed | Case-dependent. Transfers depend on the specific situation (e.g., legal requests or security incidents). See “International Data Transfers” for our general approach and safeguards where transfers outside the EEA are required. | As long as necessary for the specific legal/security purpose. |
We will only use your personal data for the purposes listed in the Processing overview table above or for closely related purposes. If we need to use your data for any other purpose, we will inform you and ensure there is a valid legal basis for that new processing.
If you have questions about the specific legal basis applicable to a particular processing activity, feel free to contact us for more information.
Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies in a limited manner:
- Strictly Necessary Cookies: We may use essential cookies that enable core site functionality (such as language selection, cookie preference tools, security and network management). These cookies do not require consent. We also use a web hosting provider (Amazon Web Services) to operate and secure our website, which may involve processing limited server log data for security and troubleshooting purposes.
- Cookie Consent Management (CookieYes): We use CookieYes as our cookie consent management platform (CMP) to display our cookie banner and store your cookie choices. CookieYes sets a necessary cookie (e.g., “cookieyes-consent”) to remember your preferences so they are respected on subsequent visits.
- Language Preference (Polylang): We use the Polylang plugin to provide multilingual content. Polylang may set a cookie (commonly “pll_language”) to remember your selected language and show the website in that language on subsequent pages/visits. The language preference cookie is stored for 1 year.
- Analytics: We use Plausible Analytics to understand how visitors use our website and to improve content and user experience. Plausible does not use cookies or persistent identifiers and does not store IP addresses in identifiable form. Further details regarding legal basis, recipients, international transfers and retention are set out in the Processing overview table above.
- Advertising Cookies: We use third-party advertising tools (Google Ads and LinkedIn Insight Tag) which may set cookies or similar trackers on your device, but only if you have given consent via our cookie consent banner. These tools are used to measure advertising effectiveness and, where enabled, support remarketing. You can withdraw your consent at any time via our cookie settings. You can update your choices at any time using the cookie settings link/banner on our website. Further details regarding legal basis, recipients, international transfers and retention are set out in the Processing overview table above.
You can manage or delete cookies at any time through your browser settings.
For more information about how these providers process data, please refer to their privacy and cookie policies:
- Plausible Analytics (Data Policy): https://plausible.io/data-policy
- Google (Privacy Policy): https://policies.google.com/privacy
- Google (How Google uses cookies): https://policies.google.com/technologies/cookies
- LinkedIn (Privacy Policy): https://www.linkedin.com/legal/privacy-policy
- LinkedIn (Cookie Policy): https://www.linkedin.com/legal/cookie-policy
- CookieYes (Privacy Policy): https://www.cookieyes.com/privacy-policy/
- CookieYes (Cookie Policy): https://www.cookieyes.com/cookie-policy/
- Amazon Web Services (Privacy Notice): https://aws.amazon.com/privacy/
- Amazon Web Services (GDPR and Data Processing): https://aws.amazon.com/compliance/gdpr-center/
- Microsoft (Privacy Statement): https://www.microsoft.com/en-us/privacy/privacystatement
Data Sharing and Disclosure
We treat your personal data with care and confidentiality. We do not sell or rent personal data to third parties. However, we may share your information in the following circumstances:
- Service Providers: We use trusted third-party service providers to assist us in operating our website and delivering our services. These include our analytics provider (Plausible) and advertising partners (Google and LinkedIn) described above, as well as web hosting or IT support services. We use Amazon Web Services (AWS, hosted in the EU/Stockholm region) for website hosting, Amazon SES (EU/Stockholm) for automated outbound email, and Microsoft 365 for email and document handling. Details are provided in the “Third-Party Service Providers and Sub-Processors” section below. These parties process data on our behalf only for the purposes described in this Privacy Notice and under our instructions. We have agreements in place with such processors to ensure your data is protected (for example, Data Processing Agreements that bind them to confidentiality, security measures, and GDPR compliance).
