Integritetspolicy
SmartInfra AB:s hantering av personuppgifter
Senast uppdaterad: 13 december 2025
1. Inledning
SmartInfra Nordic AB (org.nr 559561-3794) med adress Kvarngatan 62, 174 66 Sundbyberg, Sverige ("SmartInfra", "vi", "oss" eller "vårt") är personuppgiftsansvarig för behandlingen av dina personuppgifter enligt denna integritetspolicy.
Denna policy beskriver hur vi samlar in, använder, lagrar och skyddar dina personuppgifter när du använder våra tjänster SmartURai och SmartAudit, samt vår webbplats smartinfra.se.
2. Personuppgifter vi samlar in
2.1 Kontoinformation
- Identifieringsuppgifter: Namn, e-postadress, telefonnummer
- Företagsinformation: Företagsnamn, organisationsnummer, bransch
- Autentiseringsuppgifter: Lösenord (krypterat), inloggningshistorik
- Prenumerationsinformation: Valda abonnemang, betalningshistorik, licenser
2.2 Användningsdata
- Systemanvändning: Inloggningar, funktioner som används, tidsanvändning
- AI-interaktioner: Juridiska frågor, dokument som laddas upp, genererade svar
- Auditdata: Auditprojekt, företagsinformation, enkätsvar (SmartAudit)
- Teknisk data: IP-adress, webbläsarinformation, enhetstyp
2.3 Juridiska dokument (SmartURai)
- Projektdokument: Ritningar, specifikationer, ändringsorder och andra tillhandahållna handlingar
- Korrespondens: E-post, brev, underrättelser
- Analysresultat: AI-genererade juridiska analyser och rekommendationer
3. Ändamål och rättslig grund
3.1 Fullgörande av avtal (Artikel 6.1.b GDPR)
- Tillhandahålla SmartURai och SmartAudit-tjänsterna
- Hantera ditt konto och prenumeration
- Bearbeta betalningar och fakturering
- Tillhandahålla teknisk support
3.2 Berättigat intresse (Artikel 6.1.f GDPR)
- Förbättra våra AI-modeller och tjänstekvalitet
- Analysera användningsmönster för produktutveckling
- Säkerhet och bedrägeriförebyggande
- Marknadsföring av liknande tjänster (med opt-out möjlighet)
3.3 Samtycke (Artikel 6.1.a GDPR)
- Marknadsföring via e-post och telefon
- Cookies för analys och marknadsföring
- Delning av aggregerad statistik med partners
4. Dataskydd och säkerhet
4.1 Kryptering
- TLS 1.3: För säker dataöverföring
- AES-256 kryptering: För all lagrad data
- Krypterade databaser: All datalagring är krypterad
- Säkra API-anslutningar: Alla API-anrop är skyddade
4.2 Infrastruktur
- Europäiska datacenter: All data lagras inom EU
- SOC 2 Type II certifiering: Verifierad säkerhet
- ISO 27001: Internationell informationssäkerhetsstandard
- 24/7 övervakning: Kontinuerlig säkerhetsloggning och övervakning
5. Datalagring och bevarande
5.1 Lagringsperioder
- Aktiva konton: Under hela avtalstiden plus 3 år för redovisningsändamål
- Juridiska dokument: 7 år efter projektavslut (byggrättslig praxis)
- Auditdata: 5 år efter audit-avslut (compliance-krav)
- Användningsloggar: 2 år för säkerhets- och supportändamål
- Marknadsföringsdata: Tills samtycke återkallas eller 3 år utan aktivitet
5.2 Dataradering
När lagringsperioden löpt ut raderas data säkert enligt branschstandard. Vid kontoavslut kan du begära omedelbar radering av dina personuppgifter, förutom data vi är skyldiga att behålla enligt lag.
6. Delning av personuppgifter
6.1 Vi delar INTE dina data med:
- Andra kunder eller konkurrenter
- Reklam- eller marknadsföringsföretag (utan samtycke)
- Sociala medier
- Icke-auktoriserade tredje parter
6.2 Vi kan dela data med:
- Tekniska leverantörer: Render.com (hosting), Stripe (betalningar) - under strikta databehandlingsavtal
- Juridiska myndigheteter: Vid lagkrav eller domstolsbeslut
- Säkerhetstjänster: Vid bedrägeriforsök eller säkerhetsincidenter
- Företagsförvärv: Vid fusion eller förvärv (med fortsatt integritetsskydd)
7. Dina rättigheter enligt GDPR
7.1 Tillgång och Information
- Registerutdrag: Få en kopia av dina personuppgifter
- Information: Veta vilka data vi har och varför
- Dataportabilitet: Exportera dina data i strukturerat format
7.2 Ändring och Kontroll
- Rättelse: Korrigera felaktiga uppgifter
- Radering: "Rätten att bli glömd" (med lagliga undantag)
- Begränsning: Stoppa viss databehandling
7.3 Invändning och Återkallelse
- Invändning: Motsätta dig viss databehandling
- Återkalla samtycke: När som helst för samtycke-baserad behandling
- Klagomål: Kontakta Integritetsskyddsmyndigheten (IMY)
7.4 Utöva dina rättigheter
Kontakta oss på:
- E-post: support@smartinfra-nordic.se
- Post: SmartInfra Nordic AB, Kvarngatan 62, 174 66 Sundbyberg
8. Cookies och spårning
Vi använder cookies och liknande tekniker för att förbättra din upplevelse på vår webbplats. Läs mer i vår cookiepolicy.
