Privacy Policy
Mapping Talents AB cares about your privacy. This policy explains which personal data we process, why, how long we keep it, and what rights you have under the General Data Protection Regulation (GDPR).
Updated
1. Data controller
Company reg. no. 559494-8670Lyckåsvägen 9, 136 72 Vendelsö, Sweden
Written contact goes through the contact form on this website. We publish no email address here: published addresses are harvested automatically and drown in spam — the form reaches us directly and we reply from a real address.
We have not appointed a Data Protection Officer. Send any data protection questions through the contact form, or to the postal address above.
2. When does this policy apply?
This policy applies when you:
- visit mappingtalents.com or any of its subdomains
- contact us through a form, email, phone, WhatsApp or social media
- are a customer, prospective customer, partner or supplier
- are a consultant sharing your CV with us for an assignment
- use an app, chatbot or integration provided by Mapping Talents AB, including via Meta (Facebook, Instagram, Messenger and WhatsApp)
Solutions we build for clients. When we develop or operate an AI agent, chatbot or automation for a company, that company is normally the data controller for its end users' data. We then act as a data processor and handle the data under a data processing agreement. Please direct questions about such data to that company first.
3. What data we process, why, and on what legal basis
| Situation | Data | Purpose | Legal basis |
|---|---|---|---|
| Contact and enquiries | Name, email, phone, company, message content | Answer questions, send quotes | Legitimate interest |
| Customer and contract relationship | Contact details, role, contract and billing details | Perform the contract, invoice, provide support | Contract |
| Bookkeeping | Invoices and vouchers | Comply with the Swedish Bookkeeping Act (bokföringslagen) | Legal obligation |
| Consultants and candidates | CV, skills, experience, availability, rate | Present you for assignments to clients and brokers | Consent or contract |
| Meta apps and integrations | Public profile (name, profile picture), app-scoped user ID, messages you send us, and email where applicable | Deliver the service you use, e.g. chat replies, bookings or quotes | Contract or legitimate interest |
| Website analytics | Anonymised or pseudonymised visit data (pages, device, approximate location) | Improve the website | Legitimate interest or consent (see section 7) |
| B2B marketing | Name, email, job title, company | Send relevant information about our services | Legitimate interest; you can opt out at any time |
We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.
4. AI and personal data
We use AI models in our services, e.g. to understand questions, summarise documents and suggest replies.
- We only send the data needed for the task
- We do not use your data to train AI models
- We choose providers that are contractually bound not to train their models on our data
- For sensitive data, we may use models running on our own infrastructure within the EU
5. Who we share data with
We never sell personal data. We only share it with:
- Suppliers (data processors) for hosting and operations, email, CRM (Customer Relationship Management), invoicing, analytics and AI models. They may only process data on our instructions
- Clients and consultant brokers, when a consultant has agreed to be presented for an assignment
- Meta Platforms, to the extent you yourself use Facebook, Instagram, Messenger or WhatsApp to communicate with us. Meta's own processing is governed by Meta's terms and privacy policy
- Public authorities, when required by law
6. Transfers outside the EU/EEA
Some providers, e.g. of AI and cloud services, may process data outside the EU/EEA (European Economic Area), mainly in the United States. We make sure such transfers are lawful under the GDPR, either through the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses, with supplementary safeguards where needed. Where possible we store data within the EU, including in the AWS (Amazon Web Services) Ireland region (eu-west-1).
7. Cookies and website statistics
Necessary cookies are required for the site to work and are always set.
No measurement or marketing tool loads before you have made a choice in the cookie banner. We use Google Consent Mode v2, which means the tools are told your choice before they are allowed to set cookies or collect data.
If you accept, the following load through Google Tag Manager:
| Tool | Purpose | Provider |
|---|---|---|
| Google Analytics 4 | Visitor statistics and how the site is used | |
| Meta Pixel | Advertising measurement and audiences | Meta Platforms |
| LinkedIn Insight Tag | Advertising measurement and audiences |
The consent banner is our own and is served from our own server. We use no external consent service, and the banner sets no third-party cookies. Your choice is stored for 182 days and you can change it at any time via Manage cookies at the bottom of the page. Rejecting is as easy as accepting.
8. How long we keep data
| Data | Retention period |
|---|---|
| Enquiries that do not lead to a contract | 12 months after last contact |
| Customer and contract data | Contract term plus 3 years (limitation period for certain claims) |
| Bookkeeping records | 7 years under the Swedish Bookkeeping Act |
| Consultant CVs | Until you withdraw consent, but no more than 24 months after last contact |
| Data from Meta apps | As long as you use the service, then deleted within 30 days |
| Web analytics | Up to 25 months |
9. Your rights
Under the GDPR you have the right to:
- access your data (a copy of the data we hold)
- have inaccurate data corrected
- have your data erased
- restrict processing
- object to processing based on legitimate interest, including direct marketing
- receive your data in a machine-readable format (data portability)
- withdraw consent at any time
How to exercise your rights: Exercise your rights.
How to request deletion of data from our apps: Data deletion.
If you are unhappy with how we process your data, you can lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), www.imy.se.
10. Security
We protect data with technical and organisational measures:
- encryption in transit and at rest
- access control and two-factor authentication
- passwords and keys managed in an encrypted vault
- networks not unnecessarily exposed to the internet
- logging and regular backups
11. Children
Our services are aimed at businesses and adults. We do not knowingly collect data about children under 16.
12. Changes
We may update this policy. The date at the top shows when it was last changed. We will announce material changes on the website or directly to those affected.
Data controller
Mapping Talents ABLyckåsvägen 9
136 72 Vendelsö
Org.nr 559494-8670 · VAT SE559494867001
Contact us
We do not publish an email address on this site. All written contact — including requests for access, rectification or erasure — goes through the form on the contact page.
Go to the contact form