Privacy Policy

Last updated: February 7, 2026

At Vantacron, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the General Data Protection Regulation (GDPR) and Swedish data protection laws.

1. Data Controller

Simon Kjellner EF

Organization Number: 060630-7254Address: Timmergrand 1, 549 63 Skovde, SwedenEmail: [email protected]Phone: +46 76 145 15 98

As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with applicable data protection laws.

2. Personal Data We Collect

Account Information

When you create an account, we collect:

  • Full name
  • Email address
  • Company name (optional)
  • Password (stored encrypted)

Payment Information

Payment processing is handled by Stripe. We do not store your credit card details. Stripe may collect payment card numbers, billing addresses, and transaction history. Please refer to Stripe's Privacy Policy for details.

Usage Data

We automatically collect:

  • IP address
  • Browser type and version
  • Operating system
  • Pages visited and features used
  • Date and time of access
  • Referring website

Website Analysis Data

When you use our SEO analysis features, we process:

  • URLs and domains you choose to analyze
  • Website content accessible through crawling
  • Technical SEO data from your websites
  • Analysis results and reports generated

Integration Data

If you connect third-party services, we may access:

  • Google Search Console data (search performance, indexing status)
  • Google Analytics data (traffic, user behavior)

You can disconnect these integrations at any time from your account settings.

4. Third-Party Data Processors

We work with trusted third-party service providers who process data on our behalf. All processors are bound by data processing agreements that ensure GDPR compliance.

ServicePurposeLocation
StripePayment processingUS (EU-US DPF certified)
DataForSEOSEO data and backlink analysisEU
GoogleSearch Console and Analytics integrationsUS (EU-US DPF certified)
SupabaseDatabase hostingEU

Data Processing Agreement (DPA): Business customers requiring a DPA for their compliance needs can request one by contacting [email protected].

5. International Data Transfers

Primary Storage: Your data is primarily stored within the European Union (EU).

Transfers Outside EU: Some of our service providers (Stripe, Google) are based in the United States. These transfers are protected by:

  • EU-US Data Privacy Framework (DPF) certification
  • Standard Contractual Clauses (SCCs) approved by the European Commission
  • Additional technical and organizational safeguards

6. Data Retention

Active Accounts

Data is retained for as long as your account remains active.

Deleted Accounts

Personal data is retained for 1 year after account deletion for legal compliance purposes (tax records, dispute resolution).

Payment Records

Transaction records are retained for 7 years as required by Swedish accounting law (Bokforingslagen).

Server Logs

Technical logs are automatically deleted after 90 days.

7. Your Rights Under GDPR

Under the General Data Protection Regulation (Articles 15-22), you have the following rights:

Right of Access: Request a copy of all personal data we hold about you.
Right to Rectification: Request correction of inaccurate or incomplete personal data.
Right to Erasure: Request deletion of your personal data ('right to be forgotten').
Right to Restrict Processing: Request limitation of how we process your data.
Right to Data Portability: Receive your data in a structured, machine-readable format.
Right to Object: Object to processing based on legitimate interest or for direct marketing.
Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.

How to Exercise Your Rights

You can exercise most of these rights directly through your Vantacron account:

  • Data Export: Request a full export of your data from Account Settings > Privacy > Export Data
  • Account Deletion: Delete your account from Account Settings > Privacy > Delete Account
  • Data Summary: View a summary of all data we store about you in Account Settings > Privacy

For other requests or assistance, contact us at [email protected]. We will respond within 30 days as required by GDPR.

Right to Lodge a Complaint

If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Swedish supervisory authority:

Integritetsskyddsmyndigheten (IMY)

Box 8114, 104 20 Stockholm, Sweden

Website: www.imy.se

8. Cookies

Essential Cookies

These cookies are strictly necessary for the operation of our platform and are always active:

  • Session cookies: To keep you logged in during your visit
  • Authentication tokens: To securely verify your identity
  • Security cookies: To protect against cross-site request forgery
  • Cookie consent preference: To remember your cookie choices

Analytics & Advertising Cookies

With your consent, we use the following third-party cookies and tracking technologies to understand how our site is used and to measure the effectiveness of our advertising:

  • Google Analytics (GA4): Measures website traffic, user behavior, and engagement to help us improve our services
  • Google Ads: Tracks conversions from our advertising campaigns
  • Meta Pixel: Measures effectiveness of advertising on Meta platforms (Facebook, Instagram)

Your Cookie Choices

When you first visit our website, a cookie consent banner will ask for your permission before any analytics or advertising cookies are loaded. You can choose to accept all cookies or use only essential ones. Your choice is stored locally and respected on all subsequent visits. You can change your preference at any time by clearing your browser's local storage for this site or contacting us at [email protected].

9. Data Security

We implement appropriate technical and organizational measures to protect your personal data:

  • Encryption of data in transit (TLS/SSL) and at rest
  • Secure password hashing using industry-standard algorithms
  • Regular security assessments and updates
  • Access controls limiting data access to authorized personnel
  • Infrastructure hosted on secure, certified platforms

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the supervisory authority within 72 hours as required by GDPR Article 33.

10. Children's Privacy

Vantacron is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected], and we will promptly delete the information.

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

For material changes that affect how we process your personal data, we will:

  • Notify you via email at least 30 days before the changes take effect
  • Update the "Last updated" date at the top of this policy
  • Provide a summary of key changes

We encourage you to review this policy periodically to stay informed about how we protect your data.

12. Contact Information

If you have any questions about this Privacy Policy, want to exercise your data protection rights, or have concerns about how we handle your data, please contact us:

Simon Kjellner EF

Organization Number: 060630-7254

Address: Timmergrand 1, 549 63 Skovde, Sweden

Email: [email protected]

Phone: +46 76 145 15 98

We aim to respond to all privacy-related inquiries within 30 days.