Den utför arbetet, och stannar sedan för att fråga
Nova läser er arbetsyta, redovisar varje anrop den gjort, och föreslår ändringen. Ingenting skrivs förrän en människa bekräftar det.
↳ Se förloppetProdukt

Legal / Privacy PolicyEffective September 10, 2026
Venuvo AB, org. nr 559499‑4484. This is the document as it stands today. When it changes, the effective date above changes with it.
All documents are indexed on the legal page. A Swedish version of this document is available on request from info@venuvo.net.
Language: This policy exists in Swedish and English. In the event of any discrepancy between the versions, the Swedish version prevails. See Section 14.
Venuvo AB (org.nr 559499-4484), a company registered under the laws of Sweden with its registered office in Örebro, Sweden ("Venuvo AB", "we", "us", or "our"), operates the Venuvo platform — a cloud-based customer relationship management service (the "Service"). This Privacy Policy describes how we collect, use, disclose, retain, and otherwise process personal data in connection with our Service, our website at https://www.venuvo.net (the "Website"), and all related applications, communications, and interactions.
We process personal data in accordance with Regulation (EU) 2016/679 (the General Data Protection Regulation, "GDPR"), the Swedish Data Protection Act (dataskyddslagen, SFS 2018:218), the Swedish Electronic Communications Act (2022:482), and all other applicable data protection legislation.
This Privacy Policy applies to all individuals who visit our Website, create an account, use the Service, communicate with us, or otherwise interact with Venuvo. It applies regardless of how you access the Service — whether through a web browser, mobile device, API, or any other means.
This policy is information about how we process personal data. It is not a consent and does not require you to agree to anything. Where we rely on consent, that is stated expressly in Section 5, and such consent is obtained separately and may be withdrawn at any time.
This Privacy Policy explains what information we collect about you, why we collect it, how we use it, who we share it with, how long we keep it, and what rights you have.
Venuvo operates in two distinct capacities, and which one applies determines your rights and our obligations.
We act as Data Controller for Personal Data that we collect and process for our own purposes. This includes:
As Data Controller, we are responsible for complying with all GDPR obligations, including ensuring lawful processing, implementing security measures, responding to data subject rights requests, and notifying authorities of a Personal Data Breach.
When a Customer (the "Data Controller") uses the Service to store, manage, and process their end-users' or clients' Personal Data, we act as Data Processor on the Customer's behalf. In this capacity:
Example: If a recruitment agency uses Venuvo to store candidate contact information, the agency is the Data Controller and Venuvo is the Data Processor, acting on their instructions under our DPA.
If you are a Venuvo Customer, your rights regarding your account data are exercised directly with us, as we are the Controller.
If you are a contact or end-user of a Venuvo Customer, your data rights should be exercised with the Customer who entered your data — they are the Controller. We will assist the Customer in fulfilling your request in accordance with our DPA.
We apply the principle of data minimisation — we collect only what is necessary for the specific purpose.
The Service includes AI-powered features ("Nova"). When you use Nova, the content you provide (input) is processed to generate responses and suggestions (output). This processing takes place via our AI Sub-Processors Google LLC (Gemini API) and Lovable Labs Incorporated, which process the content on our instructions and under Standard Contractual Clauses for transfers outside the EEA. See our Sub-Processor List for details.
AI processing of Customer Data to improve or train AI models takes place only where the consent-governed setting for that purpose is enabled. Where the setting is disabled, Customer Data is not used for model training. Aggregated, anonymized usage patterns that do not identify you or any individual may be used to improve the Nova features.
Customers may upload, submit, import, or otherwise provide Personal Data to the Service. This may include contact information, business information, communication records, deal and transaction information, notes, tags, custom fields, and any other information the Customer chooses to store.
We process Customer Data solely as a Data Processor in accordance with our DPA. The Customer is responsible for ensuring that they have a lawful basis for collecting and storing this data.
We do not knowingly collect:
| Purpose | Data categories | Legal basis |
|---|---|---|
| Providing and maintaining the Service | Account Information, Device Data, Usage Data | Performance of a contract, Art. 6(1)(b) |
| Processing payments | Billing Information | Performance of a contract, Art. 6(1)(b); legal obligation, Art. 6(1)(c) for tax retention |
| Customer support | Account Information, Communications | Performance of a contract, Art. 6(1)(b) |
| Service improvement and analytics | Usage Data, Log Data (aggregated) | Legitimate interest, Art. 6(1)(f) |
| Website measurement (cookieless) | Aggregate usage data | Legitimate interest, Art. 6(1)(f) |
| Security and fraud prevention | Log Data, Device Data, Usage Data | Legitimate interest, Art. 6(1)(f) |
| Legal compliance | As required by law | Legal obligation, Art. 6(1)(c) |
| Improving or training AI features | Customer Data (only where enabled) | Consent, Art. 6(1)(a) |
| Marketing communications | Account Information | Consent, Art. 6(1)(a) |
| Functional cookies | Settings stored on your device | Consent, Art. 6(1)(a) |
Where we rely on legitimate interest we have carried out a balancing assessment and can explain it on request. You have the right to object to such processing under Section 8.6.
Where we rely on consent — AI training, marketing, and functional cookies — that consent is requested separately, is not bundled with acceptance of these terms, and may be withdrawn at any time without affecting the lawfulness of processing carried out beforehand.
Website measurement is cookieless and stores nothing on your device, so it falls outside the consent requirement for cookies in the Swedish Electronic Communications Act (2022:482). You may nevertheless opt out at any time via the cookie banner or 'Cookie settings' in the footer.
