Privacy policy
This policy covers contact requests, accounts, sign-in and billing. Text in your Gateway installation never reaches Maskera. Read more about how data is handled.
Data controller: Hägvall Labs AB, organization no. 559598-0110, Sankt Göransgatan 153 lgh 1603, 112 17 Stockholm. Contact: hej@maskera.dev.
What Maskera processes and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Contact details and the content of inquiries | Answer questions, schedule walkthroughs and handle registered interest | Legitimate interest or steps requested by you before entering into a contract | As long as needed to handle the inquiry and follow up on agreements |
| Name and email address | Create and identify the account and send password resets and operational messages | Performance of a contract | Until the account is deleted |
| Hashed password | Sign-in. The password is never stored in plaintext | Performance of a contract | Until the account is deleted |
| IP address during sign-in and registration | Limit automated attacks against sign-in and account creation | Legitimate interest: security | For the lifetime of the session |
| Billing data | Payment. Stripe processes the data; Maskera stores only the customer's Stripe ID | Performance of a contract and legal obligations under Swedish accounting law | 7 years under Swedish accounting law |
What Maskera does not do
- Maskera does not sell personal data in the customer portal.
- Maskera does not receive text processed by your Gateway installation and therefore does not use it for model training.
- Maskera uses no marketing tracking cookies. Sign-in sets a technical cookie required for the session to work.
Who else receives the data
Maskera uses suppliers for servers, email delivery and payments. None of them processes text passing through your Gateway installation. See roles, countries and ownership relationships on Where does your data live? The page is updated when a supplier changes.
Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interest. The account and its associated data can be deleted in the customer portal under “Account and data”. Requests for access, rectification or export are handled through hej@maskera.dev.
If you are unhappy with how Maskera processes your data, you can complain to the Swedish Authority for Privacy Protection: imy.se.
Changes
If the policy changes in a way that affects you, the account email address will be notified before the change takes effect.