PRIVACY POLICY
Senast uppdaterad: 31 juli 2026
This Privacy Policy ("Policy") explains how Concept Bandits Sweden AB, company registration number 559445-4745, with its registered office at Knäppingsborgsgatan 38, 602 26 Norrköping, Sweden ("Company", "we", "our", or "us"), collects, uses, stores, shares, and protects personal data when you access or use our AI-powered investment research platform, website, mobile applications, APIs, and related services (collectively, the "Service").
This Policy has been prepared in accordance with:
-
Regulation (EU) 2016/679 (General Data Protection Regulation -- "GDPR");
-
applicable Swedish data protection legislation;
-
other applicable European Union privacy laws.
By using the Service, you acknowledge that your personal data will be processed as described in this Policy.
1. INTRODUCTION
1.1 Purpose of this Privacy Policy
Your privacy is important to us.
This Privacy Policy explains:
-
what personal data we collect;
-
why we collect it;
-
how we process it;
-
who we share it with;
-
how we protect it;
-
how long we retain it;
-
what rights you have under applicable data protection laws.
Our objective is to process your personal data lawfully, fairly, transparently, and securely.
1.2 Scope
This Privacy Policy applies whenever you:
-
visit our website;
-
create an Account;
-
purchase a Subscription;
-
use AI-powered features;
-
contact customer support;
-
participate in surveys;
-
interact with our applications;
-
receive newsletters;
-
use any service provided by the Company.
This Policy applies regardless of whether the Service is accessed through:
-
desktop devices;
-
mobile phones;
-
tablets;
-
APIs;
-
future software platforms.
1.3 Data Controller
For purposes of the GDPR, the data controller responsible for your personal data is:
Concept Bandits Sweden AB
Company Registration Number: 559445-4745
Knäppingsborgsgatan 38
602 26 Norrköping
Sweden
Email: [Privacy Email]
Website: [Website]
Where required by law, the Company may appoint a Data Protection Officer ("DPO") or other privacy contact. Updated contact details will be published on the Company's website.
1.4 Changes to this Policy
The Company may update this Privacy Policy from time to time in order to:
-
comply with legal requirements;
-
reflect changes to our Service;
-
introduce new technologies;
-
improve transparency;
-
respond to regulatory guidance.
Material changes will be communicated through appropriate means, including within the Service or by email where required by law.
Your continued use of the Service following the effective date of an updated Policy constitutes acknowledgment of the revised Policy.
2. DEFINITIONS
For the purposes of this Privacy Policy, the following terms shall have the meanings set out below.
2.1 Personal Data
"Personal Data" means any information relating to an identified or identifiable natural person as defined by Article 4 of the GDPR.
Examples include:
-
name;
-
email address;
-
billing information;
-
IP address;
-
device identifiers;
-
online identifiers;
-
account information;
-
usage data.
2.2 Processing
"Processing" means any operation performed on Personal Data, whether or not by automated means.
Processing includes:
-
collection;
-
recording;
-
storage;
-
organization;
-
adaptation;
-
retrieval;
-
consultation;
-
analysis;
-
disclosure;
-
transmission;
-
deletion;
-
destruction.
2.3 Data Controller
"Data Controller" means the legal entity determining the purposes and means of processing Personal Data.
For this Service, the Data Controller is Concept Bandits Sweden AB.
2.4 Data Processor
"Data Processor" means any third party processing Personal Data on behalf of the Company under a written data processing agreement.
Examples may include:
-
cloud hosting providers;
-
payment processors;
-
customer support platforms;
-
analytics providers.
2.5 User
"User" means any individual who accesses or uses the Service.
2.6 Account
"Account" means a registered user profile used to access the Service and its features.
2.7 Consent
"Consent" means any freely given, specific, informed, and unambiguous indication of the User's wishes by which they agree to the processing of Personal Data for one or more specific purposes.
Where processing is based on consent, Users may withdraw that consent at any time without affecting the lawfulness of processing carried out before withdrawal.
2.8 Usage Data
"Usage Data" means technical and analytical information generated through your interaction with the Service.
This may include:
-
pages visited;
-
session duration;
-
clicks;
-
navigation paths;
-
device type;
-
browser version;
-
operating system;
-
referral URLs;
-
timestamps;
-
feature usage.
