Privacy Policy
Last updated: August 2026
Data controller: Anton Wester AB (org. no. 559489-0914)
Address: Dalhemsgatan 10 K, 431 67 Mölndal
Contact: [email protected]
1. Introduction
Your privacy is important to us. This policy describes how Anton Wester AB ("we", "us", "SökHem") collects, uses, stores and protects your personal data when you use our platform. We always process your data in accordance with the General Data Protection Regulation (GDPR) and Swedish law.
2. What personal data we collect
We only process the data necessary to provide and secure our service:
- Account details: Name, email address and phone number (if you provide it).
- Search profiles and preferences: Your settings for housing watches (e.g. price range, geographic area, living area).
- Payment data: We use external payment providers (Stripe). We never store or have access to your full card details.
- Technical data and security logs: IP address, browser type, time of request and which endpoint was called. This is collected automatically to maintain security, prevent overload (DDoS) and stop automated scanning (scraping/bot traffic).
- Content you upload: Images or text that you voluntarily provide in your profile or when creating a listing.
- Communication: Email addresses provided for interest registrations about future features.
3. Legal bases for processing
We only process your data when we have a valid legal basis under the GDPR:
- Contract (Art. 6(1)(b)): To create your account, provide the watch service and handle payments.
- Legitimate interest (Art. 6(1)(f)): For security monitoring (e.g. rate limits and logging of suspected malicious traffic), and for internal, anonymised usage statistics to improve the platform's functionality.
- Consent (Art. 6(1)(a)): For marketing communications (newsletters) and the use of non-essential analytics cookies (e.g. Google Analytics). Consent can be withdrawn at any time.
- Legal obligation (Art. 6(1)(c)): To meet requirements under the Swedish Bookkeeping Act (retention of invoices for 7 years).
4. Retention periods
We do not keep your data longer than necessary for the purpose:
- Account data and search profiles: For as long as your account is active. Deleted within 30 days of your request to close the account.
- Security logs (abuse/rate limiting): Max 30 days, after which they are deleted automatically.
- Internal usage statistics (anonymised): Max 90 days.
- Accounting records: 7 years under the Swedish Bookkeeping Act.
- Interest registrations: Until the feature has launched and you have been notified, or at most 24 months.
5. Sharing data with third parties (Data processors)
We never sell your personal data. We only share data with carefully selected providers acting as data processors on our behalf, solely to the extent required to provide the service. We have signed Data Processing Agreements (DPAs) with all providers to ensure they meet the GDPR's requirements.
- Payment services: Stripe (for secure payment handling).
- Operations and security: Cloudflare (for CDN and attack protection) and our hosting provider for servers/databases (located within the EU/EEA).
- Communication: Resend and Mara (for transactional emails and notifications).
- Analytics and marketing: Google Analytics and Google Ads (only with your explicit consent via the cookie banner).
- Map services: OpenStreetMap (Nominatim) for geocoding addresses into coordinates.
- AI providers: External providers (e.g. via APIs from established cloud services) are used only for specific features such as automatic image captioning (alt text) or language-model help with text drafting.
Transfer of data outside the EU/EEA: Some of our providers (e.g. Google, Cloudflare) may be established in the United States. When personal data is transferred outside the EU/EEA, we ensure this happens in accordance with the GDPR by relying on either the EU-US Data Privacy Framework (for certified companies) or the European Commission's Standard Contractual Clauses (SCCs), supplemented with technical safeguards such as encryption in transit.
6. AI processing and your responsibility
Some features in SökHem use artificial intelligence. To protect your privacy, we apply the following strict rules:
- We only use AI providers whose published API terms prohibit the use of customer data for model training. We never transfer directly identifiable data (name, email, phone) to AI providers. You can read more about each provider's data policy on their website, and we update our provider list on an ongoing basis.
- Matching between watches and listings happens in our own secure code and is never sent to external AI providers.
- Important user responsibility: When you upload images to a listing, they are processed automatically to generate descriptions. You are responsible for not uploading images containing sensitive personal data (e.g. clear faces of other people, personal documents, mailboxes with names or passwords). Only upload images you have the right to share and that do not reveal unnecessary private information.
7. Automated decision-making and profiling (Art. 22 GDPR)
SökHem uses algorithms to automatically match property listings against the filters you have set in your search profile (e.g. price, rooms, area).
Under Art. 22 GDPR this does not count as an "automated decision with legal or similarly significant effect". The reason is that:
- Matching is based solely on the filters you have actively set yourself.
- It does not affect your legal rights.
- You always make the final, manual decision on whether to act on a match.
- You can change or delete your profile at any time, which immediately stops matching.
8. Your rights
Under the GDPR you have the following rights regarding your personal data:
- Right of access: Request a register extract of the data we hold about you.
- Right to rectification: Request that inaccurate data be corrected.
- Right to erasure (the "right to be forgotten"): Request that we delete your data, unless the law (e.g. the Bookkeeping Act) requires us to keep it.
- Right to data portability: Receive your data in a structured, machine-readable format.
- Right to object: Object to processing based on legitimate interest or direct marketing.
To protect your privacy, we may ask you to verify your identity (e.g. by logging in or an ID check) before fulfilling a request for an extract or erasure. Send your request to [email protected]. We respond without undue delay, and no later than within 30 days.
9. Complaints
If you believe we do not handle your personal data in accordance with this policy or applicable law, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se. We do, however, encourage you to first contact us at [email protected] so that we can try to resolve the issue together.
10. Changes to this policy
We may update this privacy policy to reflect changes in our services or in applicable legislation. Material changes are notified by email or through a clear notice on the platform before they take effect.