INTYGIO · Privacy Policy Version 1.1 · 2026-09-03
Kader Cadre AB · intygio.com
Privacy Policy
Version 1.1 · 3 September 2026
This Privacy Policy explains how INTYGIO, operated by Kader Cadre AB, collects,
uses, and protects personal data in connection with its website and services.

Issued under Regulation (EU) 2016/679 (GDPR) Art. 13 and Art. 14.
Data Controller
Kader Cadre AB
Organisation number: 559576-6097 · Registered in Sweden
Operating as: INTYGIO · Domain: intygio.com
Privacy contact: privacy@intygio.com

This Policy applies to personal data processed by Kader Cadre AB ("INTYGIO", "we", "us") in two contexts:

Website Visitors
Anyone visiting intygio.com, including contact form enquiries.
API Customers
Organisations and their account holders who access the INTYGIO API and platform.
Not Covered Here
Product passport payloads submitted via the API are governed by the Data Processing Agreement between INTYGIO and the customer.
Product Design Note INTYGIO's Digital Product Passport infrastructure is designed to carry no personal data in passport payloads. The signed proof records contain product, batch, and certification data only. Where a customer chooses to include personal data in a payload, INTYGIO acts as Processor and that processing is governed by a separate Data Processing Agreement.

§1   Data We Collect and Why

1.1 Website Visitors

Data Purpose Legal Basis Retention
IP address, browser type, pages visited, timestamps Web analytics; security and abuse prevention Art. 6(1)(f) — Legitimate interests (operating a secure, functional website) 90 days
Name, e-mail address, company, message (contact form) Responding to enquiries; pre-contractual communication Art. 6(1)(b) — Pre-contractual steps at your request; or Art. 6(1)(f) — Legitimate interests 24 months from last contact, unless a contract is entered

1.2 API Customer Account Holders

Data Purpose Legal Basis Retention
Name, work e-mail address, phone number Account management; service communications; support Art. 6(1)(b) — Performance of contract Duration of contract + 3 years
Company name, VAT/organisation number, billing address Contract performance; invoicing; statutory accounting obligations Art. 6(1)(b) — Contract; Art. 6(1)(c) — Legal obligation (Swedish Accounting Act) 7 years (accounting records)
API usage logs (timestamps, endpoint, volume — no payload content) Usage-based billing; service quality; security monitoring Art. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interests 13 months
Support communications (e-mail, messages) Resolving support requests; service improvement Art. 6(1)(b) — Contract; Art. 6(1)(f) — Legitimate interests 24 months from resolution

1.3 Verification Requests

Anyone can present a product passport to the INTYGIO API for verification, for example by scanning a QR code. The request reaches INTYGIO directly from the scanner's device. For this data INTYGIO is the Controller: verification requests are generated by third parties and are not Customer Data under the Terms of Service.

Data Purpose Legal Basis Retention
IP address of the requesting device, time of the request, the passport verified, the verification result Detecting abuse and cloned passports (for example the same passport verified from an unusual number of addresses); aggregate verification statistics provided to the Customer that issued the passport Art. 6(1)(f) — Legitimate interests (integrity of the verification service; the issuer's interest in knowing how its passports are used) 13 months, after which the record is deleted

Statistics provided to a Customer are aggregated. No individual verification request, and no IP address, is disclosed to a Customer or to any other party except as required by law. INTYGIO does not derive location from these addresses today; should country-level statistics be introduced, they will be derived from the same data, for the same purposes, and this Policy will be updated first.

INTYGIO · Privacy Policy §2 Recipients · §3 Transfers · §4 Your Rights

§2   Recipients and Sub-Processors

We do not sell, rent, or trade personal data. We share data only with the following categories of recipients:

Recipient Role Purpose Location
Inleed AB Sub-processor (web hosting and e-mail) Hosting of the intygio.com website; mailboxes for legal@ and security@intygio.com Sweden, EU
Brevo SAS Sub-processor (transactional e-mail) Delivery of sign-in links and account e-mail to API customer account holders France, EU
DigiCert Europe Netherlands B.V. EU Qualified Trust Service Provider (QTSP) Qualified electronic seal certificate (QSealC) issuance and remote signing Netherlands (EU)
Competent authorities Required by law Compliance with legal obligations (e.g. IMY, tax authorities, courts) EU / Sweden

All sub-processors are bound by data processing agreements that impose GDPR-equivalent obligations. The current list of sub-processors, with a dated change log, is published at intygio.com/legal/subprocessors.

§3   International Transfers

The INTYGIO API runs on infrastructure operated by INTYGIO in Sweden. The website host, the qualified trust service provider, and the e-mail provider are established within the European Economic Area. At the time of this Policy's publication, no transfers of personal data to countries outside the EEA take place.

