Privacy Policy — RAMSagent Skip to content

Privacy Policy

Last updated: 2026-01-01

Grejps AB ("we", "us") cares about your privacy. This policy explains how we collect, use, and protect your personal data.

1. Who is responsible?

Data Controller

Grejps AB Reg. no: 559564-7438 Email: info@ramsagent.com

Data Protection Officer (DPO)

We have assessed that our operations do not require a formal Data Protection Officer. Instead, all privacy matters are handled directly by our security team at info@ramsagent.com.

2. What data do we collect?

2.1 Account Information

  • Name, email address, phone number
  • Company name and registration number
  • Billing information
  • Profile picture (optional)

2.2 Usage Data

  • Login information and session data
  • Features you use and how often
  • Technical information (device, browser, IP address)
  • Notification history

2.3 Content Data

  • Text and documents you create in the Service
  • Voice recordings during dictation (see specific section below)

3. How do we use your data?

We process your data to:

  • Provide and improve the Service
  • Administer your account and billing
  • Provide customer support
  • Send important information about the Service
  • Comply with legal requirements

Legal basis: Performance of contract, legitimate interest, consent (for marketing), and legal obligation.

4. Specific Data Processing

4.1 Transcription Only (Voice Data)

When you use the voice recording feature, your voice is used solely to convert speech to text. We do not create or store any biometric profiles ("voiceprints") that can identify you.

4.2 Immediate Deletion

The audio file is sent encrypted for transcription and is automatically deleted immediately after the text is generated. No audio data is saved long-term.

4.3 Signature Data

When you sign digitally, we save:

  • Your signature (graphical representation)
  • Timestamp of the signing
  • Your IP address (for authenticity)
  • The document hash (to verify it hasn't changed)

This data is stored as long as the document remains and may be needed for legal verification.

5. AI Processing

5.1 How AI is Used

The Service uses AI to generate text suggestions. Your data is processed to provide you with relevant results.

5.2 No External Training

We have agreements with our AI providers guaranteeing that your data is not used to train their general models.

5.3 Internal Improvement

We may use anonymized and aggregated data to improve our own algorithms. All personal information is removed before such use.

6. Encryption and Security

6.1 Protecting Your Data

  • All data is encrypted during storage and transfer
  • We use industry-standard security solutions
  • Access to data is strictly limited to authorized personnel

6.2 Right to be Forgotten

When you request deletion of your account, the encryption keys for your data are destroyed, making the information permanently inaccessible – even in backups.

7. Where is data stored?

Your data is stored with Supabase in Frankfurt, Germany (EU). For AI analysis, data may be temporarily transferred to OpenAI (USA), Anthropic (USA) or Google Gemini (EU/USA) protected by the EU-US Data Privacy Framework or EU Commission Standard Contractual Clauses. Audio files are deleted immediately after transcription. Payment data is handled by Stripe within the EU/USA.

8. How long is data stored?

We retain your data according to the following principles:

  • Account data: As long as the account is active, plus 12 months after deletion
  • Content data (documents, risk assessments, work preparations): As long as the account is active, deleted upon account removal
  • Signature data: As long as the signed document exists, minimum 10 years for legal verification
  • Voice recordings: Deleted immediately after transcription
  • Usage logs: 12 months
  • Images and attachments: As long as the linked risk assessment exists, deleted upon account removal
  • Support tickets: 24 months after the ticket is closed
  • Billing and payment data: As required by accounting law (7 years)

9. Your Rights

You have the right to:

  • Access your data
  • Request correction of incorrect data
  • Request deletion ("right to be forgotten")
  • Object to certain processing
  • Request data portability
  • Withdraw consent

Contact us at info@ramsagent.com to exercise your rights.

10. Complaints

You have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe we are processing your data incorrectly.

11. Changes

We may update this policy. significant changes will be notified via email or in the Service.\nContact: info@ramsagent.com

Have questions?

Contact us at info@ramsagent.com

info@ramsagent.com