Privacy Policy
1. Controller
The controller responsible for processing personal data on this website is:
NetSymphony AB
Norr Mälarstrand 54
112 20 Stockholm
Sweden
Company registration number: 559008-3605
Email: contact@netsymphony.se
2. General information
We process personal data in accordance with the General Data Protection Regulation (GDPR) and other applicable data protection and electronic communications laws. Personal data means any information relating to an identified or identifiable individual.
3. Website access, hosting and content delivery
3.1 Server and security logs
When you access this website, our technical infrastructure processes in particular:
- your IP address;
- the date and time of access;
- the requested address and the amount of data transferred;
- the referrer URL, if transmitted by your browser;
- browser type and version, operating system and device information;
- HTTP status, error, diagnostic and security information and technical request IDs.
We process this information to deliver the website, maintain its stability and security, investigate technical errors and defend against attacks. The legal basis is Article 6(1)(f) GDPR. Our legitimate interests are the secure, reliable and abuse-free operation of the website.
We delete or anonymise log data once it is no longer required for these purposes. It may be retained for longer where necessary to investigate a specific security incident, establish, exercise or defend legal claims, or comply with a legal obligation.
3.2 Hosting by Fly.io
We use infrastructure supplied by Fly.io, Inc., USA, to provide and secure this website. Fly.io processes the connection and log data needed to transmit the website on our behalf. Further information: Fly.io Privacy Policy.
3.3 Images delivered through Backblaze B2
Some images and other static files are delivered through Backblaze, Inc., USA, from a European storage region. When such a file is requested, Backblaze receives technically necessary connection data, including the IP address, requested file, time, browser/device information and, where transmitted, the referrer URL. The legal basis is Article 6(1)(f) GDPR; our legitimate interest is the fast and stable delivery of the website. Further information: Backblaze Privacy Notice.
3.4 Google Fonts
This website currently loads fonts from servers operated by Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland, and affiliated companies, in particular Google LLC, USA. Google therefore receives in particular your IP address and technical information about the font request, such as browser/device information and, where transmitted, the referrer URL. The purpose is a consistent and efficient presentation of the website. The legal basis is Article 6(1)(f) GDPR. Further information: Google Privacy Policy.
4. Contact form and business communications
If you use our contact form, we process the data you enter. The form currently collects:
- full name, email address and company as required fields;
- telephone number as an optional field;
- the time of the request and technical metadata needed for transmission and security.
We use this data to deal with your request, communicate with you and, where applicable, take steps before entering into a contract. Where your request concerns a contract or pre-contractual measures, the legal basis is Article 6(1)(b) GDPR. For other business enquiries, the legal basis is Article 6(1)(f) GDPR; our legitimate interest is handling and documenting business communications.
We use HubSpot CRM to handle and manage enquiries. HubSpot generally processes contact data stored in the CRM as our processor. Depending on the request, access is also granted to those employees and carefully selected service providers who need it to respond or securely operate our systems.
We generally delete enquiries that do not result in a contractual relationship no later than twelve months after the last substantive contact. We retain documents relevant to contracts or accounting for the applicable statutory retention periods. We may retain information for longer where necessary to establish, exercise or defend legal claims.
We need the required fields to respond meaningfully to your enquiry. Without them, we may be unable to process the request. Providing a telephone number is voluntary.
5. Consent management, cookies and browser storage
5.1 Consent management
We use a consent management tool to ask for and record your choices concerning non-essential cookies and similar browser storage. Storage needed to remember your choice and deliver the website accordingly is necessary.
The legal basis for processing the consent record is Article 6(1)(c) GDPR where we use it to meet legal accountability and evidence requirements, supplemented by Article 6(1)(f) GDPR. Necessary storage and access rely on the relevant exceptions under national laws implementing Article 5(3) of the ePrivacy Directive, in particular Chapter 9, Section 28 of the Swedish Electronic Communications Act (2022:482) and, where applicable, Section 25(2) TDDDG.
5.2 Analytics only with consent
We use non-essential analytics cookies and comparable storage, and carry out the related processing through HubSpot, only after you have consented to the “Analytics” category. The legal bases are your consent under Articles 6(1)(a) and 7 GDPR and the applicable consent rules governing access to your device.
You can change or withdraw your choice at any time through the “Cookie settings” link in the footer. Withdrawal is as easy as giving consent and does not affect the lawfulness of processing carried out before withdrawal.
5.3 Storage technologies used
Not every entry is created during every visit. The entries created depend in particular on your choice and the current HubSpot configuration.
Necessary cookies
These are needed for the website and consent tool to work, so they are set without asking.
csrftoken (NetSymphony): keeps our forms safe from misuse by other websites. Kept for up to 364 days.
__hs_opt_out (HubSpot): remembers that you declined cookies, so we don't ask you again. Kept for 6 months.
__hs_do_not_track (HubSpot): remembers that you don't want to be tracked, so no tracking data is sent. Kept for 6 months.
