Den här texten finns bara på engelska.
Digilog Privacy Policy
Last updated: 28 September 2026
1. Who we are
Digilog is provided by Digirocket AB, a company registered in Sweden with org. no. 559541-5554 ("Digilog", "we", "us"). This policy explains how we handle personal data when you visit our websites (digilogapp.com, digilog.se, digilog.dk, digilog.fi and our other Digilog websites), use the Digilog app at go.digilogapp.com, or receive documentation sent through it.
Questions about privacy, or requests to exercise your rights: info@digilog.se, or by post to Digirocket AB, Midsommarvägen 23, 126 35 Hägersten, Sweden. Please write "Privacy" in the subject line.
2. Our two roles
We handle personal data in two different roles, depending on whose data it is.
- As controller we decide how data is used for our websites, for the accounts of people who use Digilog, for invoicing our customers, and for sales and support. This policy covers that data in full.
- As processor we store data that our customers enter about their own work: installations, properties, their customers and contact persons, signatures, photos and fault reports. The customer (usually the installation or service company) is the controller of that data and decides what is recorded and for how long. We handle it only on the customer's instructions, under our data processing agreement. If your data appears in documentation a company created in Digilog, contact that company first; we will help them answer you.
Digilog is a business service. It is not intended for children, and we do not knowingly collect data about anyone under 16.
3. What we process and why
| Purpose | Personal data | Legal basis (GDPR art. 6) |
|---|---|---|
| Your account and sign-in | Name, email address, employer, role and permissions, phone number if given, sign-in identifier from Microsoft Entra | Contract (6.1 b) |
| Providing the platform | What users record: installation and service documentation, addresses and map positions, photos, documents, signatures, comments, fault reports, names of contact persons | Contract (6.1 b); for our customers' own records we act as processor (section 2) |
| Sending documentation and notifications | Recipient name and email address, what was sent and when, delivery status | Legitimate interest in delivering documentation and notifications sent through Digilog (6.1 f) |
| AI-assisted features | Contents of uploaded PDFs and photos | Contract (6.1 b) |
| Invoicing and accounting | Company name, org. and VAT number, billing address, invoice contact, order history | Contract (6.1 b); legal obligation under the Swedish Bookkeeping Act (6.1 c) |
| Orders through partner web shops | Details the reseller passes to us when you order Digilog products in its web shop: name, phone number, email, company, customer number and delivery address; what was ordered | Contract with the reseller (6.1 b); legitimate interest in delivering your order (6.1 f) |
| Checking company and VAT details | Org. number, VAT number | Legitimate interest in correct invoicing and preventing fraud (6.1 f) |
| Support and error reports | Name, company, email, what you tell us, technical details of the error | Legitimate interest in helping you and fixing faults (6.1 f) |
| Security and operations | IP address, request logs, browser and device type, user ID in technical logs | Legitimate interest in keeping the service secure and running (6.1 f) |
| Website statistics | Pages visited, referrer, country, device type (aggregated) | Legitimate interest (6.1 f) |
| Sales and marketing to businesses | Business contact details, which campaign or trade fair brought you to us, contact history | Legitimate interest in B2B marketing (6.1 f); you can object at any time |
We do not sell personal data, and we do not use it for automated decisions that have legal or similarly significant effects on you.
4. Where data is stored and who we share it with
The platform and its database run on Microsoft Azure in Sweden (Sweden Central). The main suppliers we use to run Digilog are listed in Appendix A (Suppliers and sub-processors), which shows the date it was last updated. We may update Appendix A when we add or replace a supplier without otherwise revising this policy. Unless Appendix A says otherwise, each one processes data only on our instructions, under a data processing agreement.
We also exchange data with parties that are not our suppliers and decide for themselves how they handle it, such as public authorities and public registers. They are listed in Appendix B (Who we share data with). Some features pass data to a party you choose: for example when you send documentation to a recipient, or when you order through a reseller's web shop, in which case the order details go back to that reseller and its order-handling provider.
5. Transfers outside the EU/EEA
Our platform and database are hosted in Sweden. We keep other data in Sweden or elsewhere in the EU/EEA wherever we can. Some suppliers in Appendix A are US companies or may process data outside the EU/EEA. We transfer data there only when one of these safeguards applies:
- the European Commission has found that the recipient's country (such as the UK) gives adequate protection, or the recipient is certified under the EU–US Data Privacy Framework, which the Commission has also found adequate; or
- we have signed the European Commission's standard contractual clauses with the recipient, together with the additional measures they require.