Should a third-party engagement require an EEA transfer in the future, INTYGIO will put in place appropriate safeguards (Standard Contractual Clauses pursuant to Art. 46 GDPR, or an adequacy decision) and update this Policy prior to any such transfer commencing.

§4   Your Rights Under GDPR

As a data subject, you have the following rights under GDPR Arts. 15–22. Requests should be submitted to privacy@intygio.com. We will respond within one calendar month (Art. 12(3)).

Access (Art. 15)
Obtain confirmation of whether we process your data and, if so, a copy of that data together with information on purposes, categories, recipients, and retention.
Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data without undue delay.
Erasure (Art. 17)
Request deletion where the data is no longer necessary, consent has been withdrawn, or you have objected and there are no overriding legitimate grounds. Statutory retention obligations may prevent full erasure.
Restriction (Art. 18)
Request that processing be restricted while accuracy is disputed, an objection is pending, or data is needed for legal claims even though it would otherwise be deleted.
Data Portability (Art. 20)
Receive personal data you provided to us in a structured, machine-readable format, where processing is based on consent or contract and carried out by automated means.
Objection (Art. 21)
Object to processing based on legitimate interests (Art. 6(1)(f)). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests.
Supervisory Authority You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or the place of the alleged infringement. The Swedish supervisory authority is:

Integritetsskyddsmyndigheten (IMY) · Box 8114, 104 20 Stockholm · imy.se · imy@imy.se

§5   Security

We implement technical and organisational measures appropriate to the risk posed by the processing activities described in this Policy. These include access controls, encryption of data in transit and at rest, audit logging, and periodic security reviews. Our measures are documented in detail in our Data Processing Agreement (available to customers on request).

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify you without undue delay in accordance with Art. 34 GDPR.

INTYGIO · Privacy Policy §6 Cookies · §7 Automated Processing · §8 Changes · §9 Contact

§6   Cookies and Similar Technologies

INTYGIO uses a minimal set of cookies and similar technologies on intygio.com. We do not use third-party advertising cookies or cross-site tracking.

Category Purpose Legal Basis Duration
Strictly necessary Session management; CSRF protection; authentication state for logged-in customers Art. 6(1)(b) — Necessary for service delivery; no consent required Session or up to 30 days
Analytics (first-party) Understanding aggregate usage of intygio.com to improve content and performance. No cross-site tracking. Data is not shared with third-party advertising platforms. Art. 6(1)(f) — Legitimate interests, balanced against your right to privacy (minimal data, EU-hosted, no fingerprinting) 90 days

You may disable cookies in your browser settings. Disabling strictly necessary cookies will affect functionality of logged-in features.

§7   Automated Decision-Making and Profiling

INTYGIO does not make decisions based solely on automated processing that produce legal or similarly significant effects on you (Art. 22 GDPR). Usage-based billing calculations are automated but are not decisions affecting legal rights — they are contractually agreed metered billing based on logged API calls.

§8   Retention Summary

The table below summarises the retention periods described in §1. Where multiple periods apply to the same data, the longer period applies where legally required.

Data Category Retention Period Basis for Retention
Website analytics 90 days from collection Legitimate interests
Contact form enquiries (no contract entered) 24 months from last contact Legitimate interests
Customer account holder data Duration of contract + 3 years Contract; legitimate interests (dispute resolution)
Invoicing and accounting records 7 years Legal obligation (Swedish Accounting Act §7:2)
API usage logs 13 months Contract (billing); legitimate interests (security)
Verification request records (§1.3) 13 months from the request Legitimate interests (abuse detection; issuer statistics)
Support communications 24 months from resolution Legitimate interests

Data is deleted or anonymised at the end of the applicable retention period. Backups are overwritten on a rolling 90-day cycle.

§9   Changes to This Policy

We may update this Policy from time to time to reflect changes in our processing activities, legal requirements, or service features. When we make material changes, we will:

Your continued use of the service after the effective date constitutes acceptance of the updated Policy. If you do not agree, you may terminate your account in accordance with the Terms of Service.

§10   Contact

For any questions about this Privacy Policy, to exercise your rights, or to request a copy of our Data Processing Agreement, please contact:

Privacy Contact
INTYGIO · Privacy Office
E-mail: privacy@intygio.com
Operated by: Kader Cadre AB (559576-6097), Sweden
Response time: within one calendar month (Art. 12(3) GDPR)

We may ask you to verify your identity before processing a rights request, to ensure we do not disclose personal data to unauthorised parties.