- Legal Requirements: We may disclose personal data if required to do so by law or in response to valid requests by public authorities (e.g., law enforcement, courts, or regulatory agencies). For example, if we receive a subpoena or a legally binding request, or need to report data breaches to authorities, we will comply with our legal obligations.
- Business Transfers: In the event of a reorganization, merger, acquisition, or sale of all or part of our business or assets, personal data relevant to that transaction may be transferred to the acquiring or merging entity. We will ensure the recipient of the data is obligated to protect your personal information in line with this Privacy Notice and applicable law.
- Protection of Rights: We may share information as necessary to enforce our terms of service or other agreements, or to protect the rights, property, or safety of Kristensson i Skåne AB, our employees, our clients, or others. This may include exchanging information with other companies and organizations for the purposes of fraud protection or credit risk reduction (in accordance with data protection laws).
In all cases, we only share the minimum personal data necessary for each purpose and ensure that any third party we share it with has a legitimate need to know and will handle the data with appropriate security and confidentiality.
Third-Party Service Providers and Sub-Processors
To ensure transparency, the table below provides an overview of our key third-party service providers (sub-processors), including the purpose of processing, categories of personal data involved, data location, and retention principles. These providers process personal data on our behalf and only in accordance with our instructions and applicable data protection agreements.
| Provider (Service) | Purpose of Processing | Categories of Personal Data | Data Location | Retention / Storage Period | Safeguards |
|---|---|---|---|---|---|
| CookieYes Limited (CookieYes CMP) UK Ownership | Cookie consent management (banner, consent preferences, and consent logs/proof of consent) | Consent preferences, consent status, timestamp, country, consent ID, pseudonymized IP as part of consent log/proof of consent. | Hosted infrastructure (AWS) – Region not publicly specified by CookieYes | 1 year | Data Processing Agreement (DPA), UK Adequacy, Standard Contractual Clauses (SCCs) |
| Google Ads (Google LLC) USA Ownership | Advertising, conversion tracking, and measuring campaign effectiveness | Online identifiers (IP address, advertising identifiers), device and browser data, interaction data (e.g. ad clicks, page visits) | United States (EU–U.S. Data Privacy Framework) | Advertising cookies typically expire within 30 days; aggregated reports retained according to Google’s standard retention settings | EU–U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs) |
| LinkedIn Ads (LinkedIn Corporation / LinkedIn Ireland UC) USA Ownership | Advertising, analytics, and measurement of LinkedIn ad performance (Insight Tag) | Online identifiers, LinkedIn user ID (if logged in), IP address, device and browser data, website interaction data | United States (EU–U.S. Data Privacy Framework) | Cookies typically retained up to 6 months; aggregated analytics retained per LinkedIn’s policies | EU–U.S. Data Privacy Framework, Standard Contractual Clauses (SCCs) |
| Amazon Web Services EMEA SARL (Web hosting) EU (Stockholm, Sweden) | Website hosting, infrastructure, and data storage | Website content, technical logs, contact form data (if submitted) | Sweden / EU / EEA | Data retained as long as necessary for website operation; logs generally kept for a limited period (weeks) unless required for security investigations | EU/EEA hosting, GDPR-compliant data processing agreement |
| Amazon SES (Amazon Web Services EMEA SARL) EU (Stockholm, Sweden) | Sending automated outbound email from the website (contact-form notifications, system emails) | Recipient email address; email content | Sweden / EU / EEA | Message data retained only as long as needed for delivery and logging (short period) | EU/EEA hosting, GDPR-compliant data processing agreement |
| Microsoft 365 (Microsoft Corporation) USA Ownership | Email communication, document storage, collaboration and internal business operations and recruitment processes | Contact details, email content, attachments, documents, business communications, job application data (CVs, cover letters, professional history, recruitment correspondence) | EU / EEA (EU-based data centers) | Data retained according to contractual relationship and legal requirements (e.g. up to 7 years for accounting-related records under Swedish law). Recruitment data is generally retained only for the duration of the recruitment process and for a limited period of 6 months, unless consent is given or legal obligations apply. | EU Data Boundary, Standard Contractual Clauses, Microsoft GDPR commitments |
International Data Transfers
Whenever we transfer or store your personal data outside of the European Economic Area (EEA), we take steps to ensure it remains protected in line with EU standards. The GDPR requires that when personal data is exported to countries outside the EEA that may not have the same data protection laws, appropriate safeguards are in place.
