Effective date: 16 September 2026. This policy replaces the policy dated 18 April 2024.
1. Who we are
Atmoz AB, corporate registration number 559345-4001
Birger Jarlsgatan 57C, 113 56 Stockholm, Sweden
privacy@atmoz.io
For the processing described in this policy, Atmoz AB is the controller: we decide the purposes and the means.
We have not appointed a data protection officer; our processing does not meet the criteria in Article 37(1) GDPR. Data-protection questions are handled at privacy@atmoz.io.
2. What this policy covers
This policy covers personal data Atmoz processes as a controller - our website, our marketing, our business contacts, support enquiries, recruitment, and our own accounting records.
It does not cover personal data inside customer accounts that we process on a customer's behalf when delivering the carbon-accounting service. When we handle financial records, ERP data, invoices or supplier documents for a customer, we act as a processor, and that processing is governed by the data processing agreement with that customer - not by this policy.
That distinction decides who you should contact:
- If you use Atmoz through your employer, or your details appear on an invoice or supplier record one of our customers has uploaded, that organisation is the controller, not Atmoz. Address access, correction and erasure requests to them in the first instance. We assist them under their documented instructions and our data processing agreement; we do not decide their response for them. §9 explains how this works in practice, including what to do if you do not know which organisation holds your data.
- If you have contacted us, subscribed to our newsletter, applied for a job, represent a customer or supplier of ours, or visited atmoz.io, this policy applies and §9 tells you how to exercise your rights.
Two documents sit alongside this one and carry the processor-side detail: the data processing agreement, which describes the platform processing, its security measures and its sub-processors, and the sub-processor register at atmoz.io/subprocessors, which is maintained to name each provider that processes customer personal data on Atmoz's behalf, what it processes, where, and which transfer mechanism applies. A copy of the data processing agreement is available from privacy@atmoz.io.
The platform does not detect, redact or filter personal data out of document text. Text is processed as printed on the document, which can include a person's name - so what reaches the platform is determined by the customer who submits it.
3. Personal data we collect
| Who you are | What we process |
|---|---|
| Customer and supplier representatives | Name, telephone number, email address, role |
| Newsletter subscribers | Name, email address |
| People who contact support | Name, email address, telephone number, and whatever the message contains |
| Job applicants | Name, contact details, qualifications, references, interview notes |
| Website visitors | Usage statistics from atmoz.io, where you consent - see §7 |
| Anyone named in our own accounting records | Name and contact details as they appear on invoices, receipts and other accounting material we issue or receive |
Where the details come from. We usually obtain representative contact details from you directly. Where we do not, they come from the organisation that employs you - a colleague giving us your details as the right contact - from a public company or business register such as Bolagsverket, or from a business contact who referred us. Job applicants' details come from the applicant, and from referees the applicant names. Details in our own accounting records come from the organisation that issued or received the document: an invoice we receive names the people its issuer chose to put on it.
Our own accounting records are not the same as customer documents. The last row above concerns Atmoz's own books - the invoices and receipts we issue and receive as a business, where we are the controller. Accounting documents that a customer uploads to the platform are a different matter entirely: there the customer is the controller, we are the processor, and the data processing agreement applies. See §2.
Support correspondence, and documents sent with it. We are the controller of our own support correspondence - who wrote to us, when, and what was asked and answered. That does not make us controller of customer-controlled material that happens to be attached to a support case: a document from a customer's account, sent to us to illustrate a problem, remains that customer's data under their data processing agreement, and we handle it on their instructions. Administering a support inbox does not convert processor data into controller data.
Whether you have to provide it. For business contacts and job applicants, providing contact details is not a statutory requirement on you, but it is necessary in order for us to enter into or perform the relationship - we cannot administer a contract without a contact person, or assess an application without an application. If you do not provide it, we cannot do those things. Where your details appear in our accounting records, retaining them is a statutory obligation on us under the Swedish Bookkeeping Act, whether or not you provided them to us directly.
4. Why we use it, and on what basis
| Who | Why | Legal basis |
|---|---|---|
| Customer and supplier representatives | Managing the business relationship | Legitimate interest - maintaining the commercial relationship with the organisation you represent, including contacting the right person about orders, invoices, service notices and contract administration |
| Newsletter subscribers | Sending the newsletter | Consent, withdrawable at any time |
| Support enquiries | Answering the enquiry | Legitimate interest - answering people who choose to contact us, and keeping a record of what was asked and answered. Note the limit in §3 on documents sent with a support case |
| Job applicants | Assessing the application | Legitimate interest - assessing your suitability for the role you applied for, and keeping a record of the decision. Where we make you an offer, the later contract stage rests on Article 6(1)(b) |
| Website visitors | Statistics about how the site is used | Consent |
| Anyone named in our own accounting records | Keeping our own books and meeting statutory accounting obligations | Legal obligation, Article 6(1)(c) - the Swedish Bookkeeping Act (bokföringslagen 1999:1078) |
Where we rely on legitimate interest, you have the right to object at any time. Write to privacy@atmoz.io and tell us what you object to. We stop unless we can show compelling legitimate grounds that override your interests, rights and freedoms.