__hs_cookie_cat_pref (HubSpot): remembers which cookie categories you accepted. Kept for 6 months.
__hs_initial_opt_in (HubSpot): stops the cookie banner from appearing over and over in some strict browser modes. Kept for 7 days.
Analytics cookies (only with your consent)
These help us understand how people use the website. They are only set if you accept the "Analytics" category.
__hstc (HubSpot): the main visitor cookie. It stores the website domain, a visitor ID, visit times and session details. Kept for 6 months.
hubspotutk (HubSpot): a pseudonymous visitor ID. If you submit a form, it can be used to link your visits to your enquiry and avoid duplicate records. Kept for 6 months.
__hssc (HubSpot): keeps track of your current visit and the pages you view. Kept for 30 minutes.
__hssrc (HubSpot): notices when you restart your browser or begin a new visit. Deleted when you close your browser.
__hmpl (HubSpot, browser storage): holds background details about tracking events. Kept until you close your browser or longer in local storage, depending on your consent.
hublytics_events_53 (HubSpot, browser storage): briefly holds tracking events before they are sent to HubSpot. Kept until you close your browser or longer in local storage, depending on your consent.
Depending on the request, HubSpot or its CDN may also set short-lived security and rate-limiting cookies. HubSpot provides a current detailed overview at Cookies set in your visitor's browser by HubSpot.
You can also delete or block cookies through your browser. Blocking necessary cookies may affect the contact form or consent management functions.
6. HubSpot Analytics and CRM
We use services supplied by HubSpot Ireland Limited, Ground Floor, Two Dockland Central, Guild Street, Dublin 1, Ireland, and affiliated companies, in particular HubSpot, Inc., 2 Canal Park, Cambridge, MA 02141, USA.
After you consent to analytics, the HubSpot tracking code collects in particular:
- pages visited, time and duration;
- source and referrer information;
- IP address and the approximate region derived from it;
- browser, device, language and screen information;
- pseudonymous online and visitor identifiers;
- events such as page views and, where applicable, form interactions.
We use this information to understand how the website is used, measure reach and improve content and navigation. If you later identify yourself by submitting an enquiry, HubSpot can technically associate the history previously collected under a visitor identifier with a CRM contact. We do this only where the underlying analytics consent has been given.
HubSpot acts as our processor under a data processing agreement for customer data in the CRM and other data it processes solely on our instructions. Under HubSpot's current privacy policy, HubSpot also uses certain data collected through its tracking code, including IP addresses and online identifiers, for its own purposes as an independent controller, including improving its products and its commercial dataset. For more information about this separate processing and the rights available to you, see the HubSpot Privacy Policy.
7. Recipients and international transfers
Recipients of personal data are, where necessary for the relevant purpose, our authorised employees and the hosting, infrastructure, CRM, analytics and IT providers identified in this policy. We disclose data to public authorities only where legally required.
Fly.io, Backblaze and HubSpot are US companies; Google Ireland and other providers may use affiliates and subprocessors outside the European Economic Area. Where personal data is transferred to the United States or another third country, we use the applicable safeguard under Chapter V GDPR. For certified US recipients, this may be the European Commission's adequacy decision for the EU-US Data Privacy Framework. Transfers not covered by it may rely in particular on the European Commission's Standard Contractual Clauses and any supplementary measures required.
You may contact contact@netsymphony.se to request further information about the safeguard used for a specific transfer and a copy of the relevant safeguard.
8. Retention
Where this policy does not state a specific period, we retain personal data only for as long as it is needed for the relevant purpose. We then delete or anonymise it unless a statutory retention requirement, investigation of a security incident, or the establishment, exercise or defence of legal claims requires longer retention.
When setting a period, we consider the nature, volume and sensitivity of the data, the risk of unauthorised use or disclosure, the purpose of processing and applicable legal periods.
9. Your rights
Subject to the applicable legal conditions, you have in particular the right to:
- access your personal data (Article 15 GDPR);
- rectify inaccurate data (Article 16 GDPR);
- request erasure (Article 17 GDPR);
- restrict processing (Article 18 GDPR);
- receive or transmit data in a structured, commonly used and machine-readable format (Article 20 GDPR);
- object, on grounds relating to your particular situation, to processing based on Article 6(1)(e) or (f) GDPR (Article 21 GDPR);
- withdraw consent at any time with effect for the future (Article 7(3) GDPR).
Where personal data is processed for direct marketing, you may object at any time without giving reasons relating to your particular situation.
To exercise your rights, contact contact@netsymphony.se.
You also have the right to lodge a complaint with a data protection supervisory authority. The authority primarily responsible for us is the Swedish Integritetsskyddsmyndigheten (IMY), www.imy.se. You may also contact another supervisory authority in the European Economic Area, in particular in the country of your habitual residence, place of work or the alleged infringement.
10. No solely automated decisions
We do not use this website to make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you.
11. Changes to this policy
We update this privacy policy when the website, services used or legal requirements change. The current version is available on this page.
Last updated: 23 September 2026