This policy explains how SvarKlar collects, uses, stores, and shares personal data. It covers website visitors, giveaway entrants, and customers. It also covers two groups who never asked to hear from us: the leads our customers hand us, and business owners we write to ourselves.
1. Who we are
SvarKlar is a brand owned and operated by Store Investeringer ApS, CVR 41622644, Præstemosen 199, 2650 Hvidovre, Denmark. For privacy questions, email frederik@svarklar.com.
2. GDPR applies
SvarKlar is a Danish company, so the EU General Data Protection Regulation (GDPR) applies to everything we do, including work for customers and entrants outside the EU. GDPR gives you clear rights over your data regardless of where you live.
3. The roles we play
For website visitors, giveaway entrants, and data our customers give us directly (their own name, email, billing info), SvarKlar is the data controller. We decide what data is collected and why.
For data about our customers' leads (the names, emails, messages, and details that flow through their website contact forms and inboxes), SvarKlar is a data processor. The customer is the controller. They decide what we do with that data, and we act on their instructions.
For business owners we contact ourselves to introduce SvarKlar, we are the data controller, and you can bring any request straight to us.
4. What we collect
From website visitors
- Name, email, business name, website URL, and any message you submit through a form.
- Page views, button clicks, outbound link clicks, form interactions, and scroll depth.
- Technical context such as the page you used, the referring page, and campaign tags in the link if present.
- If you accept cookies, PostHog uses cookie-based analytics and records how you move through the site. Every form input is masked so we do not capture what you type in a recording.
- If you decline cookies, PostHog still receives cookieless analytics using its privacy-preserving server-side hash. It uses no PostHog cookies and makes no session recording. Cookieless analytics is still analytics processing and may involve personal data or online identifiers under applicable law.
From giveaway entrants
- What you submit in the entry form: your business name, your name, your email, what your business does, an optional description of what you'd like the AI to do, and an optional phone number.
- The date and the exact wording of the rules and privacy agreement you accept, and whether you opted in to receive offers, so we can show your consent if asked.
From customers
- Contact details (name, email, phone, business name, address).
- Billing information (handled by our payment provider once enabled, not stored on our servers beyond what the provider exposes).
- Business context needed to reply well (office hours, service area, escalation contact, tone, pricing posture, the kind of work you do).
- Meta business, WhatsApp Business Account, phone-number, Facebook Page, and Instagram account identifiers, plus encrypted access tokens for the assets you connect.
- Access credentials or forwarding setup for other connected inboxes and channels.
From leads the customer asks us to handle
- Whatever the lead sends through the customer's contact form, inbox, connected WhatsApp, Facebook Messenger, or Instagram business channel: name, email, phone, address, service request, message text, attachments, and any other details they include.
- The replies we send on the customer's behalf.
- Sender and recipient identifiers, attachment metadata, timestamps, delivery and conversation status, intent classification, and a minimal activity log so we can show the customer what we did.
From business owners we contact
We introduce SvarKlar to service businesses in the United States by writing to them once, through the contact form on their own website. If a message like that turned up on your desk, here's where your details came from.
- Your business name, website, email address, phone number, and street address, all taken from your own public website and your Google business listing. Sometimes a first name, when your site publishes one.
- Public details about the business itself, such as your trade, your rating, and how many reviews you have.
- Our own notes on how inquiries seem to be handled at your business, which is what decides whether we write to you at all.
Nobody handed us your details and you never asked to hear from us, so we say that in the message itself and point you here. We write once. Tell us to stop and you come off our list right away, your whole domain with you. We won't ask you to prove who you are first. You can also email frederik@svarklar.com for a copy of what we hold, or to have it deleted.
5. Legal basis for processing
- Contract and steps you ask us to take before a possible contract for a requested call, customer billing, account management, and fulfilling the service we agreed to. For giveaway entrants, accepting the official rules forms a contract, and we process your entry to run and judge the giveaway, select and notify winners, and set up your prize.
