Privacy Policy
Oscar Demirörs, operating as a Swedish sole proprietorship (Org.nr 19930420-2097, VAT SE930420209701), is the controller for the personal data described in this Privacy Policy.
This Privacy Policy explains how personal data is collected, used, shared, retained and protected when you visit this website, contact us, book a meeting, or otherwise interact with the business.
When personal data is processed solely on behalf of a client, that client is normally the controller and its own privacy information applies. In those situations, Oscar Demirörs processes the data under the client’s instructions and the applicable service and data-processing agreements.
1. What We Collect and Where It Comes From
We may collect personal data when you submit a form, respond to an advertisement, book a meeting, contact us by email or social media, communicate with us, request a proposal, or become a client.
This may include:
- Your name, email address, phone number, job title, company name, business website, country and other professional or business details
- Information contained in forms, bookings, messages, meeting notes, proposals, agreements and other communications
- Information about your business, offer, marketing, capacity, goals and service requirements that you choose to provide
- Technical and usage data, such as IP address, device and browser information, pages viewed, interactions, referral URLs, cookie identifiers and advertising-attribution information
Personal data may be received directly from you or through website forms, booking tools, advertising and social-media platforms, email, video-meeting tools and other communication channels you use to contact us.
2. Why We Use Personal Data and the Legal Basis
We may process personal data for the following purposes:
- Inquiries, bookings and proposals: to respond, communicate, assess fit, arrange meetings and take requested steps before entering into an agreement. The legal basis is pre-contractual steps and/or our legitimate interest in managing business inquiries.
- Client services and administration: to enter into, perform and administer agreements, deliver services, manage accounts, communicate and support the client relationship. The legal basis is contract and, where relevant, legitimate interests.
- Professional follow-up and marketing: to follow up on relevant business inquiries and maintain professional relationships where permitted. The legal basis is legitimate interests or consent where consent is required.
- Website operation, security and improvement: to keep the website and systems functional, prevent misuse, troubleshoot, understand performance and improve services. The legal basis is legitimate interests and, for optional analytics or advertising technologies, consent.
- Accounting, tax and legal administration: to issue invoices, maintain required records, comply with legal obligations, and establish, exercise or defend legal claims. The legal basis is legal obligation and legitimate interests.
You are generally not legally required to provide personal data. However, we may be unable to respond to an inquiry, arrange a meeting, prepare a proposal or provide services without the information reasonably needed for that purpose.
We do not sell your personal data.
3. Cookies and Similar Technologies
We may use cookies, pixels and similar technologies that are necessary for website functionality, security and preference management.
Optional analytics and advertising-measurement technologies are used only where the required consent has been obtained. These technologies may process information about website visits, interactions, devices, browsers, referral sources and campaign attribution.
You can manage or withdraw your choices through the website’s cookie preference tool where available. You may also control cookies through your browser, although blocking necessary technologies may affect website functionality.
4. Service Providers and Other Recipients
We use external providers where reasonably necessary to operate the business, website and services. Personal data may therefore be shared with the following categories of recipients:
- Website hosting, domain and technical-infrastructure providers
- CRM, communication, messaging and automation providers
- Meeting-booking, video-conferencing, email, document-storage and business-administration providers
- Advertising, analytics, attribution and conversion-measurement providers
- Banking, payment, invoicing and accounting providers
- Professional advisers, insurers, authorities or other recipients where disclosure is legally required or reasonably necessary to protect legal rights
Providers may process data as processors under our instructions or, depending on the service and circumstances, as independent or joint controllers under their own terms. Providers may also use authorized subprocessors.
5. International Data Transfers
Some providers or their subprocessors may process personal data outside the EU or EEA, including in the United States or other countries whose data-protection rules may differ from those in the EU.
Where required, such transfers are supported by a European Commission adequacy decision, Standard Contractual Clauses, or another lawful transfer mechanism together with any additional safeguards considered appropriate.
You may contact us for further information about the safeguards relevant to your personal data.
6. AI-Supported Communications and Processing
We may use AI-supported tools to assist with communications, qualification, scheduling, administration, analysis and service delivery. Where you interact directly with an AI system, this will be disclosed where required.
AI-supported tools may help generate, organize or evaluate information, but they are not used to make solely automated decisions that produce legal or similarly significant effects concerning you. Final decisions about whether to enter into, continue or decline a client relationship are made with human involvement.
7. How Long We Keep Personal Data
We keep personal data only for as long as it is reasonably needed for the purpose for which it was collected, subject to the following general rules:
- Unconverted inquiries and booking records: generally retained for up to 24 months after the last meaningful human interaction, then deleted or anonymized unless a longer period is justified
- Client and contract records: retained during the client relationship and afterward for as long as reasonably needed for administration, contractual obligations, disputes or legal claims
- Accounting records: retained for the period required under Swedish accounting and tax law
- Marketing objections and opt-outs: a minimal suppression record may be retained for as long as needed to ensure that the objection is respected
- Cookie and analytics data: retained according to the duration communicated through the relevant cookie or preference tool
Automated workflow activity does not by itself indefinitely restart the retention period for an inactive inquiry.
8. Security
We use reasonable technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, loss or destruction.
No method of transmission or storage is completely risk-free. Security measures are reviewed and adjusted in light of the nature of the data, the processing involved, available technology and the level of risk.
9. Your Rights
Depending on the circumstances, you may have the right to:
- Request access to your personal data
- Request correction of inaccurate or incomplete data
- Request deletion of personal data
- Request restriction of processing
- Object to processing based on legitimate interests
- Object at any time to the use of your data for direct marketing
- Withdraw consent at any time where processing is based on consent
- Receive or transfer certain data in a portable format where applicable
Requests are normally handled without undue delay and within one month. We may ask for information reasonably necessary to verify your identity. Some rights are subject to legal conditions and exceptions.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) .
10. Changes to This Policy
This Privacy Policy may be updated when our services, systems, legal obligations or data-processing practices change. The current version will be published on this page with an updated date.
11. Contact
For questions, objections or requests concerning this Privacy Policy or your personal data, contact: oscar@oscardemirors.com