2.9 Cookies
"Cookies" are small text files stored on your device that enable websites and applications to recognize your browser, remember preferences, and improve functionality.
Further information is available in our Cookie Policy.
2.10 AI Processing
"AI Processing" means the automated processing of information by artificial intelligence systems for purposes such as:
-
generating market analyses;
-
summarizing financial news;
-
identifying market trends;
-
creating educational investment insights;
-
improving platform functionality.
AI Processing does not involve providing personalized financial advice or individualized investment recommendations.
3. OUR COMMITMENT TO PRIVACY
The Company is committed to processing Personal Data in accordance with the following principles:
-
Lawfulness
-
Fairness
-
Transparency
-
Purpose Limitation
-
Data Minimization
-
Accuracy
-
Storage Limitation
-
Integrity
-
Confidentiality
-
Accountability
We implement appropriate technical and organizational measures designed to protect Personal Data against unauthorized access, alteration, disclosure, loss, or destruction.
We continuously review our privacy practices to ensure ongoing compliance with applicable data protection legislation and evolving industry standards.
4. PERSONAL DATA WE COLLECT
4.1 General Principles
The Company collects only the Personal Data that is reasonably necessary to provide, improve, secure, and administer the Service.
The categories of Personal Data collected depend on how you interact with the Service, the features you use, and the preferences you choose.
The Company does not intentionally collect Personal Data that is unnecessary for the operation of the Service.
4.2 Categories of Personal Data
Depending on your interaction with the Service, we may collect:
-
Identity Information
-
Contact Information
-
Account Information
-
Authentication Information
-
Subscription Information
-
Billing Information
-
Device Information
-
Usage Information
-
AI Interaction Data
-
Communication Data
-
Customer Support Data
-
Marketing Preferences
-
Security Logs
-
Technical Diagnostics
5. INFORMATION YOU PROVIDE
5.1 Registration Information
When creating an Account, you may provide:
-
Full name
-
Email address
-
Country of residence
-
Password
-
Preferred language
-
Time zone
Providing inaccurate or incomplete information may affect your ability to use certain features of the Service.
5.2 Subscription Information
If you purchase a Subscription, we may collect:
-
Subscription plan
-
Subscription status
-
Purchase history
-
Renewal dates
-
Invoice information
-
Payment confirmations
-
Tax information where applicable
Complete payment card details are processed directly by our payment processor and are not stored on our servers.
5.3 Customer Support
When contacting Customer Support, we may collect:
-
Name
-
Email address
-
Account ID
-
Support messages
-
Attachments
-
Screenshots
-
Technical information necessary to resolve your request
Support interactions may be retained to improve customer service and ensure quality.
5.4 Communications
If you subscribe to newsletters, product updates, or marketing communications, we may process:
-
Email address
-
Subscription preferences
-
Communication history
-
Marketing consent
-
Email interaction statistics (such as opens and clicks where legally permitted)
You may unsubscribe from marketing communications at any time.
6. ACCOUNT INFORMATION
6.1 Account Data
When using the Service, we maintain information associated with your Account, including:
-
Account creation date
-
Username
-
Account status
-
Subscription status
-
Login history
-
Security settings
-
Authentication preferences
-
Feature usage
-
Notification preferences
6.2 Authentication Information
To secure your Account, we may process:
-
Password hash
-
Multi-factor authentication settings
-
Login verification tokens
-
Device verification information
-
Security event logs
Passwords are stored using industry-standard cryptographic hashing techniques and are never stored in plain text.
7. BILLING AND PAYMENT INFORMATION
7.1 Payment Processing
Payments are processed through trusted third-party payment providers, such as Stripe.
Depending on your chosen payment method, the payment provider may process:
-
Name
-
Billing address
-
Payment method
-
Card issuer
-
Transaction identifiers
-
VAT information
-
Currency
-
Payment status
The Company does not store full payment card numbers or security codes.
7.2 Subscription Management
We process payment-related information to:
-
Activate subscriptions
-
Renew subscriptions
-
Prevent fraud
-
Process refunds
-
Comply with accounting obligations
-
Generate invoices
-
Provide customer support
8. AI INTERACTION DATA
8.1 AI Requests
When using AI-powered features, the Company may process information necessary to generate requested outputs.
