1. Data Controller
Reflect Företagsutveckling AB (org. nr 556625-1277), Kungstensgatan 38, 113 59 Stockholm, Sweden, is the data controller for the processing of personal data described in this policy.
When Reflect conducts research on behalf of a client, Reflect acts as a data processor. In such cases, the processing is governed by a data processing agreement between Reflect and the client.
2. What Personal Data We Process
We process different categories of personal data depending on how you interact with us.
- Contact details: name, email address, and phone number provided through client relationships or contact forms
- Account data: email address and name when signing in via email/password or Google OAuth
- Survey responses: answers provided in market research, either anonymously or linked to an identifier depending on the study design
- Technical data: IP address, browser type, operating system, and session cookies
- Organisation data: company name, role, and project affiliation for client contacts
3. Purpose and Legal Basis
We process personal data for the following purposes under the respective legal bases.
Performance of contract (Article 6(1)(b) GDPR): delivery of agreed services, management of user accounts, communication regarding ongoing projects.
Legitimate interest (Article 6(1)(f) GDPR): conducting market research, improving our platform and analytical methods, technical operations and security.
Consent (Article 6(1)(a) GDPR): processing of special category data in surveys (e.g. political opinions, health data), use of non-essential cookies.
4. Market Research
Reflect conducts market research as part of its services. Respondents participate without creating accounts. Sessions are managed via temporary cookies.
Survey data is generally processed in aggregated and anonymised form. When a survey collects special category data (Article 9 GDPR), explicit consent is obtained before data collection begins.
When Reflect acts as a data processor on behalf of a client, the purposes of processing are determined by the client, and the processing is governed by the data processing agreement.
5. AI Services
We use AI services from Anthropic (Claude API) and Google (Gemini) for analysis, text processing, and quality control within our platform. Personal data may be included in material processed by these services.
Both providers have agreements ensuring that data is not used for model training. Anthropic processes data in the US under EU Standard Contractual Clauses. Google Gemini processes data within the EU/EEA.
6. Sub-processors and Third Parties
We share personal data with the following categories of service providers, all under data processing agreements.
- Supabase (database hosting, EU-west-1 Frankfurt, Germany)
- Vercel (web hosting and application delivery)
- Anthropic (AI analysis, US, with EU Standard Contractual Clauses)
- Google (OAuth authentication and AI analysis within the EU/EEA)
7. International Transfers
The majority of all data processing takes place within the EU/EEA. Certain sub-processors (Anthropic, Vercel) have operations in the US. Transfers to the US are protected by EU Standard Contractual Clauses (SCC) in accordance with Article 46(2)(c) GDPR.
We never disclose personal data to third parties beyond what is described in this policy, unless required by law.
8. Cookies and Tracking
We use the following types of cookies.
Essential cookies: session management for logged-in users (customer portal) and session management for survey respondents. These do not require consent.
We do not use third-party cookies for advertising or tracking. We do not use analytics cookies.
9. Retention Periods
Personal data is not stored longer than necessary for the stated purposes.
- Client contacts: for the duration of the client relationship, plus 36 months after last contact
- Survey responses: for the duration of the project, then anonymised or deleted per the project agreement
- Account data: for as long as the account is active
- Technical logs: maximum 90 days
- Accounting records: 7 years as required by Swedish law (Bokföringslagen 1999:1078)
10. Your Rights
Under the GDPR you have the following rights.
- Right of access: you may request an overview of what personal data we process about you
- Right to rectification: you may request correction of inaccurate data
- Right to erasure: you may request deletion of your data when it is no longer needed
- Right to restriction: you may request that processing be restricted under certain conditions
- Right to data portability: you may request your data in a machine-readable format
- Right to object: you may object to processing based on legitimate interest
- Right to withdraw consent: if processing is based on consent, you may withdraw it at any time
- Right to lodge a complaint: you may contact the Swedish Authority for Privacy Protection (IMY), imy.se
11. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, and destruction. This includes encryption in transit (TLS), role-based access controls, row-level security (RLS) in the database, and regular review of access logs.
12. Changes to This Policy
We may update this privacy policy. In the event of material changes, customers with active accounts will be notified by email. The latest version is always available at reflect.se/en/privacy-policy.
13. Contact
Questions about how we handle your personal data?
Reflect Företagsutveckling AB Kungstensgatan 38, 113 59 Stockholm, Sweden Email: info@reflect.se Phone: +46 709 99 52 36
Last updated: July 2026