This Policy applies to personal data processed by Kader Cadre AB ("INTYGIO", "we", "us") in two contexts:
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| IP address, browser type, pages visited, timestamps | Web analytics; security and abuse prevention | Art. 6(1)(f) — Legitimate interests (operating a secure, functional website) | 90 days |
| Name, e-mail address, company, message (contact form) | Responding to enquiries; pre-contractual communication | Art. 6(1)(b) — Pre-contractual steps at your request; or Art. 6(1)(f) — Legitimate interests | 24 months from last contact, unless a contract is entered |
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| Name, work e-mail address, phone number | Account management; service communications; support | Art. 6(1)(b) — Performance of contract | Duration of contract + 3 years |
| Company name, VAT/organisation number, billing address | Contract performance; invoicing; statutory accounting obligations | Art. 6(1)(b) — Contract; Art. 6(1)(c) — Legal obligation (Swedish Accounting Act) | 7 years (accounting records) |
| API usage logs (timestamps, endpoint, volume — no payload content) | Usage-based billing; service quality; security monitoring | Art. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interests | 13 months |
| Support communications (e-mail, messages) | Resolving support requests; service improvement | Art. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interests | 24 months from resolution |
Anyone can present a product passport to the INTYGIO API for verification, for example by scanning a QR code. The request reaches INTYGIO directly from the scanner's device. For this data INTYGIO is the Controller: verification requests are generated by third parties and are not Customer Data under the Terms of Service.
| Data | Purpose | Legal Basis | Retention |
|---|---|---|---|
| IP address of the requesting device, time of the request, the passport verified, the verification result | Detecting abuse and cloned passports (for example the same passport verified from an unusual number of addresses); aggregate verification statistics provided to the Customer that issued the passport | Art. 6(1)(f) — Legitimate interests (integrity of the verification service; the issuer's interest in knowing how its passports are used) | 13 months, after which the record is deleted |
Statistics provided to a Customer are aggregated. No individual verification request, and no IP address, is disclosed to a Customer or to any other party except as required by law. INTYGIO does not derive location from these addresses today; should country-level statistics be introduced, they will be derived from the same data, for the same purposes, and this Policy will be updated first.
We do not sell, rent, or trade personal data. We share data only with the following categories of recipients:
| Recipient | Role | Purpose | Location |
|---|---|---|---|
| Inleed AB | Sub-processor (web hosting and e-mail) | Hosting of the intygio.com website; mailboxes for legal@ and security@intygio.com | Sweden, EU |
| Brevo SAS | Sub-processor (transactional e-mail) | Delivery of sign-in links and account e-mail to API customer account holders | France, EU |
| DigiCert Europe Netherlands B.V. | EU Qualified Trust Service Provider (QTSP) | Qualified electronic seal certificate (QSealC) issuance and remote signing | Netherlands (EU) |
| Competent authorities | Required by law | Compliance with legal obligations (e.g. IMY, tax authorities, courts) | EU / Sweden |
All sub-processors are bound by data processing agreements that impose GDPR-equivalent obligations. The current list of sub-processors, with a dated change log, is published at intygio.com/legal/subprocessors.
The INTYGIO API runs on infrastructure operated by INTYGIO in Sweden. The website host, the qualified trust service provider, and the e-mail provider are established within the European Economic Area. At the time of this Policy's publication, no transfers of personal data to countries outside the EEA take place.
Should a third-party engagement require an EEA transfer in the future, INTYGIO will put in place appropriate safeguards (Standard Contractual Clauses pursuant to Art. 46 GDPR, or an adequacy decision) and update this Policy prior to any such transfer commencing.
As a data subject, you have the following rights under GDPR Arts. 15–22. Requests should be submitted to privacy@intygio.com. We will respond within one calendar month (Art. 12(3)).
We implement technical and organisational measures appropriate to the risk posed by the processing activities described in this Policy. These include access controls, encryption of data in transit and at rest, audit logging, and periodic security reviews. Our measures are documented in detail in our Data Processing Agreement (available to customers on request).
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay in accordance with Art. 34 GDPR.
INTYGIO uses a minimal set of cookies and similar technologies on intygio.com. We do not use third-party advertising cookies or cross-site tracking.
| Category | Purpose | Legal Basis | Duration |
|---|---|---|---|
| Strictly necessary | Session management; CSRF protection; authentication state for logged-in customers | Art. 6(1)(b) — Necessary for service delivery; no consent required | Session or up to 30 days |
| Analytics (first-party) | Understanding aggregate usage of intygio.com to improve content and performance. No cross-site tracking. Data is not shared with third-party advertising platforms. | Art. 6(1)(f) — Legitimate interests, balanced against your right to privacy (minimal data, EU-hosted, no fingerprinting) | 90 days |
You may disable cookies in your browser settings. Disabling strictly necessary cookies will affect functionality of logged-in features.
INTYGIO does not make decisions based solely on automated processing that produce legal or similarly significant effects on you (Art. 22 GDPR). Usage-based billing calculations are automated but are not decisions affecting legal rights — they are contractually agreed metered billing based on logged API calls.
The table below summarises the retention periods described in §1. Where multiple periods apply to the same data, the longer period applies where legally required.
| Data Category | Retention Period | Basis for Retention |
|---|---|---|
| Website analytics | 90 days from collection | Legitimate interests |
| Contact form enquiries (no contract entered) | 24 months from last contact | Legitimate interests |
| Customer account holder data | Duration of contract + 3 years | Contract; legitimate interests (dispute resolution) |
| Invoicing and accounting records | 7 years | Legal obligation (Swedish Accounting Act §7:2) |
| API usage logs | 13 months | Contract (billing); legitimate interests (security) |
| Verification request records (§1.3) | 13 months from the request | Legitimate interests (abuse detection; issuer statistics) |
| Support communications | 24 months from resolution | Legitimate interests |
Data is deleted or anonymised at the end of the applicable retention period. Backups are overwritten on a rolling 90-day cycle.
We may update this Policy from time to time to reflect changes in our processing activities, legal requirements, or service features. When we make material changes, we will:
Your continued use of the service after the effective date constitutes acceptance of the updated Policy. If you do not agree, you may terminate your account in accordance with the Terms of Service.
For any questions about this Privacy Policy, to exercise your rights, or to request a copy of our Data Processing Agreement, please contact:
We may ask you to verify your identity before processing a rights request, to ensure we do not disclose personal data to unauthorised parties.