Privacy Policy & GDPR Notice
Last updated: July 28, 2026
1. Commitment to Privacy & Discretion
Reputera Private ("we", "us") operates in an environment where discretion, confidentiality, and data protection form the cornerstone of our operations. We process personal data strictly in accordance with the EU General Data Protection Regulation (GDPR) and Swedish data protection legislation. This Privacy Policy outlines how we collect, use, and protect information submitted via our website (private.reputera.se) and during initial intake.
2. Personal Data Collection
We adhere strictly to the principle of data minimization. On our website, we only collect personal data when voluntarily submitted, such as during: - Confidential consultation requests (name/representative, secure contact channel such as Signal/email, region, and estate classification). - Document intake inquiries for professional advisors (professional email address). We never process sensitive personal data or estate telemetry without a formal Non-Disclosure Agreement (NDA) and Data Processing Agreement (DPA) in place.
3. Legal Basis and Purpose of Processing
The processing of your personal data is based on the following legal grounds and purposes: - **Contractual Performance / Pre-contractual steps:** To respond to consultation inquiries, transmit NDAs, and scope verification mandates. - **Legitimate Interest:** To maintain the security of our web infrastructure and communicate with verified professional advisors. - **Legal Obligation:** To comply with statutory accounting and compliance requirements.
4. Retention & Deletion
Inquiries that do not progress to an active verification engagement are securely purged within 90 days. For active clients, data retention and purge protocols are governed in detail under our formal Data Processing Agreement (DPA Appendix D), ensuring temporary audit trails are erased according to strict retention schedules.
5. Third-Party & Cross-Border Transfers
Reputera Private never sells or shares personal data with third parties for marketing purposes. Data is processed within the EU/EEA. If secure third-party communication channels outside the EU/EEA are utilized, transfers are strictly safeguarded under standard contractual clauses (SCCs) approved by the European Commission.
6. Your Individual Rights
Under the GDPR, you have the right to: - Access the personal data held about you (subject access request). - Request rectification of inaccurate data or erasure ("right to be forgotten"). - Request restriction of processing or object to processing. - File a complaint with the Swedish Authority for Privacy Protection (IMY) or your local supervisory authority. For data protection inquiries, contact our privacy team at: privacy@reputera.se.