This policy explains how SvarKlar collects, uses, stores, and shares personal data. It covers website visitors, giveaway entrants, and customers. It also covers two groups who never asked to hear from us: the leads our customers hand us, and business owners we write to ourselves.
1. Who we are
SvarKlar is a brand owned and operated by Store Investeringer ApS, CVR 41622644, Præstemosen 199, 2650 Hvidovre, Denmark. For privacy questions, email frederik@svarklar.com.
2. GDPR applies
SvarKlar is a Danish company, so the EU General Data Protection Regulation (GDPR) applies to everything we do, including work for customers and entrants outside the EU. GDPR gives you clear rights over your data regardless of where you live.
3. The roles we play
For website visitors, giveaway entrants, and data our customers give us directly (their own name, email, billing info), SvarKlar is the data controller. We decide what data is collected and why.
For data about our customers' leads (the names, emails, messages, and details that flow through their website contact forms and inboxes), SvarKlar is a data processor. The customer is the controller. They decide what we do with that data, and we act on their instructions.
For business owners we contact ourselves to introduce SvarKlar, we are the data controller, and you can bring any request straight to us.
4. What we collect
From website visitors
- Name, email, business name, website URL, and any message you submit through a form.
- Page views, button clicks, outbound link clicks, form interactions, and scroll depth.
- Technical context such as the page you used, the referring page, and campaign tags in the link if present.
- If you accept cookies, PostHog uses cookie-based analytics and records how you move through the site. Every form input is masked so we do not capture what you type in a recording.
- If you decline cookies, PostHog still receives cookieless analytics using its privacy-preserving server-side hash. It uses no PostHog cookies and makes no session recording. Cookieless analytics is still analytics processing and may involve personal data or online identifiers under applicable law.
From giveaway entrants
- What you submit in the entry form: your business name, your name, your email, what your business does, an optional description of what you'd like the AI to do, and an optional phone number.
- The date and the exact wording of the rules and privacy agreement you accept, and whether you opted in to receive offers, so we can show your consent if asked.
From customers
- Contact details (name, email, phone, business name, address).
- Billing information (handled by our payment provider once enabled, not stored on our servers beyond what the provider exposes).
- Business context needed to reply well (office hours, service area, escalation contact, tone, pricing posture, the kind of work you do).
- Meta business, WhatsApp Business Account, phone-number, Facebook Page, and Instagram account identifiers, plus encrypted access tokens for the assets you connect.
- Access credentials or forwarding setup for other connected inboxes and channels.
From leads the customer asks us to handle
- Whatever the lead sends through the customer's contact form, inbox, connected WhatsApp, Facebook Messenger, or Instagram business channel: name, email, phone, address, service request, message text, attachments, and any other details they include.
- The replies we send on the customer's behalf.
- Sender and recipient identifiers, attachment metadata, timestamps, delivery and conversation status, intent classification, and a minimal activity log so we can show the customer what we did.
From business owners we contact
We introduce SvarKlar to service businesses in the United States by writing to them once, through the contact form on their own website. If a message like that turned up on your desk, here's where your details came from.
- Your business name, website, email address, phone number, and street address, all taken from your own public website and your Google business listing. Sometimes a first name, when your site publishes one.
- Public details about the business itself, such as your trade, your rating, and how many reviews you have.
- Our own notes on how inquiries seem to be handled at your business, which is what decides whether we write to you at all.
Nobody handed us your details and you never asked to hear from us, so we say that in the message itself and point you here. We write once. Tell us to stop and you come off our list right away, your whole domain with you. We won't ask you to prove who you are first. You can also email frederik@svarklar.com for a copy of what we hold, or to have it deleted.
5. Legal basis for processing
- Contract and steps you ask us to take before a possible contract for a requested call, customer billing, account management, and fulfilling the service we agreed to. For giveaway entrants, accepting the official rules forms a contract, and we process your entry to run and judge the giveaway, select and notify winners, and set up your prize.
- Legitimate interest for securing our systems, improving the service, cookieless website analytics after you decline cookies, and keeping entries in the pool for future selection rounds you agreed to when you entered. The same basis covers one message to a business we think we can help, sent to the contact details that business published itself. You can object to that at any time and we stop.
