Product

Nova · The loopIt does the work, then it stops and asks

Company

Client case · EskilstunaErgonomic bars, designed and installed worldwide

Findings

Latest · Field researchFour stages, four documents

Security

Security · How it is builtEvery control, and how it is enforced

LegalPrivacy PolicyEffective September 10, 2026

Privacy Policy

Venuvo AB, org. nr 559499‑4484. This is the document as it stands today. When it changes, the effective date above changes with it.

All documents are indexed on the legal page. A Swedish version of this document is available on request from info@venuvo.net.

Language: This policy exists in Swedish and English. In the event of any discrepancy between the versions, the Swedish version prevails. See Section 14.

1. Introduction and scope

Venuvo AB (org.nr 559499-4484), a company registered under the laws of Sweden with its registered office in Örebro, Sweden ("Venuvo AB", "we", "us", or "our"), operates the Venuvo platform — a cloud-based customer relationship management service (the "Service"). This Privacy Policy describes how we collect, use, disclose, retain, and otherwise process personal data in connection with our Service, our website at https://www.venuvo.net (the "Website"), and all related applications, communications, and interactions.

We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Swedish Data Protection Act (dataskyddslagen, SFS 2018:218), the Swedish Electronic Communications Act (2022:482), and all other applicable data protection legislation.

This Privacy Policy applies to all individuals who visit our Website, create an account, use the Service, communicate with us, or otherwise interact with Venuvo. It applies regardless of how you access the Service — whether through a web browser, mobile device, API, or any other means.

This policy is information about how we process personal data. It is not a consent and does not require you to agree to anything. Where we rely on consent, that is stated expressly in Section 5, and such consent is obtained separately and may be withdrawn at any time.

Plain language

This Privacy Policy explains what information we collect about you, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have.

2. Definitions and key terms

Personal Data
Any information relating to an identified or identifiable natural person (a "Data Subject"). An identifiable natural person is one who can be identified, directly or indirectly, by reference to an identifier such as a name, identification number, location data, online identifier, or one or more factors specific to their physical, physiological, genetic, mental, economic, cultural, or social identity.
Data Controller
The entity that determines the purposes and means of the processing of Personal Data. When Venuvo collects your account information directly, Venuvo is the Controller.
Data Processor
The entity that processes Personal Data on behalf of the Data Controller, according to the Controller's instructions. When a Venuvo customer stores their clients' contact information in the Service, Venuvo acts as Processor for that data.
Customer Data
Any data, information, content, records, or material that a Customer or its Authorized Users submits, uploads, imports, or otherwise provides to the Service. This includes contact records, deal information, notes, communications, documents, and files. Customer Data is owned by the Customer, not by Venuvo.
Processing
Any operation or set of operations performed on Personal Data, whether automated or manual. This includes collection, recording, organization, structuring, storage, adaptation, alteration, retrieval, consultation, use, disclosure by transmission, dissemination, alignment, combination, restriction, erasure, and destruction.
Sub-Processor
Any third party engaged by Venuvo to process Personal Data on behalf of a Customer. Our current Sub-Processors, together with their purpose and processing location, are listed in our Sub-Processor List.
Consent
Any freely given, specific, informed, and unambiguous indication of the Data Subject's wishes by which they, by a statement or by a clear affirmative action, signify agreement to the processing of their Personal Data.
Personal Data Breach
A breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored, or otherwise processed. This includes both cyberattacks and accidental incidents such as an employee sending data to the wrong recipient.
Authorized Users
Individuals authorized by a Customer to access and use the Service under that Customer's account, subject to the Customer's subscription limits.

3. Data controller and data processor roles

Venuvo operates in two distinct capacities, and which one applies determines your rights and our obligations.

3.1 Venuvo as Data Controller

We act as Data Controller for Personal Data that we collect and process for our own purposes. This includes:

  • Account registration data: When you sign up for the Service, we collect your name, email address, company name, and other registration details.
  • Billing and payment data: We collect payment information to process your subscription fees.
  • Website visitor data: When you visit our Website, we collect aggregate usage data through our own cookieless, first-party measurement. See our Cookie Policy for how this works.
  • Support and communication data: When you contact our support team, we collect and store the content of your communications.
  • Employment and recruitment data: If you apply for a position at Venuvo, we process your application data as Controller.

As Data Controller, we are responsible for complying with all GDPR obligations, including ensuring lawful processing, implementing security measures, responding to data subject rights requests, and notifying authorities of a Personal Data Breach.

