Privacy Policy
1Who we are
Haidrun AB (company registration no. 559259-8550), Stockholm, Sweden, is the controller responsible for the personal data described in this policy (“Haidrun”, “we”, “us”). For any privacy question, contact privacy@haidrun.com.
Where we act as a processor — for example when handling personal data on behalf of a customer within our platform services — the relevant customer agreement and data-processing terms govern, not this policy. This policy covers our role as a controller for our website and business relationships.
2Information we collect
We collect the following categories of personal data:
- Identity & contact data — name, business email, phone, employer, job title, and the content of enquiries when you request a demo, contact us, or correspond with us.
- Business relationship data — records of meetings, communications, and your interests or preferences as a prospective or existing customer, partner, investor, or supplier.
- Technical & usage data — IP address, device and browser type, approximate location derived from IP, pages viewed, referring URLs, and interactions with the site, collected through server logs and (where enabled and consented to) analytics.
- Cookie & similar-technology data — see the Cookie Policy.
- Recruitment data — if you apply for a role, the information in your application.
We generally do not seek special-category / sensitive personal data through this site and ask that you do not submit it. We collect data directly from you, automatically through your use of the site, and occasionally from public sources or business-data providers used for B2B outreach and due diligence.
3How we use it & legal bases
We use personal data to respond to enquiries and demo requests; to provide, operate, and improve the site; to communicate with you about our products and relationship; to run marketing that is relevant to your organisation; to maintain security and prevent misuse; to comply with legal, regulatory, tax, and anti-money-laundering / sanctions obligations; and to establish, exercise, or defend legal claims.
Where the GDPR applies, our legal bases are: consent (e.g. optional marketing, non-essential cookies); performance of a contract or steps taken at your request; legitimate interests (running and securing our business and site, B2B relationship management and marketing, subject to a balancing test); and compliance with a legal obligation. Where we rely on legitimate interests, you may object as described below. In other regions we rely on the equivalent lawful bases (including consent and legitimate/business purposes) recognised under local law.
4Cookies & analytics
We use strictly necessary cookies to run the site and, where you consent, analytics and preference cookies. Full detail, categories, and how to control them are in our Cookie Policy. Non-essential cookies are only set with consent where required by law (e.g. the EU/UK ePrivacy rules).
5How we share information
We share personal data only as needed:
- Service providers (processors) — hosting, content delivery, email, CRM, analytics, scheduling, and security vendors that process data on our instructions.
- Professional advisers — lawyers, auditors, and consultants under confidentiality.
- Corporate transactions — in connection with a merger, acquisition, financing, or reorganisation, subject to appropriate safeguards.
- Legal & regulatory — authorities, regulators, or courts where required by law, or to protect our rights, users, or the public.
We do not sell personal data, and we do not “share” it for cross-context behavioural advertising as those terms are defined under US state privacy laws.
6International data transfers
We operate globally, so your data may be processed in countries other than your own, including outside the EEA, the UK, the UAE, and your home jurisdiction. Where we transfer personal data across borders, we use recognised safeguards — for EEA/UK data, the European Commission’s Standard Contractual Clauses (and the UK Addendum / IDTA) or an adequacy decision; for other regions, the transfer mechanisms required by local law. A copy of the relevant safeguards is available on request.
7Data retention
We keep personal data only as long as necessary for the purposes above, then delete or anonymise it. Enquiry and CRM records are generally retained for the duration of the business relationship and a reasonable period afterwards; data kept for legal, tax, or accounting reasons is retained for the period those laws require.
8Security
We apply appropriate technical and organisational measures — including access controls, encryption in transit, logging, and vendor due diligence — to protect personal data against unauthorised access, loss, or misuse. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Where required, we will notify you and the competent authority of a data breach within the legally mandated timeframe.
9Your rights by region
Depending on where you live, you have some or all of the following rights. We honour these rights and will not discriminate against you for exercising them.
Access; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing (including direct marketing and processing based on legitimate interests); withdrawal of consent at any time; and the right not to be subject to solely automated decisions with legal or similarly significant effects. You may also lodge a complaint with your supervisory authority — in Sweden, the Integritetsskyddsmyndigheten (IMY).
For California residents (CCPA/CPRA): the right to know/access the personal information we collect, use, and disclose; to correct inaccurate information; to delete; to opt out of “sale” or “sharing” (we do neither); and to limit the use of sensitive personal information — with no discrimination for exercising these rights. Residents of other states with comprehensive privacy laws (including Virginia, Colorado, Connecticut, Utah, Texas, and others as they take effect) have comparable rights to access, correct, delete, opt out, and appeal a decision.
Rights to access and receive your personal data; to request correction; to request erasure; to restrict or stop processing; to data portability; and to object to processing, including automated processing and direct marketing, subject to the conditions in the PDPL and any applicable free-zone regime (e.g. DIFC or ADGM data-protection rules).
Rights to access and to correct your personal data, and to withdraw consent for its collection, use, or disclosure. Similar rights apply under other regional laws; we handle requests in line with the applicable framework in your jurisdiction.
10Exercising your rights
To make a request, email privacy@haidrun.com. We may need to verify your identity before acting, and we will respond within the timeframe required by the law that applies to you. You may use an authorised agent where the law permits. If you are unhappy with our response, you may contact the relevant supervisory or data-protection authority.
11Children
Our site and services are intended for businesses and professionals, not for children. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.
12Automated decision-making
We do not make decisions producing legal or similarly significant effects about you based solely on automated processing through this site.
13Changes to this policy
We may update this policy to reflect changes in our practices or the law. We will post the updated version here and change the “Last updated” date; material changes may be notified more prominently.
14Contact us
Haidrun AB — Stockholm, Sweden · Company reg. no. 559259-8550
Privacy enquiries: privacy@haidrun.com