You can ask us for a copy of the safeguards that apply to a transfer (see section 1).
6. How long we keep data
| Data | How long |
|---|---|
| Installation documentation: signed CE documentation (PDF) and the logbook | 10 years from the installation date, also after the customer's agreement ends. Once the agreement has ended, it is kept as a read-only archive at no cost, so the documentation and the logbook stay available to the customer and to the building owner. Other parts of the installation record, such as photos and other documents, may be kept in the archive for up to the same period, but we do not guarantee that they will be. EU machinery legislation requires the technical file for a machine to be kept for 10 years. A customer can export its documentation at any time, and can ask us to delete it earlier once it has taken over keeping it. |
| Your user account | As long as you are a user. We delete or anonymise it within 90 days after your account is removed. Your name stays on documentation you signed or created, because that record must remain complete. |
| A customer's other data after the agreement ends (users, settings, customer and property registers not tied to archived documentation) | Available for export for 90 days, then deleted. |
| Invoices, accounting records and orders through partner web shops | 7 years after the end of the financial year, as required by the Swedish Bookkeeping Act. |
| Sales and marketing contacts | 24 months after our last contact, unless you become a customer. |
| Support requests and error reports | 24 months. |
| Technical logs and usage telemetry | 30 to 90 days. |
| Backups | Overwritten on a rolling basis within 35 days. |
Where data must be deleted but a backup still holds it, the backup copy is removed when that backup expires.
7. Security
Data is encrypted in transit and at rest. The database is not reachable from the internet, access is limited to staff who need it, and every sign-in goes through Microsoft Entra. If a personal data breach puts your rights at risk, we tell the Swedish Authority for Privacy Protection (IMY) within 72 hours and inform you without undue delay.
8. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you and get a copy;
- have incorrect data corrected;
- have data erased when we no longer need it or have no legal basis for it;
- restrict how we use your data while a question is being settled;
- data portability: receive data you gave us in a machine-readable format;
- object to processing based on our legitimate interest, and always to direct marketing;
- withdraw consent at any time, where we rely on consent.
Email info@digilog.se to use any of these rights. We answer within one month. If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection, IMY, Box 8114, 104 20 Stockholm.
9. Cookies
Our websites and the platform use cookies. Our Cookie Policy lists each one, what it is for and how long it lasts.
10. Changes to this policy
We update this policy when our services or suppliers change. The date at the top shows the latest version. If a change significantly affects how we use your data, we tell users in Digilog or by email before it takes effect.
Appendix A: Suppliers and sub-processors
Last updated: 28 September 2026
This appendix lists the main suppliers we use to run Digilog, what they do for us and where they process data (see section 4). Unless stated otherwise below, each supplier processes data only on our instructions, under a data processing agreement.
| Supplier | What they do for us | Where data is processed |
|---|---|---|
| Microsoft (Azure) | Hosting of the platform and our websites, database, file storage, backups, technical logs and website statistics | Sweden |
| Microsoft (Entra ID) | Sign-in and user identity | EU |
| Microsoft (Azure Communication Services) | Sending email | EU |
| Microsoft (Azure AI Foundry) | AI features like reading PDFs and photos | EU |
| Microsoft (Teams) | Internal alerts to our staff about support requests and errors | EU |
| Google (Maps Platform) | Address search, address validation and maps | Global; Google LLC is a US company. Google acts as an independent controller for this data, under its own terms and privacy policy. |
| Fortnox | Invoicing and accounting | Sweden |
| Attio | Customer relationship management (sales) | EU |
Suppliers that also process personal data on our customers' behalf are listed as sub-processors in Appendix C of our Data Processing Agreement.
Appendix B: Who we share data with
Last updated: 28 September 2026
This appendix lists parties that are not our suppliers but that receive personal data from us, or provide it to us, and decide for themselves how they handle it (see section 4).
Swedish Tax Agency (Skatteverket): accounting and tax information, where the law requires it.
Statistics Sweden (SCB): when a Swedish customer enters its organisation number, we send the number to SCB and fetch the company's registered details, such as name and address.
The EU's VIES service (European Commission and national tax authorities): we send the VAT number a customer enters so that it can be verified.
Recipients you choose: when you send documentation through Digilog, the recipient receives the documentation together with the sender's name and contact details.
Resellers: when you order through a reseller's web shop, the order details go back to that reseller and its order-handling provider.