Skip to main content
Privacy Policy

Privacy Policy

Your privacy matters to us. This policy explains how we collect, use, and protect your personal data.

Effective: January 2026
Last Updated: January 2026

1. Introduction

Welcome to STRAETCH. This Privacy Policy explains how Action & Consequence AB ("we," "us," "our," or the "Company"), a Swedish limited company, collects, uses, discloses, and protects your personal data when you use the STRAETCH platform and related services (collectively, the "Service").

We are committed to protecting your privacy and processing your personal data in compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Swedish Data Protection Act, the California Consumer Privacy Act ("CCPA"), the California Privacy Rights Act ("CPRA"), and other applicable data protection laws.

Data Controller

Action & Consequence AB

Product

STRAETCH

Registered Country

Sweden

2. Data Controller and Data Processor Roles

When We Act as Data Controller

  • Your account registration and profile information
  • Your use of our platform features
  • Our marketing communications to you
  • Analytics about platform usage

When We Act as Data Processor

On behalf of our business customers (the Data Controllers):

  • Marketing content and strategies created by customers
  • Customer-uploaded data (leads, contacts, documents)
  • AI-generated content for customer use
  • Data published through social media integrations

For processing activities where we act as a Data Processor, please refer to our Data Processing Agreement (DPA) available upon request.

3. Personal Data We Collect

3.1 Account and Profile Data

Data TypePurposeLegal Basis
Name, email addressAccount creation, authentication
Contract performance
Job title, company nameService personalization
Legitimate interest
Profile photo/avatarUser identification
Consent
Password (hashed)Account security
Contract performance

3.2 Usage and Technical Data

Data TypePurposeLegal Basis
IP addressSecurity, fraud prevention
Legitimate interest
Browser type, device infoService optimization
Legitimate interest
Pages visited, features usedProduct improvement
Legitimate interest
Session data, timestampsAnalytics, troubleshooting
Legitimate interest

3.3 Business and Marketing Data

Data processed for service delivery under contract performance:

Marketing strategies, content
Brand assets, guidelines
Campaign data, calendars
AI-generated content

3.4 Payment Data

  • Billing name, address — Payment processing
  • Payment method (via Stripe) — Subscription management
  • Transaction history — Accounting, support

3.5 Social Media Integration Data

When you connect third-party platforms:

  • • Platform account identifiers
  • • Access tokens (encrypted)
  • • Profile name, avatar
  • • Publishing status, metrics

Supported: LinkedIn, Meta (Facebook/Instagram)

4. How We Use Your Data

Service Provision

  • • Creating and managing your account
  • • Providing marketing strategy and content features
  • • Processing AI-assisted content creation
  • • Enabling social media publishing
  • • Providing customer support

Service Improvement

  • • Analyzing usage patterns to improve features
  • • Identifying and fixing technical issues
  • • Developing new functionality
  • • Conducting product research

Communication

  • • Sending service-related notifications
  • • Providing security alerts
  • • Sending marketing communications (with consent)
  • • Responding to inquiries

Legal and Security

  • • Preventing fraud and abuse
  • • Enforcing our terms of service
  • • Complying with legal obligations
  • • Protecting rights and safety

5. AI Data Processing

5.1 How AI Features Work

STRAETCH uses artificial intelligence to generate marketing content, analyze strategies, and provide recommendations.

AspectOur Practice
Data sent to AIAnonymized prompts; company names and PII stripped
AI ProviderOpenAI (with Data Processing Agreement)
Data retention by AIZero retention policy; data not used for AI training
Human reviewNo routine human review of AI inputs/outputs

5.2 Your Control Over AI Processing

View your AI conversation history
Delete AI conversation history at any time
Export your AI-generated content
Opt out of AI features (limited functionality)

6. Data Sharing and Disclosure

6.1 Subprocessors

ProviderPurposeLocationSafeguards
Supabase / AWSInfrastructure, database, authentication
EU (Ireland)
Standard Contractual Clauses, DPA
OpenAIAI content verification & analytics
US
DPA, anonymized data only
AnthropicAI content creation
US
DPA, anonymized data only
StripePayment processing
EU
PCI-DSS compliance, DPA
ResendEmail delivery
US
DPA, Standard Contractual Clauses
DataForSEOSearch/keyword data
EU
No PII transmitted
FirecrawlWeb scraping for social listening
US
Public URLs only
LovableApplication hosting
EU
DPA
Google CloudAnalytics (GA4, Search Console)
EU
DPA, Standard Contractual Clauses

6.2 Social Media Platforms

When you connect social media platforms (LinkedIn, Meta):

  • Not our subprocessors: These are independent services you choose to connect
  • Their own terms apply: Data shared is governed by their privacy policies
  • Your responsibility: You are responsible for platform terms compliance
  • We act as conduit: STRAETCH transmits your content via official APIs

6.3 Legal Disclosures

We may disclose data when required by law, subject to our policy which includes:

  • • Legality review of all requests
  • • Challenging overbroad or unlawful requests
  • • Data minimization
  • • Customer notification when legally permitted

6.4 Business Transfers

In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you before your data becomes subject to a different privacy policy.