3.2 Venuvo as Data Processor

When a Customer (the "Data Controller") uses the Service to store, manage, and process their end-users' or clients' Personal Data, we act as Data Processor on the Customer's behalf. In this capacity:

  • The Customer decides what Personal Data to collect from their clients and why — they are the Controller.
  • We process Customer Data solely according to the Customer's documented instructions and our Data Processing Agreement (DPA).
  • We do not determine the purposes of processing Customer Data.
  • We do not sell, rent, or use Customer Data for our own purposes, except as necessary to provide the Service.

Example: If a recruitment agency uses Venuvo to store candidate contact information, the agency is the Data Controller and Venuvo is the Data Processor, acting on their instructions under our DPA.

3.3 Why this distinction matters to you

If you are a Venuvo Customer, your rights regarding your account data are exercised directly with us, as we are the Controller.

If you are a contact or end-user of a Venuvo Customer, your data rights should be exercised with the Customer who entered your data — they are the Controller. We will assist the Customer in fulfilling your request in accordance with our DPA.

4. Personal data we collect

We apply the principle of data minimisation — we collect only what is necessary for the specific purpose.

4.1 Data you provide directly

  • Account Information: Name, email address, company name, job title, phone number (optional), and password. If you register on behalf of an organization, we may also collect the organization's name, size, and industry.
  • Billing Information: Billing address, VAT number (for EU business customers), and payment method details. Payment card numbers are processed directly by our payment processor — we do not store complete card numbers on our servers. We retain a tokenized reference and the last four digits of your card for identification purposes.
  • Communications: The content of your communications with us via email, support tickets, chat, or phone, your contact details, and metadata such as timestamps and subject lines.
  • Profile Information: Profile picture, time zone, language preference, and notification settings.
  • Survey and Feedback Data: Responses and comments if you participate in surveys, beta programs, or provide product feedback.

4.2 Data collected automatically

  • Usage Data: Features used, pages and screens visited, actions taken, session duration, and navigation paths within the Service.
  • Device and Technical Data: Device type, operating system and version, browser type and version, and screen resolution.
  • Log Data: Request date and time, referral URL, pages requested, HTTP status codes, and user agent string, retained for security monitoring and troubleshooting. Website measurement does not store your IP address — see Cookie Policy Section 3.3.
  • Cookies and similar technologies: See our Cookie Policy for detailed information about what we use, why, and how to manage your preferences.

4.3 Data from AI-powered features (Nova)

The Service includes AI-powered features ("Nova"). When you use Nova, the content you provide (input) is processed to generate responses and suggestions (output). This processing takes place via our AI Sub-Processors Google LLC (Gemini API) and Lovable Labs Incorporated, which process the content on our instructions and under Standard Contractual Clauses for transfers outside the EEA. See our Sub-Processor List for details.

AI processing of Customer Data to improve or train AI models takes place only where the consent-governed setting for that purpose is enabled. Where the setting is disabled, Customer Data is not used for model training. Aggregated, anonymized usage patterns that do not identify you or any individual may be used to improve the Nova features.

4.4 Customer Data

Customers may upload, submit, import, or otherwise provide Personal Data to the Service. This may include contact information, business information, communication records, deal and transaction information, notes, tags, custom fields, and any other information the Customer chooses to store.

We process Customer Data solely as a Data Processor in accordance with our DPA. The Customer is responsible for ensuring that they have a lawful basis for collecting and storing this data.

4.5 Data we do not collect

We do not knowingly collect:

  • Special categories of Personal Data (Article 9 GDPR), such as data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data, health data, or data concerning a person's sex life or sexual orientation — unless a Customer inputs such data into the Service, in which case the Customer bears responsibility as Controller.
  • Personal data of children under the age of 16 (or the applicable age of consent in the relevant jurisdiction).
  • Social security numbers, national identification numbers, or equivalent government identifiers, unless required for billing or tax compliance.

5. Purposes and legal bases for processing

PurposeData categoriesLegal basis
Providing and maintaining the ServiceAccount Information, Device Data, Usage DataPerformance of a contract, Art. 6(1)(b)
Processing paymentsBilling InformationPerformance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) for tax retention
Customer supportAccount Information, CommunicationsPerformance of a contract, Art. 6(1)(b)
Service improvement and analyticsUsage Data, Log Data (aggregated)Legitimate interest, Art. 6(1)(f)
Website measurement (cookieless)Aggregate usage dataLegitimate interest, Art. 6(1)(f)
Security and fraud preventionLog Data, Device Data, Usage DataLegitimate interest, Art. 6(1)(f)
Legal complianceAs required by lawLegal obligation, Art. 6(1)(c)
Improving or training AI featuresCustomer Data (only where enabled)Consent, Art. 6(1)(a)
Marketing communicationsAccount InformationConsent, Art. 6(1)(a)
Functional cookiesSettings stored on your deviceConsent, Art. 6(1)(a)

Where we rely on legitimate interest we have carried out a balancing assessment and can explain it on request. You have the right to object to such processing under Section 8.6.

