Privacy Policy
Last updated: February 7, 2026
Contents
At Vantacron, we are committed to protecting your privacy and ensuring the security of your personal data. This Privacy Policy explains how we collect, use, store, and protect your information in compliance with the General Data Protection Regulation (GDPR) and Swedish data protection laws.
1. Data Controller
Simon Kjellner EF
Organization Number: 060630-7254Address: Timmergrand 1, 549 63 Skovde, SwedenEmail: [email protected]Phone: +46 76 145 15 98
As the data controller, we determine the purposes and means of processing your personal data and are responsible for ensuring compliance with applicable data protection laws.
2. Personal Data We Collect
Account Information
When you create an account, we collect:
- Full name
- Email address
- Company name (optional)
- Password (stored encrypted)
Payment Information
Payment processing is handled by Stripe. We do not store your credit card details. Stripe may collect payment card numbers, billing addresses, and transaction history. Please refer to Stripe's Privacy Policy for details.
Usage Data
We automatically collect:
- IP address
- Browser type and version
- Operating system
- Pages visited and features used
- Date and time of access
- Referring website
Website Analysis Data
When you use our SEO analysis features, we process:
- URLs and domains you choose to analyze
- Website content accessible through crawling
- Technical SEO data from your websites
- Analysis results and reports generated
Integration Data
If you connect third-party services, we may access:
- Google Search Console data (search performance, indexing status)
- Google Analytics data (traffic, user behavior)
You can disconnect these integrations at any time from your account settings.
3. Legal Basis for Processing
Under GDPR Article 6, we process your personal data based on the following legal grounds:
Contract Performance (Article 6(1)(b))
Processing necessary to provide our services, including account creation, website analysis, and customer support.
Legitimate Interest (Article 6(1)(f))
Processing for security, fraud prevention, service improvement, and analytics to enhance user experience.
Consent (Article 6(1)(a))
Where we send marketing communications or process optional data, we rely on your explicit consent which you can withdraw at any time.
Legal Obligation (Article 6(1)(c))
Processing required to comply with Swedish tax law, accounting requirements, and legal requests from authorities.
4. Third-Party Data Processors
We work with trusted third-party service providers who process data on our behalf. All processors are bound by data processing agreements that ensure GDPR compliance.
| Service | Purpose | Location |
|---|---|---|
| Stripe | Payment processing | US (EU-US DPF certified) |
| DataForSEO | SEO data and backlink analysis | EU |
| Search Console and Analytics integrations | US (EU-US DPF certified) | |
| Supabase | Database hosting | EU |
Data Processing Agreement (DPA): Business customers requiring a DPA for their compliance needs can request one by contacting [email protected].
5. International Data Transfers
Primary Storage: Your data is primarily stored within the European Union (EU).
Transfers Outside EU: Some of our service providers (Stripe, Google) are based in the United States. These transfers are protected by:
- EU-US Data Privacy Framework (DPF) certification
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Additional technical and organizational safeguards
6. Data Retention
Active Accounts
Data is retained for as long as your account remains active.
Deleted Accounts
Personal data is retained for 1 year after account deletion for legal compliance purposes (tax records, dispute resolution).
Payment Records
Transaction records are retained for 7 years as required by Swedish accounting law (Bokforingslagen).
Server Logs
Technical logs are automatically deleted after 90 days.
7. Your Rights Under GDPR
Under the General Data Protection Regulation (Articles 15-22), you have the following rights:
How to Exercise Your Rights
You can exercise most of these rights directly through your Vantacron account:
- Data Export: Request a full export of your data from Account Settings > Privacy > Export Data
- Account Deletion: Delete your account from Account Settings > Privacy > Delete Account
- Data Summary: View a summary of all data we store about you in Account Settings > Privacy
For other requests or assistance, contact us at [email protected]. We will respond within 30 days as required by GDPR.
Right to Lodge a Complaint
If you believe we have not handled your data correctly, you have the right to lodge a complaint with the Swedish supervisory authority:
9. Data Security
We implement appropriate technical and organizational measures to protect your personal data:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure password hashing using industry-standard algorithms
- Regular security assessments and updates
- Access controls limiting data access to authorized personnel
- Infrastructure hosted on secure, certified platforms
In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you and the supervisory authority within 72 hours as required by GDPR Article 33.
10. Children's Privacy
Vantacron is not intended for use by individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have inadvertently collected data from a minor, please contact us immediately at [email protected], and we will promptly delete the information.
11. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
For material changes that affect how we process your personal data, we will:
- Notify you via email at least 30 days before the changes take effect
- Update the "Last updated" date at the top of this policy
- Provide a summary of key changes
We encourage you to review this policy periodically to stay informed about how we protect your data.
12. Contact Information
If you have any questions about this Privacy Policy, want to exercise your data protection rights, or have concerns about how we handle your data, please contact us:
Simon Kjellner EF
Organization Number: 060630-7254
Address: Timmergrand 1, 549 63 Skovde, Sweden
Email: [email protected]
Phone: +46 76 145 15 98
We aim to respond to all privacy-related inquiries within 30 days.