7. International Data Transfers

7.1 Primary Data Location

All core data storage and processing occurs in AWS EU (Ireland), providing EU-based data residency for European users.

7.2 Transfers Outside the EU/EEA

For limited US-based processing, we ensure adequate protection through:

  • • Standard Contractual Clauses (SCCs)
  • • Supplementary measures where required
  • • Data Processing Agreements with all subprocessors
  • • Anonymization where possible

8. Data Retention

8.1 Retention Periods

Data CategoryRetention PeriodBasis
Account dataDuration of account + 30 daysContract
AI conversation history7 days (local)User preference
Audit logs2 yearsLegitimate interest, legal
Payment records7 yearsLegal obligation
Backup data90 days after deletion requestTechnical necessity

8.2 Deletion Upon Termination

When you close your account or your subscription ends:

  • Most data is deleted within 30 days
  • Backup data is purged within 90 days
  • Anonymized, aggregated analytics may be retained
  • Legal records are retained as required by law

9. Your Rights (GDPR)

As a data subject under GDPR, you have the following rights:

9.1

Right of Access (Article 15)

Request a copy of your personal data and information about how we process it.

9.2

Right to Rectification (Article 16)

Request correction of inaccurate or incomplete personal data.

9.3

Right to Erasure (Article 17)

Request deletion of your personal data ("right to be forgotten").

9.4

Right to Restriction (Article 18)

Request that we limit how we use your data in certain circumstances.

9.5

Right to Data Portability (Article 20)

Receive your data in a structured, machine-readable format.

9.6

Right to Object (Article 21)

Object to processing based on legitimate interests or for direct marketing.

9.7

Rights Related to Automated Decision-Making (Article 22)

Not be subject to decisions based solely on automated processing that significantly affect you.

9.8 How to Exercise Your Rights

In-app

Settings → Security → Account & Data Deletion

Response time

Within 30 days

10. Your Rights (CCPA/CPRA - California Residents)

10.1 Right to Know

You can request information about the categories and specific pieces of personal data we've collected.

10.2 Right to Delete

You can request deletion of your personal data, subject to certain exceptions.

10.3 Right to Opt-Out of Sale/Sharing

We do not sell your personal data. We do not share personal data for cross-context behavioral advertising.

10.4 Right to Non-Discrimination

We will not discriminate against you for exercising your privacy rights.

10.6 Categories of Data Collected

In the preceding 12 months, we have collected:

Identifiers (name, email, IP address)
Commercial information (transaction history)
Internet activity (usage data)
Professional information (job title, company)
Inferences (marketing preferences)

11. Cookies and Tracking

Essential Cookies

Required for platform functionality (authentication, security). Cannot be disabled.

Analytics Cookies

Used to understand how you use our platform. Can be managed in cookie settings.

Marketing Cookies

Used for targeted advertising (with consent). Not currently implemented.

11.4 Your Cookie Choices

You can manage cookies through:

Browser settings
Our cookie consent banner
In-app privacy settings

12. Security Measures

We implement comprehensive security measures including:

CategoryMeasures
EncryptionTLS 1.3 in transit, AES-256 at rest
Access ControlRole-based access, MFA available
InfrastructureAWS with SOC 2 certification
Monitoring24/7 security monitoring, intrusion detection
DevelopmentSecure development lifecycle (SDLC)
Incident Response72-hour breach notification

13. Children's Privacy

STRAETCH is not intended for individuals under 18 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately at compliance@straetch.com.

14. Third-Party Links

Our platform may contain links to third-party websites or services. We are not responsible for the privacy practices of these third parties. We encourage you to read their privacy policies.

15. Changes to This Policy

We may update this Privacy Policy periodically. We will notify you of material changes by:

  • Email notification
  • In-app notification
  • Prominent notice on our website

Continued use of the Service after changes constitutes acceptance of the updated policy.

16. Data Protection Officer

While not legally required for our current size, we have designated a privacy contact:

Action & Consequence AB

compliance@straetch.com

Stockholm, Sweden

17. Supervisory Authority

If you are unsatisfied with our handling of your data, you have the right to lodge a complaint:

Swedish Authority for Privacy Protection (IMY)

www.imy.se

imy@imy.se

18. Contact Us

For any questions about this Privacy Policy or our data practices:

Website

straetch.com/privacy

Address

Stockholm, Sweden

Version: 2.0 • Last Updated: January 2026 • Contact: compliance@straetch.com

We use cookies to enhance your experience.