Where we rely on consent — AI training, marketing, and functional cookies — that consent is requested separately, is not bundled with acceptance of these terms, and may be withdrawn at any time without affecting the lawfulness of processing carried out beforehand.

Website measurement is cookieless and stores nothing on your device, so it falls outside the consent requirement for cookies in the Swedish Electronic Communications Act (2022:482). You may nevertheless opt out at any time via the cookie banner or 'Cookie settings' in the footer.

6. Data retention

We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, after which it is securely deleted or anonymized.

Data categoryRetention periodReason
Account InformationDuration of account + 12 monthsPost-termination inquiries and legal obligations
Billing Information7 years from transaction dateSwedish Bookkeeping Act (SFS 1999:1078)
Usage Data and Log DataMaximum 24 monthsService improvement and security monitoring
Website measurement dataLimited period, deleted by daily routinesSee Cookie Policy Section 3.3
Nova conversationsStandard 180 days; Pro 365 days; Enterprise duration of subscriptionProviding AI features; storage minimisation by tier
Customer DataDuration of subscription + 90 daysExport period; then permanently deleted per DPA
Support CommunicationsDuration of account + 24 monthsService quality and dispute resolution
Consent recordsDuration of consent + 36 monthsProof of compliance

When the retention period expires, Personal Data is permanently deleted or irreversibly anonymized so that it can no longer be linked to any individual.

Important: If you request deletion of your account, we will delete your Personal Data within 30 days, except for data we are legally required to retain (such as billing records under Swedish bookkeeping law). Customer Data deletion follows the timeline specified in our DPA.

7. Data sharing and international transfers

7.1 Categories of recipients

We may share Personal Data with the following categories of recipients, and only to the extent necessary:

  • Sub-Processors: Third-party service providers who process data on our behalf to help us deliver the Service. All are contractually bound to process data only on our instructions and to implement appropriate security measures. A complete and current listing, with names and processing locations, is set out in our Sub-Processor List.
  • Payment processor: Our payment processor handles payment transactions, governed by its own privacy policy and PCI DSS compliance.
  • AI Sub-Processors: Google LLC (Gemini API) and Lovable Labs Incorporated process Nova inputs and outputs on our instructions, as described in Section 4.3.
  • Professional advisors: Lawyers, accountants, auditors, and other advisors, bound by professional confidentiality obligations.
  • Legal and regulatory authorities: Where disclosure is required by law, regulation, legal process, or enforceable government request. We will notify you of such requests where legally permitted.
  • Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets. We will notify you before your Personal Data becomes subject to a different privacy policy.

We do not sell your Personal Data. We do not share Personal Data with third parties for their own marketing purposes. We do not use Personal Data for targeted advertising.

7.2 International data transfers

Our primary data infrastructure is hosted within the European Union (Stockholm, Sweden). This means that Customer Data and most Account Information is stored within the EU.

In some cases, Personal Data may be transferred to or accessed from countries outside the European Economic Area, where a Sub-Processor operates outside the EU. This applies in particular to our AI Sub-Processors. When such transfers occur, we ensure adequate protection through one or more of the following:

  • Adequacy decisions: Transfers to countries the European Commission has determined provide an adequate level of protection (Article 45 GDPR).
  • Standard Contractual Clauses: EU Commission-approved contractual terms requiring the recipient to protect Personal Data to European standards (Article 46(2)(c) GDPR).
  • Supplementary measures: Additional technical and organizational measures as recommended by the European Data Protection Board, where a transfer impact assessment indicates they are necessary.

You may request a copy of the applicable transfer safeguards by contacting us at the address below.

8. Your rights under the GDPR

8.1 Right of access (Article 15)

You have the right to request confirmation of whether we process your Personal Data and, if so, to receive a copy of that data along with information about the purposes of processing, categories of data, recipients, retention periods, and the source of the data if it was not collected directly from you.

8.2 Right to rectification (Article 16)

You have the right to request that inaccurate Personal Data be corrected and that incomplete Personal Data be completed. For account information, you can usually make corrections directly through your account settings.