- Legitimate interest for securing our systems, improving the service, cookieless website analytics after you decline cookies, and keeping entries in the pool for future selection rounds you agreed to when you entered. The same basis covers one message to a business we think we can help, sent to the contact details that business published itself. You can object to that at any time and we stop.
- Consent for website analytics cookies and session recording, which run only after you accept the cookie notice, and for marketing email, which we send only if you tick the optional offers box when you enter. You can withdraw either consent at any time.
- Customer instruction for data about leads, since the customer is the controller and we follow their rules.
- Legal obligation for records we have to keep under Danish or EU law (for example, billing records for tax purposes).
6. How we use data
- Receive, organize, classify, and reply to leads through the customer's connected website, email, WhatsApp, Facebook Messenger, and Instagram channels.
- Run and judge the giveaway, select and notify winners, and set up prizes.
- Build the activity summaries, reports, and logs we send back to the customer.
- Classify reply intent and escalate leads that need a human.
- Run billing and send service-related communications.
- Measure how the website and service work so we can improve them.
- Secure our systems and detect abuse.
We do not sell personal data. We never use our customers' lead data to market to those leads. If you give a phone number when you enter the giveaway, we use it only for direct, individual contact if you are selected. We never use that number for bulk texts or automated calls.
7. AI-generated replies
SvarKlar may use AI services from OpenAI or Anthropic to organize messages and draft replies. Only the provider enabled for the relevant customer's work receives the data for that work; the other provider does not. We may switch which provider is enabled. SvarKlar disables the enabled provider's optional use of submitted content for general model improvement. The AI uses the lead's message, the customer's business details, and the reply rules set during setup. Routine replies may be sent directly. Anything outside those rules goes to a person first. The activity log says which rules were used and whether AI or a person sent the reply.
8. Subprocessors
SvarKlar uses the following service providers to run the service. Each processes only the data they need to do their job, under contracts that require them to protect your data.
- Cloudflare (United States / global): website hosting, the form-submission backend that receives your form entries including giveaway entries before relaying them to us by email, a cookie-free visitor count, and protection and relay for Portal and webhook traffic.
- Hetzner (Germany, EU): encrypted offsite backups and an outage alarm. The service itself runs on our own machine in Denmark, not here.
- Brevo (France, EU): outbound email sending.
- Purelymail (United States): the hello@svarklar.com inbox and the SMTP relay that sends confirmations and notifications when you submit a form.
- PostHog (EU region): website analytics. If you accept, it uses cookies for full analytics and session replay. Recordings mask every form input, so PostHog does not receive your typed name, email, phone, or message in a recording. If you decline, it receives cookieless analytics through its privacy-preserving server-side hash, with no PostHog cookies and no replay. Cookieless does not automatically make the processing anonymous or outside data-protection rules.
- Google (United States / global): Gmail connection and mailbox access when a customer connects Google.
- Meta (United States / global): authorization for connected WhatsApp, Facebook Messenger, and Instagram business channels, and carrying messages and replies through those channels.
- OpenAI and Anthropic (United States): possible AI providers for organizing messages and drafting replies. Only the provider enabled for the relevant customer's work receives the data for that work.
- Cal.com (United States): scheduling, if you book a call with us.
- Telegram (international): operator alerts for new entries and escalation cases.
- Stripe (United States): card payments, if you pay us. Stripe takes your card details on its own checkout page and we never see or store them.
Not yet active: we plan to use Billy (Denmark, EU) for invoicing once we bill you that way. It processes no personal data today, and we will update this list before it does.
9. International data transfers
Some providers process data outside the EEA, including in the United States. We use the provider's applicable transfer safeguards, such as the EU-US Data Privacy Framework or Standard Contractual Clauses. When we return customer-controlled lead data from Denmark to a customer outside the EEA, the customer's signed agreement includes the applicable EU transfer clauses.
10. Retention
- Website analytics and session recordings: analytics events are kept for up to 12 months. Session recordings (accepters only) are kept for 30 days, then deleted.
- Giveaway entries: kept for up to 5 years so we can run the giveaway, award prizes to selected entrants, and keep our records, then deleted. We delete your entry sooner on request.