- Consent for website analytics cookies and session recording, which run only after you accept the cookie notice, and for marketing email, which we send only if you tick the optional offers box when you enter. You can withdraw either consent at any time.
- Customer instruction for data about leads, since the customer is the controller and we follow their rules.
- Legal obligation for records we have to keep under Danish or EU law (for example, billing records for tax purposes).
6. How we use data
- Receive, organize, classify, and reply to leads through the customer's connected website, email, WhatsApp, Facebook Messenger, and Instagram channels.
- Run and judge the giveaway, select and notify winners, and set up prizes.
- Build the activity summaries, reports, and logs we send back to the customer.
- Classify reply intent and escalate leads that need a human.
- Run billing and send service-related communications.
- Measure how the website and service work so we can improve them.
- Secure our systems and detect abuse.
We do not sell personal data. We never use our customers' lead data to market to those leads. If you give a phone number when you enter the giveaway, we use it only for direct, individual contact if you are selected. We never use that number for bulk texts or automated calls.
7. AI-generated replies
OpenAI is currently enabled to organize customer messages and draft replies. It receives the message, supported photos or PDF content needed for the task, the customer's business details, and the reply rules. We keep the original supported files for review, export, and deletion. If a file cannot be read safely, the message waits for a person instead of being answered without that information. Optional model training and environment sharing are turned off. Anthropic is not enabled for this work. Before another AI provider receives customer data, we will update this policy and give any notice required by the signed customer agreement.
Routine replies may be sent directly under the customer's rules. Anything outside those rules goes to a person first. The activity log says which rules were used and whether AI or a person sent the reply.
8. Services we share data with
Each service below receives data when we use the function described for it. Its legal role depends on that function. Where a service acts as a subprocessor for customer-controlled data, the subprocessor terms in the signed customer agreement apply.
- Cloudflare (United States / global): website hosting, the form-submission backend that receives your form entries including giveaway entries before relaying them to us by email, a cookie-free visitor count, and protection and relay for Portal and webhook traffic.
- Hetzner (Germany, EU): encrypted offsite backups and an outage alarm. The service itself runs on our own machine in Denmark, not here.
- Brevo (France, EU): outbound email sending.
- Purelymail (United States): the hello@svarklar.com inbox, form confirmations, Portal sign-in links, billing and service notices, and configured emergency emails. A Meta emergency email contains the owner's email address, business name, a Portal link, and the fact that review is needed. It does not contain the lead's message, attachment, or Meta sender or recipient identifier.
- PostHog (EU region): website analytics. If you accept, it uses cookies for full analytics and session replay. Recordings mask every form input, so PostHog does not receive your typed name, email, phone, or message in a recording. If you decline, it receives cookieless analytics through its privacy-preserving server-side hash, with no PostHog cookies and no replay. Cookieless does not automatically make the processing anonymous or outside data-protection rules.
- Google (United States / global): Gmail connection and mailbox access when a customer connects Google.
- Meta (United States / global): authorization for connected WhatsApp, Facebook Messenger, and Instagram business channels, and carrying messages and replies through those channels.
- OpenAI (Ireland / United States / global): the AI service currently enabled for customer message handling. It receives the message text, supported photos or PDF content, business details, and reply rules needed for the task. Optional model training and environment sharing are turned off. Its privacy policy describes its processing locations and practices.
- Anthropic (United States): a possible future AI provider. It is not enabled for customer message handling.
- Cal.com (United States): scheduling, if you book a call with us.
- Telegram (international): configured operator alerts for new entries and escalation cases. A Meta emergency alert contains the business identifier and the fact that review is needed. It does not contain the lead's message, attachment, or Meta sender or recipient identifier.
- Stripe (United States): card payments, if you pay us. Stripe takes your card details on its own checkout page and we never see or store them.
Not yet active: we plan to use Billy (Denmark, EU) for invoicing once we bill you that way. It processes no personal data today, and we will update this list before it does.
9. International data transfers
Some providers process data outside the EEA, including in the United States. Their terms and privacy notices describe their processing locations and any transfer safeguards they provide. When SvarKlar returns customer-controlled lead data from Denmark to a customer outside the EEA, the customer's signed agreement includes the applicable EU transfer clauses.
10. Retention
- Website analytics and session recordings: analytics events are kept for up to 12 months. Session recordings (accepters only) are kept for 30 days, then deleted.
