Skip to content
mappingtalents

Privacy Policy

Mapping Talents AB cares about your privacy. This policy explains which personal data we process, why, how long we keep it, and what rights you have under the General Data Protection Regulation (GDPR).

Updated

1. Data controller

Company reg. no. 559494-8670Lyckåsvägen 9, 136 72 Vendelsö, Sweden

Written contact goes through the contact form on this website. We publish no email address here: published addresses are harvested automatically and drown in spam — the form reaches us directly and we reply from a real address.

We have not appointed a Data Protection Officer. Send any data protection questions through the contact form, or to the postal address above.

2. When does this policy apply?

This policy applies when you:

  • visit mappingtalents.com or any of its subdomains
  • contact us through a form, email, phone, WhatsApp or social media
  • are a customer, prospective customer, partner or supplier
  • are a consultant sharing your CV with us for an assignment
  • use an app, chatbot or integration provided by Mapping Talents AB, including via Meta (Facebook, Instagram, Messenger and WhatsApp)

Solutions we build for clients. When we develop or operate an AI agent, chatbot or automation for a company, that company is normally the data controller for its end users' data. We then act as a data processor and handle the data under a data processing agreement. Please direct questions about such data to that company first.

3. What data we process, why, and on what legal basis

SituationDataPurposeLegal basis
Contact and enquiriesName, email, phone, company, message contentAnswer questions, send quotesLegitimate interest
Customer and contract relationshipContact details, role, contract and billing detailsPerform the contract, invoice, provide supportContract
BookkeepingInvoices and vouchersComply with the Swedish Bookkeeping Act (bokföringslagen)Legal obligation
Consultants and candidatesCV, skills, experience, availability, ratePresent you for assignments to clients and brokersConsent or contract
Meta apps and integrationsPublic profile (name, profile picture), app-scoped user ID, messages you send us, and email where applicableDeliver the service you use, e.g. chat replies, bookings or quotesContract or legitimate interest
Website analyticsAnonymised or pseudonymised visit data (pages, device, approximate location)Improve the websiteLegitimate interest or consent (see section 7)
B2B marketingName, email, job title, companySend relevant information about our servicesLegitimate interest; you can opt out at any time

We do not make decisions based solely on automated processing that have legal or similarly significant effects on you.

4. AI and personal data

We use AI models in our services, e.g. to understand questions, summarise documents and suggest replies.

  • We only send the data needed for the task
  • We do not use your data to train AI models
  • We choose providers that are contractually bound not to train their models on our data
  • For sensitive data, we may use models running on our own infrastructure within the EU

5. Who we share data with

We never sell personal data. We only share it with:

  • Suppliers (data processors) for hosting and operations, email, CRM (Customer Relationship Management), invoicing, analytics and AI models. They may only process data on our instructions
  • Clients and consultant brokers, when a consultant has agreed to be presented for an assignment
  • Meta Platforms, to the extent you yourself use Facebook, Instagram, Messenger or WhatsApp to communicate with us. Meta's own processing is governed by Meta's terms and privacy policy
  • Public authorities, when required by law

6. Transfers outside the EU/EEA

Some providers, e.g. of AI and cloud services, may process data outside the EU/EEA (European Economic Area), mainly in the United States. We make sure such transfers are lawful under the GDPR, either through the EU–US Data Privacy Framework or the European Commission's Standard Contractual Clauses, with supplementary safeguards where needed. Where possible we store data within the EU, including in the AWS (Amazon Web Services) Ireland region (eu-west-1).

7. Cookies and website statistics

Necessary cookies are required for the site to work and are always set.

No measurement or marketing tool loads before you have made a choice in the cookie banner. We use Google Consent Mode v2, which means the tools are told your choice before they are allowed to set cookies or collect data.

If you accept, the following load through Google Tag Manager:

ToolPurposeProvider
Google Analytics 4Visitor statistics and how the site is usedGoogle
Meta PixelAdvertising measurement and audiencesMeta Platforms
LinkedIn Insight TagAdvertising measurement and audiencesLinkedIn

The consent banner is our own and is served from our own server. We use no external consent service, and the banner sets no third-party cookies. Your choice is stored for 182 days and you can change it at any time via Manage cookies at the bottom of the page. Rejecting is as easy as accepting.

8. How long we keep data

DataRetention period
Enquiries that do not lead to a contract12 months after last contact
Customer and contract dataContract term plus 3 years (limitation period for certain claims)
Bookkeeping records7 years under the Swedish Bookkeeping Act
Consultant CVsUntil you withdraw consent, but no more than 24 months after last contact
Data from Meta appsAs long as you use the service, then deleted within 30 days
Web analyticsUp to 25 months

9. Your rights

Under the GDPR you have the right to:

  • access your data (a copy of the data we hold)
  • have inaccurate data corrected
  • have your data erased
  • restrict processing
  • object to processing based on legitimate interest, including direct marketing
  • receive your data in a machine-readable format (data portability)
  • withdraw consent at any time

How to exercise your rights: Exercise your rights.

How to request deletion of data from our apps: Data deletion.

If you are unhappy with how we process your data, you can lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), www.imy.se.

10. Security

We protect data with technical and organisational measures:

  • encryption in transit and at rest
  • access control and two-factor authentication
  • passwords and keys managed in an encrypted vault
  • networks not unnecessarily exposed to the internet
  • logging and regular backups

11. Children

Our services are aimed at businesses and adults. We do not knowingly collect data about children under 16.

12. Changes

We may update this policy. The date at the top shows when it was last changed. We will announce material changes on the website or directly to those affected.

Data controller

Mapping Talents AB
Lyckåsvägen 9
136 72 Vendelsö
Org.nr 559494-8670 · VAT SE559494867001

Contact us

We do not publish an email address on this site. All written contact — including requests for access, rectification or erasure — goes through the form on the contact page.

Go to the contact form