9. Kontaktinformation
SmartInfra® Nordic AB - Dataskyddsombud
E-post: privacy@smartinfra-nordic.se
Webbplats: smartinfra.se
Postadress:
SmartInfra Nordic AB
Kvarngatan 62
174 66 Sundbyberg
Sverige
10. Ändringar av integritetspolicyn
Vi kan uppdatera denna integritetspolicy för att återspegla ändringar i våra tjänster, gällande lagstiftning eller branschpraxis. Väsentliga ändringar kommer att meddelas via:
- Meddelande på vår webbplats och i våra applikationer
- Push-notifiering i SmartURai och SmartAudit
Fortsatt användning av våra tjänster efter ändringar innebär att du accepterar den uppdaterade policyn.
Privacy Policy – SmartQuality & SmartQuality Field
Last updated: 17 July 2026
1. Introduction
SmartInfra Nordic AB (Company Registration No. 559561-3794), Kvarngatan 62, 174 66 Sundbyberg, Sweden ("SmartInfra", "we", "our" or "us"), is the data controller for the processing of personal data described in this Privacy Policy.
This Privacy Policy explains how we collect, use, store and protect personal data when you use SmartQuality, SmartQuality Field, and our website https://www.smartinfra-nordic.se.
SmartQuality is a digital quality management platform for construction and infrastructure projects. SmartQuality Field is the companion mobile application used by site personnel for inspections, documentation and quality control.
2. Personal Data We Collect
Depending on how you use SmartQuality, we may process the following categories of personal data.
2.1 Account Information
- Name
- Email address
- Company name
- User role and permissions
- Login credentials (encrypted)
- Login history
2.2 Project Information
While using SmartQuality you may create or upload project-related information including:
- Project names
- Construction areas
- Quality documentation
- Checklists
- Inspection results
- Comments
- Uploaded photographs
- Uploaded files
- Digital signatures (where applicable)
Project documentation is processed solely to provide the SmartQuality services and remains under the control of the customer organization.
2.3 Technical Information
We automatically collect limited technical information such as:
- IP address
- Device type
- Operating system
- Browser information (web application)
- App version
- Error logs
- Security logs
This information is used exclusively for security, troubleshooting and service improvement.
3. Purpose and Legal Basis
We process personal data for the following purposes.
3.1 Performance of a Contract (Article 6(1)(b) GDPR)
- Provide SmartQuality services
- Authenticate users
- Manage user accounts
- Store project documentation
- Synchronize data between devices
- Provide technical support
3.2 Legitimate Interests (Article 6(1)(f) GDPR)
- Improve system stability and performance
- Maintain information security
- Prevent fraud and unauthorized access
- Produce anonymous usage statistics
- Improve user experience
3.3 Consent (Article 6(1)(a) GDPR)
Where required, we process personal data based on your consent for:
- Marketing communications
- Optional cookies on our website
- Optional product feedback
Consent may be withdrawn at any time.
4. Artificial Intelligence
SmartQuality may use Artificial Intelligence (AI) to assist users with quality management tasks, including generating suggestions, identifying potential quality requirements and improving workflow efficiency.
Customer project data is not used to train public or general AI models without the customer's explicit consent.
AI-generated results are intended to support users and should always be reviewed by qualified personnel before being relied upon.
5. Security
We take appropriate technical and organizational measures to protect personal data.
These include:
- Encrypted HTTPS communication (TLS)
- Encrypted password storage
- Secure cloud infrastructure
- Role-based access control
- Tenant isolation between customer organizations
- Continuous security monitoring
- Regular backups
Each customer's project data is logically separated from other customers. Customer data is never shared between organizations.
6. Data Retention
Personal data is retained only as long as necessary.
Typical retention periods include:
- User accounts: while the account remains active
- Project documentation: according to the customer's agreement and applicable legal requirements
- Security logs: up to two years
- Support requests: up to three years
Upon request, personal data may be deleted unless retention is required by law or contractual obligations.
7. Sharing of Personal Data
We do not sell personal data.
We do not share personal data with:
- Other customers
- Competitors
- Advertising networks
- Social media platforms
Personal data may be shared only with trusted service providers necessary for delivering the service, including:
- Cloud hosting providers
- Payment providers (where applicable)
- Technical support providers
All such providers are bound by appropriate data processing agreements.
We may also disclose information when required by applicable law.
8. International Transfers
Where personal data is transferred outside the European Economic Area (EEA), appropriate safeguards will be implemented in accordance with GDPR.
Whenever possible, customer data is stored within the European Union.
9. Your Rights
Under the GDPR you have the right to:
- Access your personal data
- Correct inaccurate information
- Request deletion of personal data
- Restrict processing
- Object to processing
- Receive your data in a portable format
- Withdraw consent where processing is based on consent
- Lodge a complaint with your local supervisory authority
Swedish users may contact the Swedish Authority for Privacy Protection (IMY).
10. Cookies
Our website uses cookies to improve user experience and website functionality.
The SmartQuality Field mobile application does not use browser cookies.
11. Children's Privacy
SmartQuality is intended for professional business use and is not directed toward children under the age of 16.
12. Contact Information
SmartInfra Nordic AB
Kvarngatan 62
174 66 Sundbyberg
Sweden
Website:
https://www.smartinfra-nordic.se
General Support:
support@smartinfra-nordic.se
Privacy Questions:
privacy@smartinfra-nordic.se
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in legislation, technology or our services.
The latest version will always be available at:
https://www.smartinfra-nordic.se/privacy.html
Material changes may also be communicated through the SmartQuality application or by email where appropriate.
Last updated (General): 13 December 2025