Safespring is a Swedish cloud infrastructure provider, proudly Swedish owned and operated.
We deliver Public Cloud and Private Cloud services for organisations that require secure, reliable, and high-performance infrastructure. Safespring operates through legal entities in Sweden and Norway and provides services from data centres located within these jurisdictions.
This Privacy Policy describes how Safespring (“we”, “us”, “our”) processes personal data in accordance with:
- General Data Protection Regulation (“GDPR”)
- ePrivacy Directive
- Digital Services Act
- ISO/IEC 27001
1. Data Controller
Safespring AB
559075-0245
Rättarvägen 3, 169 68 Solna
Sweden
For privacy-related matters, including the exercise of data subject rights, you may contact us at gdpr@safespring.com
2. Your Rights Under GDPR
You are entitled to the following rights under applicable data protections laws:
- The right to access: You are entitled to receive certain information on our processing of your personal data. Such information is provided in this information document. Further, you have the right to receive a copy of the personal data we process relating to you. Upon request, we will provide a copy of your personal data in a commonly used electronic form.
- The right to rectification: You are entitled to obtain rectification of inaccurate personal data and to have incomplete personal data completed.
- The right to erasure (“right to be forgotten”): You may under certain circumstances request us to delete your personal data. Please note that this right is not unconditional. Therefore, an attempt to invoke the right might not lead to an action from us.
- The right to restriction of processing: You may under certain circumstances request from us to restrict the processing of your personal data. Please note that this right is not unconditional. Therefore, an attempt to invoke the right might not lead to an action from us.
- The right to data portability: You are entitled to receive your personal data (or have your personal data directly transmitted to another data controller) in a structured, commonly used and machine-readable format.
- The right to object: You are entitled to object to certain processing activities conducted by us in relation to your personal data, such as our processing of your personal data based on our legitimate interest.
- Right to withdraw consent: In the event we process data on the basis of your consent, you are entitled to withdraw your consent at any time.
- Lodge a complaint: You have the right to lodge a complaint with the supervisory authority, see the details below.
Contact Information
Local Authorities
Sweden
Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY)
website: https://www.imy.se/
Norway
Norwegian Data Protection Authority (Datatilsynet)
website: https://www.datatilsynet.no/
Denmark
Danish Data Protection Agency (Datatilsynet)
website: https://www.datatilsynet.dk/english
Finland
Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto)
website: https://tietosuoja.fi/en/home
3. Categories of Data Subjects
We may process personal data relating to:
- Website visitors
- Job applicants
4. Website Privacy
4.1 Purpose of Processing
When you visit our website, we may process your website data to evaluate, develop and improve our website and our services, in particular for the purpose of:
- Website functionality and security
- Analytics and performance monitoring
- Campaign effectiveness tracking
- Improvement of user experience
4.2 Categories of Personal Data
We may process:
- IP address (anonymised where technically feasible)
- Device and browser metadata
- Date/time and session data
- Page views and interaction data
- Referrer URLs
- Marketing parameters
- Download/click behaviour
- Error logs
- Session interaction data (if applicable)
Where possible, IP addresses are truncated or anonymised immediately upon collection.
4.3 Legal Basis (GDPR Art. 6)
The processing is based on:
- Art. 6(1)(a) GDPR — Consent (where required for non-essential cookies or tracking)
- Art. 6(1)(f) GDPR — Legitimate interest (in the case of strictly necessary cookies our processing is necessary for our legitimate interest to ensure that our website and services are meeting your and our needs over time).
4.4 Retention
We will retain your Personal Data:
- Raw analytics and log data: maximum 12 months from collection.
Retention periods are defined in accordance with ISO 27001 control requirements for information lifecycle management.
4.5 Cookies and Similar Technologies
We use cookies and similar technologies in compliance with the ePrivacy Directive and GDPR. Cookies may include:
- Strictly necessary cookies
- Functional cookies
- Analytics technologies
- Consent management cookies (read more about our cookies in the Cookies setting)
5. Recruitment
5.1 Purpose of Processing
If you submit a job application, we will process your Personal Data in order to administer your application and assess whether to proceed with your application and potentially offer you employment.
5.2 Categories of Personal Data
We may process:
- Name, address, phone number, e-mail address
- CV and application documents including work experience and education background and other information voluntarily provided by you.
- Assessment notes
5.3 Legal Basis
The processing is based on:
- Art. 6(1)(a) — Consent (if you consent to be included in a candidate pool)
- Art. 6(1)(b) — Pre-contractual steps
5.4 Retention
We will retain your Personal Data:
- During active recruitment
- Up to 12 months for candidate pooling (unless consent is withdrawn)
6. Recipients and International Transfers
To fulfill the purposes described above, we may need to share personal data with suppliers when they perform services on our behalf, mainly to support recruitment. See the list below of our engaged processors.
Your personal data is generally only processed within the EU/EEA. In the event the data is transferred to a country outside the EU/EEA, as set out in the list below, we ensure that such transfer is lawful. If the European Commission does not consider that the country ensures an adequate level of protection, the transfer to the third party will be supported by the Commission’s standard contractual clauses and, where applicable, supplemented with additional safeguards. Finally, your personal data may also be transferred to the United States, where applicable, and such transfers are based on the recipient being certified under the EU-US Data Privacy Framework Program.
| Name of processor | Location of Processing | Description of Processing | Corporate Location | DPA |
|---|---|---|---|---|
| Hailey HR | Finland, Sweden | ATS used to evaluate candidates | Sweden | Hailey HR DPA |
| LinkedIn – Recruitment | USA, EU operations in Ireland | Used to link candidate CVs to ATS | USA | LinkedIn DPA |
7. Automated Decision-Making
We do not engage in automated decision-making or profiling within the meaning of GDPR Art. 22, unless explicitly stated and legally permitted.
8. Third-Party Websites
Our website may contain links to third-party websites. Our processing will still be in accordance with this privacy policy, but when you have used these links to leave our site, you should exercise caution and inform yourself of the privacy statement applicable to the website in question. We are not responsible for their data processing practices.
9. Contact Us
If you have any questions about your rights, please feel free to contact us at gdpr@safespring.com