We retain Personal Data only for as long as necessary to fulfil the purposes for which it was collected, after which it is securely deleted or anonymized.
| Data category | Retention period | Reason |
|---|---|---|
| Account Information | Duration of account + 12 months | Post-termination inquiries and legal obligations |
| Billing Information | 7 years from transaction date | Swedish Bookkeeping Act (SFS 1999:1078) |
| Usage Data and Log Data | Maximum 24 months | Service improvement and security monitoring |
| Website measurement data | Limited period, deleted by daily routines | See Cookie Policy Section 3.3 |
| Nova conversations | Standard 180 days; Pro 365 days; Enterprise duration of subscription | Providing AI features; storage minimisation by tier |
| Customer Data | Duration of subscription + 90 days | Export period; then permanently deleted per DPA |
| Support Communications | Duration of account + 24 months | Service quality and dispute resolution |
| Consent records | Duration of consent + 36 months | Proof of compliance |
When the retention period expires, Personal Data is permanently deleted or irreversibly anonymized so that it can no longer be linked to any individual.
Important: If you request deletion of your account, we will delete your Personal Data within 30 days, except for data we are legally required to retain (such as billing records under Swedish bookkeeping law). Customer Data deletion follows the timeline specified in our DPA.
We may share Personal Data with the following categories of recipients, and only to the extent necessary:
We do not sell your Personal Data. We do not share Personal Data with third parties for their own marketing purposes. We do not use Personal Data for targeted advertising.
Our primary data infrastructure is hosted within the European Union (Stockholm, Sweden). This means that Customer Data and most Account Information is stored within the EU.
In some cases, Personal Data may be transferred to or accessed from countries outside the European Economic Area, where a Sub-Processor operates outside the EU. This applies in particular to our AI Sub-Processors. When such transfers occur, we ensure adequate protection through one or more of the following:
You may request a copy of the applicable transfer safeguards by contacting us at the address below.
You have the right to request confirmation of whether we process your Personal Data and, if so, to receive a copy of that data along with information about the purposes of processing, categories of data, recipients, retention periods, and the source of the data if it was not collected directly from you.
You have the right to request that inaccurate Personal Data be corrected and that incomplete Personal Data be completed. For account information, you can usually make corrections directly through your account settings.
You have the right to request deletion of your Personal Data in certain circumstances, including when the data is no longer necessary for the purpose it was collected, when you withdraw consent, or when the data has been unlawfully processed. We may retain data where we have a legal obligation to do so, or where it is necessary for the establishment, exercise, or defence of legal claims.
You can request that we restrict processing while we verify the accuracy of data you have contested, while we assess whether our legitimate interests override your rights, or where processing is unlawful but you prefer restriction over erasure.
You have the right to receive your Personal Data in a structured, commonly used, machine-readable format (such as JSON or CSV) and to transmit that data to another controller. This right applies to data you have provided to us that is processed based on consent or contract, using automated means.
You have the right to object to processing based on legitimate interest. Upon objection, we will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or where processing is necessary for legal claims. You have an absolute right to object to processing for direct marketing purposes.
Where processing is based on consent, you may withdraw your consent at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal. You can withdraw consent by adjusting your settings, using the unsubscribe link in marketing emails, or contacting us.
You have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects you. We do not make any decisions based solely on automated processing that have legal or similarly significant effects on individuals. Nova generates suggestions for you to act on; it does not make decisions about you.
Contact us at info@venuvo.net. We will verify your identity before processing your request and will respond without undue delay and within one month of receipt. If your request is complex or we receive a large number of requests, we may extend this period by a further two months, in which case we will inform you within the first month.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, "IMY") at imy.se, or with any other competent supervisory authority in your EU/EEA member state of residence or place of work.
We implement technical and organizational measures under Article 32 GDPR to protect Personal Data against unauthorized or unlawful processing, accidental loss, destruction, alteration, or damage. These include:
Further detail on our security measures is available to customers on request.
No method of transmission or storage is completely secure. While we work to protect your Personal Data, we cannot guarantee absolute security. If you become aware of a security vulnerability, please report it to us at info@venuvo.net.
Where a Personal Data Breach occurs, we notify the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware of it, to the extent Article 33 GDPR requires. Where the breach is likely to result in a high risk to your rights and freedoms, we notify you without undue delay under Article 34 GDPR. Customers are notified within the timeframes set out in our Data Processing Agreement.
The Service is designed for business use and is not directed to individuals under the age of 16 (or the applicable minimum age in the relevant jurisdiction). We do not knowingly collect Personal Data from children. If we become aware that we have collected Personal Data from a child without appropriate parental or guardian consent, we will take prompt steps to delete that data. If you believe a child has provided us with Personal Data, please contact us at info@venuvo.net.
The Service or Website may contain links to third-party websites, applications, or services. We are not responsible for the privacy practices of these third parties. We encourage you to review their privacy policies before providing any Personal Data to them. The inclusion of a link does not imply endorsement of the linked website or service by Venuvo.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, or legal requirements. When we make material changes, we will:
The version in force at any given time is published on the Website with its effective date.
This policy exists in Swedish and English. In the event of any discrepancy between the versions, the Swedish version prevails.
If you have questions, concerns, or requests regarding this Privacy Policy, our data processing practices, or if you wish to exercise any of your data subject rights, please contact us:
Venuvo AB
Org.nr: 559499-4484
Örebro, Sweden
Email: info@venuvo.net
Website: https://www.venuvo.net
For complaints regarding our processing of Personal Data, you may also contact the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY): Box 8114, 104 20 Stockholm, Sweden, imy.se
Legal and privacy enquiries go to info@venuvo.net and reach a founder, not a queue.