Some of our service providers are based in, or have servers in, countries outside the EEA:
- United States: Some of our service providers and partners may process personal data in the United States or otherwise outside the EU/EEA, depending on the service used and your choices (for example, if you consent to advertising cookies). Where personal data is transferred outside the EU/EEA, we ensure that an appropriate transfer mechanism under the GDPR is in place. This may include relying on an adequacy decision by the European Commission (where applicable), and/or implementing EU Standard Contractual Clauses (SCCs) and, where necessary, supplementary measures to ensure an essentially equivalent level of protection. Details about which providers may involve transfers and the safeguards used are set out in the Processing overview table and in the Third-Party Service Providers and Sub-Processors section.
- Other Countries: We primarily use service providers with processing in the EU/EEA. If in the future we need to transfer personal data to any other country outside the EU/EEA, we will ensure that a GDPR-approved transfer mechanism is in place before the transfer takes place. Depending on the circumstances, this may include relying on an EU adequacy decision (where applicable) and/or implementing EU Standard Contractual Clauses (SCCs), Binding Corporate Rules (BCRs), or other safeguards permitted under the GDPR. Where required, we will also implement supplementary measures to ensure an essentially equivalent level of protection. If an appropriate safeguard cannot be ensured, we will not carry out the transfer unless a limited GDPR derogation applies in a specific case. We will reflect any material changes in this Privacy Notice and in the Processing overview table.
You can contact us if you would like more information about our international data transfer practices or the safeguards we apply (for example, to obtain a copy of the Standard Contractual Clauses we use with third-party service providers).
Data Security
We take data security seriously. We have implemented appropriate technical and organizational measures to protect your personal data from unauthorized access, alteration, disclosure, or destruction. These measures include, for example, using firewalls and encryption to protect data, maintaining secure servers, using HTTPS (SSL/TLS) encryption to secure data in transit on our website, and enforcing access controls so that only authorized personnel and contractors (who are bound by confidentiality obligations) can access personal data on a need-to-know basis. We also maintain internal policies and conduct training to ensure that staff handle personal data with care and integrity.
We regularly review our security practices and update them in line with technological developments and industry standards. Additionally, we ensure that any third-party processors handling personal data on our behalf (such as our analytics or hosting providers) are also employing strong security measures.
Please note that while we strive to protect your information with a high degree of care, no method of transmission over the Internet or method of electronic storage is 100% secure. Therefore, we cannot guarantee absolute security of your data. However, in the unlikely event of a data breach affecting your personal data, we will follow all applicable breach notification laws. This means we will notify you and the relevant supervisory authority (e.g., IMY in Sweden) without undue delay when required by GDPR, and we will take all reasonable steps to mitigate any potential harm.
Data Retention
We retain personal data in accordance with the retention periods specified in the Processing overview table above and only for as long as necessary to fulfill the purposes for which it was collected, or to satisfy legal, accounting, or reporting requirements.
Once the applicable retention period is over, or if the data is no longer needed for the purpose it was collected, we will either securely delete the personal data or anonymize it (so it can no longer be associated with an identifiable individual). If deletion is not immediately feasible (for example, because the data is stored in backups), we will ensure the data remains securely stored and isolated from further active use until deletion is possible.
Your Rights Under GDPR
As an individual in the European Union (or in other jurisdictions with similar data protection laws), you have certain rights regarding your personal data. These rights, subject to certain conditions and exceptions, include:
- Right of Access: You have the right to request confirmation of whether we are processing your personal data, and if so, to request a copy of the personal data we hold about you. This allows you to know and verify the lawfulness of our processing.
