DoCRA

Legal

Privacy Policy

Draft – last updated 29 September 2026

Svenska

1. Who we are and how to contact us

{{COMPANY_LEGAL_NAME}} (org. no. {{ORG_NUMBER}}), {{REGISTERED_ADDRESS}}, is the data controller for the personal data described in this policy. Contact: DoCRA, hello@docra.eu.

2. What data we collect

  • Scope check: name, company, work email, optional product name, country, company size and your answers.
  • Contact form and partner form: name, company, email, phone number (optional) and your message.
  • Customers: contact details, invoicing details and the technical information you share for the gap analysis, such as product and firmware details and notes from discovery calls.
  • Website analytics: cookieless and aggregated. We do not build personal profiles.
  • Admin login: the email address used to send the sign-in link.

3. Purposes and legal bases (GDPR Art. 6)

  • Answering requests and following up on the scope check: legitimate interest in business-to-business contact, together with the checkbox where you agree to be contacted.
  • Delivering paid services: performance of a contract.
  • Invoicing and bookkeeping: legal obligation.
  • Improving the site: legitimate interest, using aggregated analytics only.

4. AI processing

Drafts of gap reports are generated with an AI model based on the scope check answers and our notes from calls with you. Every report is reviewed by a person before it is sent. No decisions with legal or similarly significant effects are made automatically.

5. Recipients and processors

We use the following categories of providers. They act only on our instructions under data processing agreements.

  • Hosting and database: {{HOSTING_AND_DATABASE_PROVIDER}}
  • Website platform: {{WEBSITE_PLATFORM_PROVIDER}}
  • AI model provider: {{AI_MODEL_PROVIDER}}
  • Email provider: {{EMAIL_PROVIDER}}
  • Analytics provider: {{ANALYTICS_PROVIDER}}

6. Transfers outside the EU/EEA

Some providers may process data outside the EU/EEA. Such transfers rely on the EU–US Data Privacy Framework or the European Commission's standard contractual clauses.

7. How long we keep data

  • Leads and scope check results: up to 24 months after the last contact.
  • Customer data: for the duration of the engagement plus 24 months.
  • Accounting records: 7 years, as required by the Swedish Bookkeeping Act.
  • Opt-outs: kept as a suppression record so that we do not contact you again.

8. Your rights

You have the right to access, rectification, erasure, restriction of processing, objection (including to direct marketing, at any time), data portability and to withdraw your consent. Email us at hello@docra.eu to exercise your rights.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.

9. Security

Access to personal data is limited to admins. Data is encrypted in transit and database access is role-based.

10. Changes to this policy

We may update this policy. The date at the top of the page shows when it was last changed.

These terms are a draft and will be reviewed by a lawyer.