- Website messages and call-booking enquiries: kept for up to 12 months after the last update. If a customer relationship starts, the details needed for that relationship are kept separately under the customer rules below.
- Customer account details: kept while the customer is active and for up to 2 years after the relationship ends.
- Customer-controlled lead and message data: kept while needed to deliver the service. On cancellation, we stop new processing and revoke connected-account access. The customer downloads one ZIP that can be uploaded later. We then delete the customer data we use to run the service. We do not save another copy of the ZIP. Encrypted backups age out within 90 days.
- Connected Meta access: kept until the customer disconnects the channel or cancels. Disconnecting stops new collection, revokes connected-account access, and deletes the stored access token. If provider revocation fails, our daily retention process retries it. Messages and other data already received remain under the customer's instructions and the retention rule above.
- Business owners we contacted: kept for 24 months after we last wrote to you, then the personal details are wiped. One exception. If you asked us to stop, your email address and domain stay on a do-not-contact list for good, because that record is the only thing keeping us from reaching you again by mistake.
- Billing and tax records: kept for 5 years after the end of the financial year, or longer if the law requires it.
11. Your rights
Under GDPR, you can:
- request a copy of the data we hold about you;
- ask us to correct data that is wrong;
- ask us to delete data we no longer need to keep;
- restrict or object to how we process your data;
- withdraw consent (for example, to marketing email) at any time;
- request a portable copy of the data you gave us.
If you are a lead whose data is being handled by SvarKlar on behalf of one of our customers, the customer is the data controller. Please contact the customer directly for access or deletion. We will support the customer in fulfilling your request.
To exercise any of these rights, email frederik@svarklar.com.
12. Security
We use industry-standard security measures: encrypted connections (HTTPS), least-privilege access, credentials stored outside the public repository, and regular backups. No system is perfect. If a breach affects your data, we will notify you in line with GDPR's 72-hour rule where applicable.
13. Cookies and browser storage
This website shows a notice with equally weighted Accept and Decline choices. If you accept, PostHog uses first-party browser storage for full site analytics and session replay. Every form input is masked in recordings. If you decline, PostHog uses no cookies and makes no recording, but it still receives cookieless analytics through its privacy-preserving server-side hash. That does not automatically make the processing anonymous or outside data-protection rules. We do not use cookies for advertising or to track you across other websites.
Use Cookie settings in the footer at any time to change your choice. Switching from Accept to Decline removes SvarKlar's test and visit-attribution storage, tells PostHog to clear its analytics storage in that browser, and stops new cookie-based analytics and recordings. Cookieless analytics continues. Data already received follows the retention periods in section 10 unless you ask us to delete it using the contacts in section 11.
The website uses these browser-storage items:
- PostHog analytics storage, named
ph_<project token>_posthog: a first-party cookie and local-storage copy created only after Accept. The cookie lasts for up to 365 days. It holds browser and session analytics state and enables session replay. Withdrawing consent clears PostHog's stored copy in that browser. - Cookie choice, named
svarklar_cookie_choice: local storage used only to remember Accept or Decline. It remains until you change the choice or clear browser data. - Site-test and visit attribution, named
svarklar_*_variantandsvarklar_attr_*: created only after Accept. Test assignments stay until consent is withdrawn or browser data is cleared. Visit-attribution data clears when the tab closes. - Pending choice, named
svarklar_consent_event_pending: may hold your choice until PostHog finishes loading. It is deleted after the choice event is sent. If PostHog is blocked, it remains until you change your choice or clear browser data.
14. Complaints
If you believe SvarKlar is not handling your data properly, contact us first and we'll try to fix it. You also have the right to complain to the Danish Data Protection Authority (Datatilsynet) at datatilsynet.dk, or your local EU data protection authority if you live elsewhere in the EU.
15. Changes
This policy may be updated as the service evolves. The version published here is the current one. We'll refresh the "Last updated" date at the top when we change anything material.
16. Contact
Privacy questions: frederik@svarklar.com.