Legal · GDPR (EU 2016/679)
GDPR Privacy Notice
Last updated: 17 September 2026 · Sansa Group AB · sansagroup.eu
1. Controller
Sansa Group AB, Gothenburg, Sweden · support@sansagroup.eu · sansagroup.eu. No separate DPO is appointed; privacy enquiries go to the same address and are handled by management.
2. Purposes, categories & bases
- Enquiry handling (identity + contact + brief content): Art. 6(1)(b)/(f).
- Site security & anti-abuse (IP, logs, device signals): Art. 6(1)(f).
- Optional analytics/marketing: Art. 6(1)(a) consent, withdrawable anytime.
3. Recipients & processors
Cloudflare, Inc. (CDN/hosting/security, Art. 28 DPA) and our email-delivery provider for form messages. Sub-processors for Sansavision/Grasp client work are governed by separate DPAs and are out of scope for this website notice.
4. Transfers outside EEA
EU-first hosting. Any non-adequate transfer uses SCCs (2021/914) with transfer risk assessment and encryption in transit/at rest.
5. Retention
Enquiries 24 months; logs 12 months; consent records 3 years (accountability); accounting 7 years (Swedish Bokföringslagen).
6. Your rights (Art. 12–22)
- Access, rectification, erasure, restriction, portability, objection (including to direct marketing, absolute).
- Withdraw consent anytime without affecting prior lawful processing.
- We verify identity proportionately and respond within one month (extendable by two for complexity).
7. Complaints
Contact us first. You may also complain to Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, or your habitual-residence authority.
8. Automated decisions
We do not make solely-automated decisions with legal or similarly significant effects via this website.
Questions? support@sansagroup.eu