Examples include:
-
User prompts
-
Selected financial instruments
-
Search queries
-
Watchlists
-
Preferences
-
Analytical requests
-
Market research requests
8.2 AI Responses
The Company may temporarily store AI-generated outputs in order to:
-
Display results
-
Improve service quality
-
Detect technical errors
-
Investigate abuse
-
Resolve customer support issues
AI-generated outputs are not used to create personalized financial profiles unless explicitly stated and supported by a lawful basis under applicable law.
8.3 AI Service Improvement
Where permitted by applicable law, anonymized or aggregated interaction data may be used to:
-
Improve AI performance
-
Detect hallucinations
-
Enhance response quality
-
Improve accuracy
-
Develop new AI functionality
Such processing is designed to avoid identifying individual users wherever reasonably possible.
9. TECHNICAL AND DEVICE INFORMATION
9.1 Device Information
To ensure security and compatibility, we may automatically collect technical information, including:
-
Device type
-
Operating system
-
Browser type
-
Browser version
-
Screen resolution
-
Language settings
-
Device identifiers
-
Time zone
-
Network information
9.2 IP Address
We may process your IP address for purposes including:
-
Security
-
Fraud prevention
-
Abuse detection
-
Geographic localization
-
Regulatory compliance
-
Network diagnostics
IP addresses are retained only for as long as reasonably necessary for these purposes or as required by applicable law.
9.3 Log Information
Our servers automatically generate logs that may include:
-
Login timestamps
-
Logout timestamps
-
Error logs
-
API requests
-
Authentication events
-
Session identifiers
-
Browser information
-
Security events
Server logs are used to maintain the security, reliability, and performance of the Service.
10. USAGE DATA
10.1 Platform Analytics
We may collect information regarding how Users interact with the Service, including:
-
Pages viewed
-
Time spent on pages
-
Navigation paths
-
Feature usage
-
Search activity
-
Dashboard interactions
-
Click events
-
Session duration
-
Subscription activity
10.2 Performance Monitoring
Usage information helps us:
-
Improve user experience
-
Optimize AI models
-
Identify software bugs
-
Improve platform stability
-
Measure feature popularity
-
Enhance product development
Where possible, analytics are performed using aggregated or pseudonymized data.
11. COOKIES AND TRACKING TECHNOLOGIES
11.1 Cookies
The Service uses cookies and similar technologies to:
-
Maintain user sessions
-
Remember preferences
-
Improve security
-
Analyze traffic
-
Measure performance
-
Enhance user experience
11.2 Types of Cookies
The Company may use:
-
Strictly Necessary Cookies
-
Functional Cookies
-
Analytics Cookies
-
Performance Cookies
-
Security Cookies
-
Preference Cookies
Marketing or advertising cookies will only be used where permitted by applicable law and, where required, after obtaining your consent.
11.3 Cookie Preferences
You may manage your cookie preferences through:
-
Our cookie consent banner
-
Your browser settings
-
Device settings, where applicable
Disabling certain cookies may affect the functionality of the Service.
12. LEGAL BASIS FOR PROCESSING PERSONAL DATA
The Company processes Personal Data only where a valid legal basis exists under Article 6 of the General Data Protection Regulation ("GDPR").
Depending on the circumstances, one or more legal bases may apply.
12.1 Performance of a Contract
We process Personal Data where necessary to perform our contractual obligations to you.
This includes processing necessary to:
-
create and manage your Account;
-
authenticate your identity;
-
provide access to subscription services;
-
generate AI-powered market analyses;
-
process payments;
-
provide customer support;
-
maintain platform functionality;
-
deliver purchased services.
Without such processing, the Company would be unable to provide the Service.
12.2 Consent
Certain processing activities are based upon your explicit consent.
Examples include:
-
marketing communications;
-
newsletters;
-
optional cookies;
-
promotional emails;
-
product announcements;
-
surveys.
You may withdraw your consent at any time.
Withdrawal of consent shall not affect processing carried out before such withdrawal.
12.3 Legitimate Interests
The Company processes Personal Data where necessary for its legitimate business interests, provided that such interests are not overridden by your fundamental rights and freedoms.
