Privacy Policy
Last updated: 1 January 2026
1. Controller
Algorythm AB, a company registered in Sweden ("Algorythm", "we", "us", or "our"), is the data controller responsible for your personal data processed in connection with this website and our services.
If you have any questions or concerns about this Privacy Policy or our data practices,
please contact us at:
info@algorythm.se
2. Data We Collect
We may collect and process the following categories of personal data:
- Contact data: name, corporate email address, job title, company name.
- Inquiry data: the content of messages you submit through our contact form, including the service category and briefing details you provide.
- Technical data: IP address, browser type and version, operating system, and pages visited, collected automatically through server logs for security and operational purposes.
We do not collect sensitive personal data (such as health, biometric, or financial data) through this website.
3. Legal Bases and Purposes
We process your personal data on the following legal bases under the General Data Protection Regulation (GDPR):
Legitimate interests (Art. 6(1)(f) GDPR)
To respond to your inquiry, to communicate about potential engagements, and to maintain the security and performance of our website.
Performance of a contract (Art. 6(1)(b) GDPR)
Where processing is necessary to take pre-contractual steps at your request or to perform a contract to which you are a party.
Compliance with legal obligations (Art. 6(1)(c) GDPR)
Where processing is required to comply with applicable Swedish or EU law.
4. How We Use Your Data
We use collected data to:
- Respond to and follow up on consultation inquiries.
- Assess the fit between your technical challenge and our services.
- Maintain our legitimate business communications and records.
- Secure and improve the operation of this website.
- Comply with legal and regulatory requirements.
We do not use your data for automated decision-making or profiling.
5. Data Sharing
We do not sell, rent, or trade your personal data to third parties. We may share data with trusted service providers (such as cloud infrastructure or email delivery providers) solely to operate our services, under data processing agreements that require them to protect your data in accordance with GDPR.
We may disclose personal data if required to do so by law or a competent authority, or where disclosure is necessary to protect the rights, property, or safety of Algorythm AB, our clients, or others.
6. International Transfers
This website is operated from Sweden and intended for recipients located within the European Economic Area (EEA). If any data is transferred outside the EEA, we ensure appropriate safeguards are in place in accordance with Chapter V of the GDPR (e.g., Standard Contractual Clauses).
7. Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this policy, or as required by law. Inquiry data from prospective clients that does not lead to an engagement is deleted within 12 months. Data related to active or past engagements is retained for the period required by applicable Swedish accounting and tax law (generally 7 years).
8. Your Rights
Under GDPR you have the following rights with respect to your personal data:
- Right of access – to obtain confirmation of whether we process your data and receive a copy.
- Right to rectification – to have inaccurate data corrected.
- Right to erasure – to request deletion of your data where there is no overriding legal basis to retain it.
- Right to restriction – to request that we limit the processing of your data.
- Right to data portability – to receive your data in a structured, machine-readable format.
- Right to object – to object to processing based on legitimate interests.
- Right to withdraw consent – where processing is based on consent, to withdraw it at any time without affecting prior processing.
To exercise any of these rights, please contact us at info@algorythm.se. We will respond within 30 days. You also have the right to lodge a complaint with the Swedish Data Protection Authority (Integritetsskyddsmyndigheten, IMY) at imy.se.
9. Cookies and Tracking
This website uses only technically necessary cookies required for server-side rendering and session integrity. We do not use advertising, analytics, or third-party tracking cookies. No cookie consent banner is required for strictly necessary cookies under ePrivacy rules.
10. Security
We implement appropriate technical and organisational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access, in accordance with Art. 32 GDPR.
11. Changes to this Policy
We may update this Privacy Policy from time to time. Material changes will be indicated by an updated "Last updated" date at the top of the page. Continued use of our website after any changes constitutes your acknowledgement of the revised policy.