- Right to Rectification: You have the right to request that we correct or update any inaccurate or incomplete personal data we hold about you. We strive to keep your data accurate and will address correction requests promptly.
- Right to Erasure: You have the right to request deletion of your personal data in certain circumstances. This right (also known as the “right to be forgotten”) applies, for example, if the data is no longer necessary for the purposes it was collected, if you withdraw consent and no other legal basis for processing exists, or if you believe we are unlawfully processing your data. Please note that this right is not absolute – we may need to retain certain information where required by law or where we have compelling legitimate grounds to keep it (e.g., for legal claims or fraud prevention).
- Right to Restrict Processing: You have the right to request that we limit the processing of your personal data under certain conditions. For instance, you can request restriction if you contest the accuracy of the data (while we are verifying it), or if you object to our processing based on legitimate interests (while we assess the request), or when processing is unlawful but you prefer we restrict use of the data rather than delete it. When processing is restricted, we will store your data but not use it further until the restriction is lifted (except for exempted purposes like legal claims or protecting others’ rights).
- Right to Data Portability: For data that you have provided to us and which we process by automated means based on your consent or to perform a contract, you have the right to request a copy in a structured, commonly used, machine-readable format (for example, CSV or JSON file). You also have the right to transmit that data to another controller, or have us transfer it for you where technically feasible. This right facilitates moving your business or services elsewhere if you choose.
- Right to Object: You have the right to object to our processing of your personal data in certain situations. You can always object to processing for direct marketing purposes, and if you do, we will stop processing your data for that purpose. If we are processing your data based on legitimate interests, you can object if you believe your rights and interests outweigh our interests; we will then re-evaluate our reasons for processing your data. If your objection is valid and we have no compelling reason to continue processing, we will stop the processing in question.
- Right to Withdraw Consent: If we are processing any of your personal data based on your consent, you have the right to withdraw that consent at any time. For example, if you consented to cookies, you can change your mind and disable them (via our site or your browser). Withdrawing consent will not affect the lawfulness of processing that occurred before the withdrawal. If you withdraw consent for a specific purpose, we will stop the processing of your data for that purpose unless we have another lawful basis to continue (which we would communicate to you).
- Right to Lodge a Complaint: If you believe that we have infringed your data protection rights or GDPR obligations, you have the right to file a complaint with a supervisory authority. Kristensson i Skåne AB is established in Sweden, so our lead supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). You can contact IMY or visit their website for information on how to submit a complaint. If you reside in another EU/EEA country, you may choose to contact your local data protection authority instead.
To exercise any of your rights, please contact us using the information in the next section. We will respond to your request as soon as possible, and no later than one month from receipt of your request (this may be extended by an additional two months for complex requests, but we will inform you if an extension is needed). Please note that we may need to verify your identity before fulfilling certain requests, to ensure that we do not disclose data to the wrong person. This could involve asking for additional information or identification. There is no fee for exercising your rights unless the requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.
Contact Us
If you have any questions about this Privacy Notice or our data practices, or if you wish to exercise your rights or raise a concern, please contact us.
Kristensson i Skåne AB
Postal address: Hällavägen 14-0, SE-244 95 Dösjebro, Sweden
Email: dataprotection@kiskane.se
Phone: +46 70 32 48 128
We will be happy to assist you and address any requests or concerns you may have regarding your personal data.
Updates to this Privacy Notice
We may update or revise this Privacy Notice from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. When we make changes, we will update the “Last Updated” date at the top of this Notice. If the changes are significant, we may also notify you by additional means (for example, by posting a prominent notice on our website or, if we have your email on file, by sending you an email notification).
We encourage you to review this Privacy Notice periodically to stay informed about how we are protecting your information. Your continued use of our website or services after any changes to this Notice will be deemed acceptance of those changes, to the extent permitted by law.
By using our website, you trust us with some of your personal information. We value that trust and are committed to using your data responsibly and transparently. If anything in this Privacy Notice is unclear or if you need further information, please do not hesitate to reach out to us at the contact details provided above.
Thank you for reading our Privacy Notice.