Legitimate interests include:
-
improving platform functionality;
-
developing AI technologies;
-
preventing fraud;
-
cybersecurity;
-
customer support;
-
service analytics;
-
internal reporting;
-
quality assurance;
-
enforcing contractual rights;
-
detecting abuse;
-
improving user experience.
Whenever processing relies upon legitimate interests, the Company performs an appropriate balancing assessment.
12.4 Legal Obligations
Certain Personal Data must be processed to comply with applicable legal obligations.
These may include obligations relating to:
-
accounting;
-
taxation;
-
anti-fraud measures;
-
consumer protection;
-
judicial requests;
-
regulatory investigations;
-
law enforcement requests.
12.5 Protection of Vital Interests
In exceptional circumstances, Personal Data may be processed where necessary to protect the vital interests of an individual.
13. PURPOSES OF PROCESSING
The Company processes Personal Data only for specified, explicit, and legitimate purposes.
13.1 Account Administration
Personal Data is processed to:
-
create user accounts;
-
authenticate users;
-
maintain account settings;
-
manage subscriptions;
-
recover lost accounts;
-
verify ownership;
-
prevent unauthorized access.
13.2 Service Delivery
Processing enables us to:
-
operate the platform;
-
generate AI analyses;
-
provide dashboards;
-
deliver investment research;
-
maintain watchlists;
-
display market information;
-
provide premium features.
13.3 Customer Support
Personal Data may be processed to:
-
respond to enquiries;
-
resolve technical issues;
-
investigate complaints;
-
improve support quality;
-
communicate with Users.
13.4 Security
Processing is necessary to:
-
detect fraud;
-
monitor suspicious activity;
-
prevent cyberattacks;
-
investigate security incidents;
-
protect infrastructure;
-
secure user accounts.
13.5 Billing
We process Personal Data to:
-
process subscription payments;
-
issue invoices;
-
administer refunds;
-
manage renewals;
-
verify payment status.
13.6 Legal Compliance
Processing may be required to:
-
comply with applicable laws;
-
respond to court orders;
-
satisfy accounting obligations;
-
fulfill tax obligations;
-
comply with regulatory requirements.
14. AI PROCESSING
14.1 AI Functionality
The Service uses artificial intelligence to assist in generating:
-
market summaries;
-
financial news analysis;
-
trend identification;
-
technical observations;
-
educational investment insights;
-
statistical evaluations.
AI processing is designed to support users in conducting independent research.
14.2 AI Inputs
Information submitted to AI-powered features may be processed for the purpose of generating requested outputs.
Examples include:
-
user prompts;
-
selected companies;
-
stock symbols;
-
watchlists;
-
search requests;
-
analytical questions.
Users should avoid submitting confidential or unnecessary personal information when interacting with AI features.
14.3 AI Outputs
AI-generated outputs are automatically created and may contain inaccuracies, omissions, or outdated information.
The Company does not guarantee the accuracy, completeness, or reliability of AI-generated content.
14.4 AI Improvement
Where permitted by applicable law, anonymized or aggregated interaction data may be used to:
-
improve AI models;
-
enhance response quality;
-
reduce errors;
-
identify technical issues;
-
optimize system performance.
The Company does not use identifiable personal information for AI model training unless a lawful basis exists and such use is clearly disclosed.
15. AUTOMATED DECISION-MAKING
The Company does not make decisions producing legal or similarly significant effects based solely on automated processing within the meaning of Article 22 GDPR.
AI-generated analyses are informational and do not replace human decision-making.
Users remain solely responsible for evaluating information before making financial decisions.
16. SHARING PERSONAL DATA
The Company does not sell Personal Data.
Personal Data may be shared only where necessary for legitimate business purposes or where required by law.
Recipients may include:
-
payment processors;
-
cloud hosting providers;
-
analytics providers;
-
customer support providers;
-
identity verification providers;
-
legal advisors;
-
auditors;
-
regulatory authorities.
All recipients are required to process Personal Data in accordance with applicable data protection legislation.
17. THIRD-PARTY SERVICE PROVIDERS
The Company may engage carefully selected third-party providers to support operation of the Service.
These providers may process Personal Data solely on our behalf and only in accordance with written contractual agreements.
