Legal

Privacy Policy

Last updated: FILL IN — date the final text is published

Draft structure — not yet in force.

This page is a skeleton awaiting final drafting. Under the GDPR the controller must be a named legal entity, so the final text cannot be completed until the company is registered.

This page must contain final text before the URL is submitted to Stripe for review. Each section below states what belongs in it.

1. Data controller

Legal name, organisation number, registered address and contact email of the controller. Whether a data protection officer has been appointed.

2. Personal data we collect

Account data (name, email, phone), booking data (service address, vehicle registration number, description of the fault, job history), payment data (handled by Stripe — state that full card numbers are never received or stored by us), communications with customer service, and technical data such as device and log information.

3. Purposes and legal bases

Each purpose paired with its Article 6 legal basis: performing the booking contract, complying with accounting and tax obligations, preventing fraud and handling disputes on the basis of legitimate interests, and marketing on the basis of consent. Vehicle registration numbers and service addresses need explicit treatment.

4. Who we share data with

The mechanic assigned to a booking and what they receive; Stripe as payment processor; hosting, email and support providers; accountants and advisers; and authorities where required by law. A processor list with each provider's role.

5. Transfers outside the EU/EEA

Whether any processor transfers data outside the EU/EEA, and the safeguard relied on (adequacy decision or standard contractual clauses). Stripe's transfer position must be stated here.

6. How long we keep data

Retention period per category, including the statutory retention period for accounting records under the Swedish Bookkeeping Act, and what happens when an account is deleted.

7. Your rights

Access, rectification, erasure, restriction, portability, objection, and withdrawal of consent — with the address to send a request to and the response time.

8. Cookies and similar technologies

Which cookies this website and the app set, their purpose, and how consent is obtained where it is required. If the website sets no non-essential cookies, say so plainly — that is the current state of this site.

9. Security

Technical and organisational measures: encryption in transit, access control, and the fact that card data is handled by Stripe rather than by us.

10. Complaints

The right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), including its contact details.

11. Contact

info@zyntravision.com
FILL IN — postal address for privacy requests