Automated decision-making. In the processing described in this policy we do not take decisions about you based solely on automated processing - including profiling - that produce legal effects concerning you or similarly significantly affect you. Whether a customer's own use of the platform involves automated decision-making under Article 22 is a question for that customer as controller, not for Atmoz.
We do not sell personal data, and we do not share it for advertising purposes.
5. Who we share it with
For the data described in this policy, the categories of recipient are: our website analytics provider (where you consent - see §7), and our email, CRM and recruitment tooling.
The terms governing each recipient follow the role it actually holds - our processor, or an independent controller acting for its own purposes - rather than the category heading above.
We also disclose personal data where we are required to by law, or where it is necessary to establish, exercise or defend legal claims.
Recipients that also process customer platform data are named individually at atmoz.io/subprocessors; that register is maintained to cover every third-party provider processing customer personal data on Atmoz's behalf in delivering the platform, however that provider is purchased, integrated or used.
6. Transfers outside the EU/EEA
Where a recipient is established outside the EU/EEA, or processes the data there, we assess the transfer and select the safeguard by reference to the actual receiving entity, the destination country and the processing that takes place there - not by where a corporate group has its headquarters. A parent company's location or certification does not automatically cover its subsidiaries, and these mechanisms are not a ranked hierarchy applied by corporate structure:
- An adequacy decision applies only within its own scope - the countries, and in some cases the categories of recipient or data, that the decision actually covers.
- We rely on the EU-US Data Privacy Framework only where the actual US recipient and the relevant processing are covered by a valid certification, including where the recipient is expressly identified as a covered entity. Group affiliation alone is insufficient - a certification held somewhere in a corporate group does not by itself cover a given recipient.
- EU Standard Contractual Clauses, where they apply, are accompanied by an assessment of the transfer and of the law and practice in the destination country, with supplementary measures where that assessment shows they are needed.
Information about the applicable safeguards, and copies of the relevant instruments where appropriate, can be requested from privacy@atmoz.io - subject to redaction of commercial terms and of third parties' personal data.
Transfers arising from the platform processing we carry out as a processor are assessed the same way; the mechanism applying to each sub-processor is stated at atmoz.io/subprocessors and in the data processing agreement.
7. Cookies and website analytics
Consent for storing information on, or reading it from, your device is obtained under the Swedish Electronic Communications Act (lag 2022:482, ch. 9 § 28), which implements Article 5(3) of the ePrivacy Directive. Strictly-necessary storage is exempt from that consent requirement and is used only for the purposes listed in the Cookie Policy; we do not ask for consent to it. The Article 6 basis in §4 governs what we then do with the data.
For website analytics on atmoz.io, these commitments hold regardless of which analytics tool we use:
- Analytics runs only after you consent to it, and you can change or withdraw that consent at any time from the link in the site footer.
- Analytics data is not used for advertising, is not associated with accounts you hold elsewhere, and is not used to track you across devices or sites.
- Analytics data is retained for a short, capped period, stated in the Cookie Policy.
- We do not reconstruct or model the behaviour of visitors who declined.
The analytics tool currently in use, its configuration and its retention periods are stated in the Cookie Policy, which we keep current as tooling changes.
Your cookie-consent choice is stored in your browser until you withdraw it, clear your browser storage, or the cookie-consent version changes.
Browser storage in the platform is a separate matter and is not covered by this policy. It is functional only - login session, interface preferences, integration authorisation flows - and is described in the data processing agreement.
Full detail: Cookie Policy.
8. How long we keep it
| Data | Period | From |
|---|---|---|
| Customer and supplier contacts | 24 months after the end of the business relationship. Where the same details also appear in our accounting records, the last row applies to that copy | End of the business relationship |
| Newsletter subscribers | Until you unsubscribe | - |
| Support enquiries | Atmoz-controlled support correspondence: 24 months after closure of the enquiry. Customer-controlled documents or content supplied to investigate a platform issue remain subject to the customer's documented instructions and the applicable data processing agreement; this 24-month period does not independently authorise their retention | Closure of the enquiry |
| Job applicants | 2 years after conclusion of the recruitment process, aligned to the limitation period for claims under the Swedish Discrimination Act (diskrimineringslagen 2008:567). Applications kept longer for future recruitment only with the applicant's consent | Conclusion of the recruitment |
| Cookie-consent record | Until you withdraw it, clear your browser storage, or the cookie-consent version changes | The date of your choice |
| Website analytics data | A short, capped period stated in the Cookie Policy | The recorded activity |
| Details in our own accounting records | 7 years after the end of the calendar year in which the financial year ended, as required by the Swedish Bookkeeping Act (bokföringslagen 1999:1078) | End of that financial year |
Retention of customer platform data is set by the customer's agreement with us and is described in the data processing agreement, not here.
