Legal

Privacy policy

Last updated: 24 September 2026

Cleveco cares about your personal privacy. This privacy policy describes how we process personal data when you visit our website, contact us, book a demonstration or use Cleveco's services.

The policy applies to Cleveco, operated by:

Cleveco AB

Company registration number: 559600-2096

Stockholm, Sweden

Email: info@cleveco.com

The company is the data controller for the processing described in this policy, unless otherwise stated.

1. What personal data we process

We only process personal data needed to run our business, communicate with customers and prospects, and provide and secure Cleveco's services.

This may include:

  • name
  • company name and job title
  • email address
  • phone number
  • information you provide in a form or message
  • data related to demo or contact requests
  • user data for the customer portal, such as name, email address, company, role and permissions
  • technical security data and logs needed to protect the service and administer user accounts

2. When you visit our website

Cleveco uses aggregate statistics to understand how the website is used and which pages are visited.

Our internal page statistics are stored aggregated per page and day. We do not use IP addresses, visitor IDs or other persistent identifiers for this statistics, and we do not use it to build profiles of individual visitors.

Technical information may at the same time be processed temporarily by our operations and hosting providers when necessary to deliver the website, prevent abuse, identify technical errors and maintain security.

The legal basis for such processing is our legitimate interest in being able to operate and protect our website and IT systems.

3. When you contact us or book a demonstration

When you contact Cleveco, send an enquiry or book a demonstration, we process the data you provide to us.

The data is used to respond to your enquiry, carry out or plan a demonstration, understand your company's needs, provide relevant information about Cleveco, follow up an ongoing business dialogue, and prepare or administer a possible customer relationship.

The processing is normally based on our legitimate interest in communicating with people and companies that have contacted us themselves or shown a relevant business interest.

Contact details from an enquiry are normally kept for as long as an active business dialogue is ongoing and thereafter for a maximum of 24 months, unless there is a customer relationship or other legal basis for continued processing.

You can at any time let us know that you do not want further marketing communication.

4. When you use Cleveco's customer portal

For users of Cleveco's customer portal we process personal data needed to create and administer user accounts, manage permissions, provide the service, and maintain security and traceability.

This may for example include name and email address, company and organisational affiliation, user role and permissions, login and security information, and a history of certain administrative or security-related actions.

The data is processed for as long as the user account or customer relationship needs to be active, and thereafter for as long as required for winding down, security, legal claims or obligations under law.

5. Customer data in Cleveco's platform

Cleveco's customers can use the platform to process information within their own operations.

When a customer determines which personal data is stored or processed in Cleveco, the customer is normally the data controller and Cleveco the data processor.

Cleveco then processes the personal data on the customer's documented instructions and under a separate data processing agreement.

Questions about personal data that a company processes in its Cleveco account should primarily be directed to the company responsible for the data.

6. How long we keep personal data

We do not keep personal data longer than necessary for the purpose for which it was collected.

The retention period depends among other things on the type of data, whether there is an active customer or business relationship, contractual obligations, security and documentation needs, requirements under accounting or other applicable legislation, and the need to establish, exercise or defend legal claims.

When the data is no longer needed it is deleted or anonymised according to our procedures.

7. Suppliers and data processors

Cleveco uses external suppliers for parts of the technical infrastructure and operations, for example hosting and cloud infrastructure, database and data storage, email and communication, authentication and security, and technical operations and monitoring.

Suppliers that process personal data on our behalf may only process the data according to our instructions and under applicable agreements and data protection rules.

A current list of the sub-processors that process personal data on Cleveco's behalf is provided on request to customers. Customers are notified before Cleveco engages a new sub-processor or replaces an existing one that processes the customer's personal data.

We do not sell personal data to third parties.

8. Transfer outside the EU/EEA

Cleveco's platform is operated with providers within the EU/EEA and the United Kingdom. The database containing customer data is located in the United Kingdom, which the European Commission has assessed as having an adequate level of protection for personal data.

For a feature that calculates the expected arrival time of shipments, an external AI service is used. Only logistics data about the shipment is sent to it: container number, product model, ports, departure and arrival times, and the latest event. No personal data, customer data or prices are transferred. The calls are made to a service that does not store the content and does not use it for model training.

Should personal data in any case be transferred to a country outside the EU/EEA, this is done on the basis of the European Commission's adequacy decision or standard contractual clauses under Article 46, with supplementary safeguards where needed.

A copy of the applicable safeguards can be requested at info@cleveco.com.

9. Cookies

Cleveco may use cookies or similar technologies that are necessary for the website and the customer portal to function, for example for login, security or language selection.

Necessary cookies are not used for targeted marketing.

If we use cookies or similar technology that is not necessary, these are only activated after the visitor has given consent. Such consent must be possible to withdraw.

Information about the cookies used on the website at any given time is available together with the website's cookie settings.

10. Security

Cleveco uses technical and organisational security measures to protect personal data against unauthorised access, alteration, loss or disclosure.

Depending on which part of the service is used, this includes among other things access control, separation between different customers' data, row-level access control, multi-factor authentication for Cleveco's administrative accounts, logging of administrative and security-related events, restricted access to production environments, and technical protections for authentication and user accounts.

Access to personal data is limited to people and systems that need the information for a legitimate and defined purpose.

11. Personal data breaches

Cleveco has procedures to detect, report and investigate personal data breaches.

If a breach occurs that is likely to result in a risk to the rights and freedoms of natural persons, we report it to the Swedish Authority for Privacy Protection (IMY) without undue delay and no later than 72 hours after becoming aware of it.

If the breach is likely to result in a high risk, we also inform the data subjects affected.

When Cleveco processes personal data as a data processor for a customer, we notify the customer without undue delay after becoming aware of the breach, so that the customer can fulfil its own obligations as data controller.

12. Automated decision-making

Cleveco does not use automated decision-making or profiling that alone makes decisions producing legal or similarly significant effects for you as an individual.

13. Your rights

Depending on the circumstances, under the GDPR you have the right to obtain information about how we process your personal data, request access to the personal data we process about you, request that inaccurate data be rectified, request that personal data be erased, request that processing be restricted, object to processing based on legitimate interest, always object to the use of personal data for direct marketing, in certain cases obtain personal data in a structured and machine-readable format, and withdraw consent where processing is based on consent.

Certain rights are limited in certain situations, for example when we are required by law to retain information or need it to establish, exercise or defend legal claims.

Contact us at info@cleveco.com if you wish to exercise any of your rights.

We may need to verify your identity before disclosing or changing personal data.

14. Complaints

If you believe that Cleveco processes your personal data incorrectly, you are welcome to contact us.

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection, IMY, imy.se.

15. Changes to this policy

We may update this privacy policy when Cleveco's services, technical solutions or legal obligations change.

The latest version is always published on our website. The date of the most recent update is stated at the top of the page.

16. Contact

For questions about this privacy policy or Cleveco's processing of personal data:

Cleveco AB

Company registration number: 559600-2096

Stockholm, Sweden

Email: info@cleveco.com