Examples include providers of:
-
payment processing;
-
cloud infrastructure;
-
authentication;
-
email delivery;
-
customer support;
-
analytics;
-
security monitoring;
-
AI services.
Where providers act as processors, they are contractually required to implement appropriate technical and organizational security measures.
18. INTERNATIONAL DATA TRANSFERS
Some third-party service providers may process Personal Data outside the European Economic Area ("EEA").
Where Personal Data is transferred internationally, the Company ensures that appropriate safeguards are implemented in accordance with Chapter V GDPR.
Such safeguards may include:
-
European Commission Adequacy Decisions;
-
Standard Contractual Clauses (SCCs);
-
other legally recognized transfer mechanisms.
The Company regularly reviews international transfers to ensure ongoing compliance with applicable data protection laws.
19. DATA PROCESSING AGREEMENTS
Where Personal Data is processed by third-party processors on behalf of the Company, written Data Processing Agreements ("DPAs") are maintained where required by Article 28 GDPR.
These agreements require processors to:
-
process Personal Data only on documented instructions;
-
implement appropriate security measures;
-
assist with GDPR compliance;
-
support the exercise of data subject rights;
-
notify the Company of security incidents where required;
-
delete or return Personal Data upon termination of services, unless retention is required by law.
20. DATA RETENTION
20.1 Retention Principles
The Company retains Personal Data only for as long as necessary to fulfill the purposes for which it was collected, to comply with applicable legal obligations, resolve disputes, enforce agreements, and protect the security and integrity of the Service.
When Personal Data is no longer required, it will be securely deleted, anonymized, or otherwise irreversibly de-identified, unless continued retention is required by applicable law.
20.2 Account Information
Personal Data associated with your Account is generally retained for the duration of your active Account.
Following Account deletion, Personal Data may be retained for a limited period where necessary to:
-
comply with legal obligations;
-
resolve disputes;
-
prevent fraud;
-
investigate security incidents;
-
enforce contractual rights;
-
maintain backup systems.
After the applicable retention period expires, the information will be securely deleted or anonymized.
20.3 Billing Records
Financial records, invoices, transaction information, and accounting documentation may be retained for the period required under applicable accounting and tax legislation.
20.4 Security Logs
Security-related logs may be retained for a limited period to:
-
investigate unauthorized access;
-
detect fraud;
-
monitor cybersecurity incidents;
-
comply with regulatory obligations;
-
improve system security.
20.5 Customer Support Records
Communications with Customer Support may be retained to:
-
resolve ongoing issues;
-
improve customer service;
-
document dispute resolution;
-
comply with legal obligations.
20.6 AI Interaction Data
AI prompts and generated responses may be temporarily retained to:
-
provide requested outputs;
-
investigate technical issues;
-
prevent misuse;
-
improve platform performance where permitted by law.
Where feasible, AI interaction data used for service improvement will be anonymized or aggregated.
20.7 Backup Copies
Encrypted backup copies of Personal Data may remain within disaster recovery systems for a limited period before being automatically overwritten or securely deleted.
21. SECURITY OF PERSONAL DATA
21.1 Security Commitment
The Company implements appropriate technical and organizational measures designed to protect Personal Data against accidental or unlawful:
-
destruction;
-
loss;
-
alteration;
-
unauthorized disclosure;
-
unauthorized access;
-
misuse.
Security measures are regularly reviewed and updated in light of technological developments and identified risks.
21.2 Technical Safeguards
Security measures may include:
-
encryption of data in transit;
-
encryption of sensitive data at rest where appropriate;
-
secure authentication mechanisms;
-
access controls;
-
firewalls;
-
intrusion detection systems;
-
vulnerability monitoring;
-
secure software development practices;
-
regular security updates.
21.3 Organizational Safeguards
The Company maintains organizational measures including:
-
confidentiality obligations for personnel;
-
access based on business need;
-
internal security policies;
-
staff training;
-
incident response procedures;
-
periodic security assessments.
21.4 Access Control
Access to Personal Data is limited to authorized personnel who require such access in order to perform their job responsibilities.
Access permissions are regularly reviewed and revoked where no longer required.