Anonymisation is not a substitute for deletion. Removing a name, masking a field or replacing an identifier with a pseudonym is not anonymisation - data that can still be linked back to a person remains personal data, and the deletion obligation still attaches to it.
9. Your rights
You have the right of access to your personal data, and the rights to rectification, erasure, restriction of processing, data portability and objection. These rights apply subject to the conditions and exceptions the GDPR attaches to each of them - they are not absolute, and which apply depends on the processing and its legal basis. Data portability in particular applies only where the processing rests on consent or on a contract and is carried out by automated means.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before you withdrew.
Where we rely on legitimate interest - the business contacts, support enquiries and recruitment described in §4 - you have the right to object at any time.
Which route applies depends on who the controller is.
If your data is covered by this policy - our website, marketing, support or recruitment - contact privacy@atmoz.io. We respond without undue delay and, in any event, within one month. Where necessary, taking account of the complexity and number of requests, we may extend this period by up to two further months. We will inform you of the extension and its reasons within the first month.
If your data is inside a customer's account - invoice contents, supplier contacts, or an account your employer gave you - the customer whose account holds the data is the controller, and your request should normally be addressed to them: they decide how it is answered. We assist them under their documented instructions and our data processing agreement, and that assistance can include searching for, retrieving, correcting or deleting data within their account where they instruct us to and the request is properly scoped to their data. What we do not do is decide their response for them, or search across other customers' accounts - no customer's instructions authorise us to look inside another's data.
If you do not know which organisation holds your data, write to us and we will help you reach them. Send whatever identifies the document - an invoice number and date, the supplier name as it appears on it, or the company you believe uploaded it. Where we can identify the controller, we will pass your request to them and ask them to respond to you directly. We cannot confirm whether a particular organisation is an Atmoz customer, because that is itself confidential; but that does not leave you without a route, and we will tell you what we have done.
Where a request concerns data we hold, we may ask for enough information to satisfy ourselves who you are before we act, so that we do not disclose personal data to the wrong person. What is proportionate depends on the request and the sensitivity of the data - often it is no more than confirming details we already hold. We ask for identity documents only where the circumstances genuinely require it.
You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se, or with the supervisory authority where you live or work.
Questions about this policy or our processing of personal data can be sent to privacy@atmoz.io.
10. Security
Atmoz operates an information security management system covering access control, logging and monitoring, incident response, secure development, data classification and retention, and vendor risk management. Its policies are documented, applied and maintained.
Durable commitments, independent of any particular tool or vendor:
- Encryption. Personal data is encrypted in transit and at rest.
- Identity. Authentication is provided by a dedicated identity provider operating within the EU/EEA. The platform operates no password store of its own.
- Access control. Access is role-based and limited to the personnel who need it for their work.
- Network posture. Backend services are not exposed to the public internet; all traffic reaches them through a controlled entry point.
The technical and organisational measures applying to customer platform data - access management, backup and recovery, logging, and vulnerability management - are set out in the data processing agreement, together with the three routes by which customer data can be reached.
11. If something goes wrong
Our documented incident response policy commits to the following.
| Event | Who we notify | Timeframe |
|---|---|---|
| A breach where Atmoz is the controller, unless it is unlikely to result in a risk to people's rights and freedoms | The Swedish Authority for Privacy Protection (IMY) | Without undue delay and, where feasible, within 72 hours of becoming aware. Where notification is made later, the reasons for the delay accompany it |
| A breach where Atmoz is the controller that is likely to result in a high risk to people's rights and freedoms | The affected individuals | Without undue delay, under Article 34 |
| A breach affecting a customer's data, where Atmoz is a processor | That customer | Without undue delay after becoming aware, as Article 33(2) requires - that is the commitment. Our target is to notify within 24 hours. The exact contractual terms are set in the data processing agreement |
We notify with the information available at the time rather than waiting for the investigation to conclude, and supplement it without undue further delay as more becomes known. Notification carries the information required by Article 33(3) to the extent known.
The 72-hour deadline in Article 33 is the controller's. Where we act as a processor it is our customer's, not ours: it runs from the moment that customer becomes aware, which our notification is intended to bring about promptly - though we cannot guarantee how much of their deadline will remain. We do not claim a 72-hour allowance of our own. We assist the customer in investigating the breach and, where they must inform data subjects under Article 34, in doing so - but the decision to notify a regulator or affected individuals, and the notification itself, remain the customer's as controller unless they authorise us to act.
For the data covered by this policy, the first two rows are our own obligations, and we discharge them ourselves.
12. Changes to this policy
We update the effective date above when this policy changes. Where a change materially affects your rights, we give active notice rather than relying on the date alone. Changes to the sub-processors handling customer platform data follow the notice period set in the data processing agreement.
Previous versions of this policy are available on request from privacy@atmoz.io.
