Skip to content

PRIVACY POLICY

What happens to your data here.

This notice covers the personal data Ampliro AB decides the purposes for: visits to this website, enquiries you send us, and the business contact details we hold. Personal data we handle inside a client engagement is governed by that client's agreement with us.

CONTROLLER

Who is responsible

Ampliro AB is the controller for the processing described on this page. That means we decide why the data is handled and how. Write to dataprotection@ampliro.com with any question about this notice. Our postal address, telephone number and company registration number are on the contact page.

We have no data protection officer, and we are not required to appoint one. That address goes to the founder, not to a mailbox nobody owns.

WHEN YOU VISIT

Visiting this website

We measure traffic with a cookieless analytics service hosted in the European Union. It stores no cookies, no browser storage and no IP addresses, and it produces counts rather than profiles. You cannot be recognised across days or devices. The cookie policy sets this out in full.

Our hosting provider keeps standard server logs, which contain IP addresses, for operation and security. The lawful basis is our legitimate interest in keeping the site available and defending it against abuse. These logs are not used to analyse behaviour or to build any picture of you.

ENQUIRIES

When you contact us

If you write to us or send the contact form, we process what you choose to tell us: your name, your organisation, your contact details and the content of your message. The lawful basis is our legitimate interest in answering, or the steps taken before entering a contract.

To keep the form usable for people rather than machines, we store a one way fingerprint built from your IP address, the date and a secret key. The address itself is never written down, the fingerprint cannot be reversed, and it is erased after thirty days.

That check rests on our legitimate interest in keeping the form open without it being flooded. It tells us nothing about who you are, and it is never used to recognise you between visits.

Please do not send special category data, security classified material or another person's personal data through the form. If you need to share something sensitive, say so in a first message and we will agree a channel that fits your requirements.

MEETING BOOKINGS

When you book a meeting

If you book a meeting through this website, we process your name and your email address, together with whatever else you choose to fill in: your organisation, your telephone number and a message about what you would like to discuss. We also keep the timezone and the language the page showed the times in, so that the confirmation matches where you are. The lawful basis is the steps taken at your request before a contract is entered into, and otherwise our legitimate interest in holding the meeting you asked for.

The booking lives in our own booking system, hosted inside the EU. No third party scheduling service is involved, and your browser never talks to anyone other than this website. The meeting is placed in our calendar at Google, the provider we use for mail and calendar, where your name and address appear in the invitation. The confirmation, the reminder and any notice of a change are sent by us.

The link for rescheduling or cancelling is a key in the address, not a login. It exists in your confirmation email and nowhere else: we never keep it in clear text, only as a one way value that cannot be reversed. Whoever holds the link can move or cancel that one meeting and reach nothing else.

The data in a booking is erased twelve months after the meeting takes place. If the meeting was cancelled, the twelve months run from the cancellation. After that the booking remains as a row without a person, so that we can count meetings over time, while the name, address, organisation, telephone number and message are gone. An automated routine does this every day. The meeting itself may remain in ordinary correspondence and in the calendar for as long as the usual rules allow, which are set out under retention below.

The message field is there for describing what you would like to discuss. Please do not send special category data or another person's personal data there, for the same reason that applies to the contact form.

AMPLIRO INSIGHTS

If you subscribe to Insights

Ampliro Insights is our analysis by email. If you sign up, we process your email address, the language you signed up in, the page the box stood on, and the date you confirmed. Nothing else. We do not ask for your name, we do not enrich the address from other sources, and we do not connect it to anything you have sent us through the contact form.

The lawful basis is your consent. Signing up sends you one message with a confirmation link, and nothing is sent until you click it. That is deliberate. It means a subscription cannot be started by someone else typing your address into a box, and it means we can show when and how each consent was given. The date, the page and which box you used are recorded for that reason and for no other.

The same one way fingerprint the contact form uses, built from your IP address, the date and a secret key, protects the signup box against automated abuse. The address itself is never written down, the fingerprint cannot be reversed, and it is erased after thirty days.

You can withdraw at any time, and every issue carries a link that does it in one step without asking you to log in or to explain yourself. Withdrawing stops the sending immediately. We keep a record that you unsubscribed and when, because that record is the evidence that we stopped, and we keep no other trace.

The mail carries no tracking pixel. We do not measure who opened an issue, and we cannot. Links in an issue point at ordinary pages on this website and carry no identifier for you. Sending is handled by a provider we already use for the contact form, on our instructions and under written terms. An address that is signed up but never confirmed is deleted after thirty days, because an unconfirmed signup is not a consent.

BUSINESS CONTACTS

People at client organisations

We hold names, roles and work contact details for people at client and prospective client organisations, gathered from our own correspondence, from public sources and from professional networks. The lawful basis is our legitimate interest in business communication in a professional context.

You can object at any time and we will stop. Marketing by email is sent only where the law allows it, and every message can be unsubscribed from in one step.

ENGAGEMENTS

Data inside an engagement

When we work in your systems or on your material, you remain the controller and we act on your instructions as a processor. That relationship is governed by a data processing agreement, not by this notice, and processing locations and subprocessors are declared per engagement.

How we handle client material, which tools may touch it and the log we keep of that, is set out in the data protection policy.

RECIPIENTS

Who else sees it

We use a small number of service providers to run our email, our hosting, our internal systems and our document storage. They act on our instructions under written terms and they do not use your data for their own purposes. A current list is available on request.

We keep processing inside the European Union and the European Economic Area wherever we can. Where a provider processes data outside it, we rely on the safeguards EU law requires, and we will tell you which ones if you ask.

RETENTION

How long we keep it

Enquiries that lead nowhere are deleted once it is clear there is nothing to continue. Correspondence connected to an engagement is kept while the engagement runs, and afterwards for the period accounting law requires and for the time a claim could still be made.

Business contact details are kept while the relationship is live and reviewed when it is not. The contact form fingerprint is erased after thirty days. Server logs are kept for a short operational period. Analytics data is aggregated and holds nothing that points to you.

An Insights subscription is kept until you withdraw it. An address that was signed up but never confirmed is deleted after thirty days, and the signup box fingerprint is erased on the same schedule as the contact form's. Once you have unsubscribed we keep only the fact that you did and the date.

A booking has its personal data erased twelve months after the meeting, or twelve months after the cancellation if the meeting was cancelled. An automated routine does this every day, and after it only the meeting time and the meeting type remain.

YOUR RIGHTS

Your rights

EU law gives you the right to access your data, to have it corrected or erased, to restrict or object to processing, and to receive it in a portable form. Sweden is where we are established, so the Swedish rules that supplement the Regulation apply to us.

The data subject rights policy explains how to exercise each of them and what happens after you ask. You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten), or to the supervisory authority in the country where you live.

CHANGES

Changes to this notice

We update this notice when what we do changes, and the date below tells you which version you are reading. Material changes are described rather than slipped in.

Last updated 31 July 2026. The change on that date added the section on meeting bookings and the retention period that goes with it. The change on 27 July added the section on Ampliro Insights.

A question about your data?

Write to dataprotection@ampliro.com and it is answered by a person. Requests to exercise a right are handled under the data subject rights policy.