21.5 Security Monitoring
The Company may continuously monitor systems to identify:
-
unauthorized access attempts;
-
malicious activity;
-
suspicious login behavior;
-
abnormal usage patterns;
-
cybersecurity threats.
Monitoring is performed solely for security, fraud prevention, and operational purposes.
22. PERSONAL DATA BREACHES
22.1 Incident Response
The Company maintains procedures designed to identify, investigate, contain, and remediate Personal Data breaches without undue delay.
22.2 Notification
Where required by applicable law, the Company shall notify the competent supervisory authority and affected individuals of a Personal Data breach within the applicable legal timeframes.
22.3 Mitigation
Following a security incident, the Company may implement measures including:
-
password resets;
-
suspension of compromised Accounts;
-
enhanced monitoring;
-
infrastructure improvements;
-
additional security controls.
23. YOUR GDPR RIGHTS
If you are located within the European Economic Area ("EEA"), the United Kingdom, or another jurisdiction providing similar legal protections, you may have the following rights under applicable data protection legislation.
23.1 Right of Access
You may request confirmation of whether we process your Personal Data.
Where applicable, you may request access to:
-
categories of Personal Data;
-
purposes of processing;
-
recipients;
-
retention periods;
-
legal basis for processing;
-
safeguards relating to international transfers.
23.2 Right to Rectification
You have the right to request correction of inaccurate or incomplete Personal Data.
The Company will make reasonable efforts to update inaccurate information without undue delay.
23.3 Right to Erasure ("Right to be Forgotten")
Subject to applicable law, you may request deletion of your Personal Data where:
-
the data is no longer necessary;
-
consent has been withdrawn;
-
processing is unlawful;
-
legal requirements permit deletion.
This right is not absolute and may be limited where retention is required by law or necessary to establish, exercise, or defend legal claims.
23.4 Right to Restrict Processing
You may request that processing of your Personal Data be restricted under circumstances provided by applicable law, including where:
-
the accuracy of data is contested;
-
processing is unlawful;
-
the Company no longer requires the data but you require it for legal claims.
23.5 Right to Data Portability
Where processing is based on consent or contract and carried out by automated means, you may request a copy of your Personal Data in a structured, commonly used, and machine-readable format.
Where technically feasible, you may request transmission directly to another controller.
23.6 Right to Object
You may object to processing based upon the Company's legitimate interests where your particular circumstances justify such objection.
The Company will assess whether compelling legitimate grounds override your interests, rights, and freedoms.
23.7 Right to Withdraw Consent
Where processing relies upon consent, you may withdraw that consent at any time.
Withdrawal shall not affect processing carried out before consent was withdrawn.
23.8 Right to Lodge a Complaint
If you believe that the processing of your Personal Data violates applicable data protection law, you have the right to lodge a complaint with the competent supervisory authority.
For users in Sweden, the competent supervisory authority is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten -- IMY).
24. EXERCISING YOUR RIGHTS
You may exercise your privacy rights by contacting the Company using the contact details provided in this Privacy Policy.
To protect your Personal Data, the Company may request reasonable information to verify your identity before fulfilling your request.
Requests will be handled within the time limits required under applicable law unless an extension is permitted.
The exercise of your rights is generally free of charge, although reasonable administrative fees may be charged where requests are manifestly unfounded, excessive, or repetitive, as permitted by law.
25. CHILDREN'S PRIVACY
The Service is intended exclusively for individuals who are at least eighteen (18) years of age.
The Company does not knowingly collect Personal Data from children.
If the Company becomes aware that Personal Data relating to a child has been collected without appropriate legal authorization, reasonable steps will be taken to delete such information without undue delay.
Parents or legal guardians who believe that a child has provided Personal Data are encouraged to contact the Company.
26. INTERNATIONAL COMPLIANCE
26.1 Global Availability
The Service may be accessible from countries outside Sweden and the European Economic Area ("EEA").
Regardless of where the Service is accessed, the Company is committed to processing Personal Data in accordance with applicable data protection legislation.
Where local laws provide additional privacy rights, the Company will comply with those laws where applicable.
26.2 Compliance with the GDPR
Where the General Data Protection Regulation ("GDPR") applies, the Company processes Personal Data in accordance with its principles, including:
-
Lawfulness;
-
Fairness;
-
Transparency;
-
Purpose Limitation;
-
Data Minimization;
-
Accuracy;
-
Storage Limitation;
-
Integrity and Confidentiality;
-
Accountability.