- Giveaway entries: kept for up to 5 years so we can run the giveaway, award prizes to selected entrants, and keep our records, then deleted. We delete your entry sooner on request.
- Website messages and call-booking enquiries: kept for up to 12 months after the last update. If a customer relationship starts, the details needed for that relationship are kept separately under the customer rules below.
- Customer account details: kept while the customer is active and for up to 2 years after the relationship ends.
- Customer-controlled lead and message data: kept while needed to deliver the service. On cancellation, we stop new processing and begin removing connected-account access. The customer downloads one ZIP that can be uploaded later. We then delete the customer data we use to run the service. Until that final download, the working copy stays frozen and available for export. We do not save another copy of the ZIP. Encrypted backups age out within 90 days.
- Connected Meta access: kept until the customer disconnects the channel or cancels. Disconnecting immediately stops SvarKlar from collecting or sending new messages through that channel. We then remove access at Meta, keeping any access still needed by another connected channel. If removal fails, we retain an encrypted credential only for removal and retry through our daily retention process. It is deleted when removal is confirmed. These credentials and temporary file-download links are excluded from customer exports. Messages and other data already received remain under the customer's instructions and the retention rule above.
- Business owners we contacted: kept for 24 months after we last wrote to you, then the personal details are wiped. One exception. If you asked us to stop, your email address and domain stay on a do-not-contact list for good, because that record is the only thing keeping us from reaching you again by mistake.
- Billing and tax records: kept for 5 years after the end of the financial year, or longer if the law requires it.
11. Your rights
Under GDPR, you can:
- request a copy of the data we hold about you;
- ask us to correct data that is wrong;
- ask us to delete data we no longer need to keep;
- restrict or object to how we process your data;
- withdraw consent (for example, to marketing email) at any time;
- request a portable copy of the data you gave us.
If you are a lead whose data is being handled by SvarKlar on behalf of one of our customers, the customer is the data controller. Please contact the customer directly for access or deletion. We will support the customer in fulfilling your request.
To exercise any of these rights, email frederik@svarklar.com.
12. Security
We use industry-standard security measures: encrypted connections (HTTPS), least-privilege access, credentials stored outside the public repository, and regular backups. No system is perfect. If a breach affects your data, we will notify you in line with GDPR's 72-hour rule where applicable.
13. Cookies and browser storage
This website shows a notice with equally weighted Accept and Decline choices. If you accept, PostHog uses first-party browser storage for full site analytics and session replay. Every form input is masked in recordings. If you decline, PostHog uses no cookies and makes no recording, but it still receives cookieless analytics through its privacy-preserving server-side hash. That does not automatically make the processing anonymous or outside data-protection rules. We do not use cookies for advertising or to track you across other websites.
Use Cookie settings in the footer at any time to change your choice. Switching from Accept to Decline removes SvarKlar's test and visit-attribution storage, tells PostHog to clear its analytics storage in that browser, and stops new cookie-based analytics and recordings. Cookieless analytics continues. Data already received follows the retention periods in section 10 unless you ask us to delete it using the contacts in section 11.
The website uses these browser-storage items:
- PostHog analytics storage, named
ph_<project token>_posthog: a first-party cookie and local-storage copy created only after Accept. The cookie lasts for up to 365 days. It holds browser and session analytics state and enables session replay. Withdrawing consent clears PostHog's stored copy in that browser. - Cookie choice, named
svarklar_cookie_choice: local storage used only to remember Accept or Decline. It remains until you change the choice or clear browser data. - Site-test and visit attribution, named
svarklar_*_variantandsvarklar_attr_*: created only after Accept. Test assignments stay until consent is withdrawn or browser data is cleared. Visit-attribution data clears when the tab closes. - Pending choice, named
svarklar_consent_event_pending: may hold your choice until PostHog finishes loading. It is deleted after the choice event is sent. If PostHog is blocked, it remains until you change your choice or clear browser data.
14. Complaints
If you believe SvarKlar is not handling your data properly, contact us first and we'll try to fix it. You also have the right to complain to the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk, or your local EU data protection authority if you live elsewhere in the EU.
15. Changes
This policy may be updated as the service evolves. The version published here is the current one. We'll refresh the "Last updated" date at the top when we change anything material.
16. Contact
Privacy questions: frederik@svarklar.com.