8.3 Right to erasure (Article 17)

You have the right to request deletion of your Personal Data in certain circumstances, including when the data is no longer necessary for the purpose it was collected, when you withdraw consent, or when the data has been unlawfully processed. We may retain data where we have a legal obligation to do so, or where it is necessary for the establishment, exercise, or defence of legal claims.

8.4 Right to restriction of processing (Article 18)

You can request that we restrict processing while we verify the accuracy of data you have contested, while we assess whether our legitimate interests override your rights, or where processing is unlawful but you prefer restriction over erasure.

8.5 Right to data portability (Article 20)

You have the right to receive your Personal Data in a structured, commonly used, machine-readable format (such as JSON or CSV) and to transmit that data to another controller. This right applies to data you have provided to us that is processed based on consent or contract, using automated means.

8.6 Right to object (Article 21)

You have the right to object to processing based on legitimate interest. Upon objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims. You have an absolute right to object to processing for direct marketing purposes.

8.7 Right to withdraw consent (Article 7(3))

Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal. You can withdraw consent by adjusting your settings, using the unsubscribe link in marketing emails, or contacting us.

8.8 Right not to be subject to automated decision-making (Article 22)

You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not make any decisions based solely on automated processing that have legal or similarly significant effects on individuals. Nova generates suggestions for you to act on; it does not make decisions about you.

8.9 How to exercise your rights

Contact us at info@venuvo.net. We will verify your identity before processing your request and will respond without undue delay and within one month of receipt. If your request is complex or we receive a large number of requests, we may extend this period by a further two months, in which case we will inform you within the first month.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY") at imy.se, or with any other competent supervisory authority in your EU/EEA member state of residence or place of work.

9. Security measures

We implement technical and organizational measures under Article 32 GDPR to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, alteration, or damage. These include:

  • Encryption: Data is encrypted in transit and at rest.
  • Tenant isolation: Each Customer's data is logically separated from every other Customer's data. One Customer cannot access another Customer's data through the Service.
  • Access controls: Role-based access controls implementing the principle of least privilege. Multi-factor authentication is available for all accounts.
  • Access logging: Access to and modification of Personal Data is logged for security monitoring and investigation.
  • Vulnerability management: Regular security assessments, dependency scanning, and prompt patching of known vulnerabilities.
  • Incident response: Documented incident response procedures with defined escalation paths and notification timelines.
  • Personnel training: All personnel with access to Personal Data receive data protection and security awareness training.

Further detail on our security measures is available to customers on request.

No method of transmission or storage is completely secure. While we work to protect your Personal Data, we cannot guarantee absolute security. If you become aware of a security vulnerability, please report it to us at info@venuvo.net.

10. Personal data breaches

Where a Personal Data Breach occurs, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware of it, to the extent Article 33 GDPR requires. Where the breach is likely to result in a high risk to your rights and freedoms, we notify you without undue delay under Article 34 GDPR. Customers are notified within the timeframes set out in our Data Processing Agreement.

11. Children's privacy

The Service is designed for business use and is not directed to individuals under the age of 16 (or the applicable minimum age in the relevant jurisdiction). We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child without appropriate parental or guardian consent, we will take prompt steps to delete that data. If you believe a child has provided us with Personal Data, please contact us at info@venuvo.net.

12. Third-party links and services

The Service or Website may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any Personal Data to them. The inclusion of a link does not imply endorsement of the linked website or service by Venuvo.

13. Changes to this privacy policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will:

  • Post the updated Privacy Policy on our Website with a revised effective date.
  • Notify you by email at least fourteen (14) days before the changes take effect.
  • Where required by law, obtain your consent before processing your Personal Data under the revised policy.

The version in force at any given time is published on the Website with its effective date.

14. Governing language

This policy exists in Swedish and English. In the event of any discrepancy between the versions, the Swedish version prevails.

15. Contact information

If you have questions, concerns, or requests regarding this Privacy Policy, our data processing practices, or if you wish to exercise any of your data subject rights, please contact us:

Venuvo AB
Org.nr: 559499-4484

Örebro, Sweden

Email: info@venuvo.net

Website: https://www.venuvo.net

For complaints regarding our processing of Personal Data, you may also contact the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): Box 8114, 104 20 Stockholm, Sweden, imy.se

Questions about this document?

Legal and privacy enquiries go to info@venuvo.net and reach a founder, not a queue.

Book a demo /30 min