26.3 International Transfers
Where Personal Data is transferred outside the EEA, the Company implements appropriate safeguards as required by applicable law.
Such safeguards may include:
-
European Commission Adequacy Decisions;
-
Standard Contractual Clauses (SCCs);
-
Binding Corporate Rules where applicable;
-
other legally recognized transfer mechanisms.
27. THIRD-PARTY WEBSITES
The Service may contain links to third-party websites, applications, or online services.
The Company is not responsible for:
-
privacy practices;
-
security practices;
-
content;
-
policies;
-
services;
provided by third parties.
Users are encouraged to review the privacy policies of third-party services before providing Personal Data.
28. THIRD-PARTY PROVIDERS
The Company relies on trusted third-party providers to operate the Service.
Examples may include providers responsible for:
-
cloud hosting;
-
authentication;
-
payment processing;
-
analytics;
-
email delivery;
-
AI services;
-
customer support;
-
infrastructure monitoring;
-
fraud detection.
Each provider is selected with consideration for applicable privacy and security requirements.
Where required by law, appropriate contractual safeguards are implemented.
29. BUSINESS TRANSFERS
In the event of:
-
a merger;
-
acquisition;
-
restructuring;
-
financing transaction;
-
sale of assets;
-
transfer of ownership;
Personal Data may be transferred to the acquiring entity, provided that such entity agrees to process Personal Data in accordance with this Privacy Policy and applicable law.
Where legally required, affected users will be informed of such transfers.
30. CHANGES TO THIS PRIVACY POLICY
The Company may revise this Privacy Policy from time to time.
Reasons for updates may include:
-
legal developments;
-
regulatory guidance;
-
technological improvements;
-
new Service features;
-
security enhancements;
-
operational changes.
Where required by applicable law, Users will receive reasonable notice of material changes.
The updated Privacy Policy becomes effective on the date specified at the beginning of the document.
Continued use of the Service following the effective date constitutes acknowledgment of the revised Privacy Policy.
31. DATA PROTECTION OFFICER
Where required under applicable law, the Company shall appoint a Data Protection Officer ("DPO").
If appointed, the DPO may be contacted regarding:
-
privacy questions;
-
GDPR rights;
-
Personal Data processing;
-
security concerns;
-
complaints relating to Personal Data.
If the Company is not legally required to appoint a DPO, privacy enquiries may instead be directed to the Company's designated privacy contact.
32. CONTACT INFORMATION
If you have any questions regarding this Privacy Policy or the processing of your Personal Data, please contact:
Concept Bandits Sweden AB
Company Registration Number: 559445-4745
Knäppingsborgsgatan 38
602 26 Norrköping
Sweden
Email: [Privacy Email]
Website: [Website URL]
The Company will make reasonable efforts to respond to privacy-related enquiries without undue delay and within the timeframes required by applicable law.
33. REGULATORY AUTHORITY
If you believe that the processing of your Personal Data violates applicable data protection legislation, you may contact the competent supervisory authority.
For users located in Sweden, the competent authority is:
Integritetsskyddsmyndigheten (IMY)
Users residing in other jurisdictions may also contact the supervisory authority responsible in their country of residence where permitted by applicable law.
34. ENTIRE PRIVACY POLICY
This Privacy Policy, together with the Company's:
-
Terms and Conditions;
-
Cookie Policy;
-
Subscription Policy;
-
Refund Policy;
-
AI Disclaimer;
-
Investment Disclaimer;
constitutes the complete statement regarding how the Company processes Personal Data in connection with the Service.
Where conflicts arise between this Privacy Policy and mandatory provisions of applicable data protection legislation, the mandatory legal provisions shall prevail.
35. EFFECTIVE DATE
This Privacy Policy becomes effective on the date stated at the beginning of this document and remains in effect until amended or replaced by the Company.
ACKNOWLEDGEMENT
By creating an Account, purchasing a Subscription, or otherwise using the Service, you acknowledge that you have read and understood this Privacy Policy.
Where consent is required by applicable law, the Company will request such consent separately through appropriate consent mechanisms.