Legal · Privacy
Privacy policy.
How Ethira AB processes personal data under the GDPR: as controller for our own organisation, and as processor for customer-controlled platform data, extension telemetry, and inference content.
Last updated: 21 August 2026
Who we are
Ethira AB (“Ethira”, “we”, “us”) is a Swedish limited company with its registered office at Luntmakargatan 26, 111 37 Stockholm, Sweden. For the processing described in this policy as controller activity, Ethira AB is the data controller under Regulation (EU) 2016/679 (the GDPR).
Privacy and data-subject requests: privacy@ethira.dev. General: hello@ethira.dev. Company number 559531-1480. Website: https://www.ethira.dev.
Scope of this policy
This policy covers personal data processed in connection with our marketing website, sales and customer-account administration, recruitment and employment, and our own vendor relationships. It also explains where we act as a processor.
It does not replace a customer’s own privacy notice, and it is not the data processing agreement (DPA) for the Ethira platform. Access to the platform is contracted separately. If a platform agreement or DPA conflicts with this policy on tenant data, that contract controls.
Ethira is the living graph of an organisation’s ICT estate: vendors, systems, agents, and data flows, so security, legal, and GRC can see how AI and data move. This policy describes personal-data processing around that product and this website.
Controller and processor
Controller. We determine the purposes and means of processing for our own organisation: operating this website; marketing and sales; account-level customer administration and billing; recruitment; employment; and managing our suppliers.
Processor. Where a customer: or, for the browser extension, the employer or organisation that deploys it: determines why and how personal data is processed, that organisation is the controller and Ethira acts as processor. That includes customer-controlled platform data, browser-extension telemetry, and content sent for AI/LLM inference on the customer’s instructions.
Data we process as controller
The categories below are typical. We do not collect more than we need for the purpose at hand.
- Website visitors. Technical logs such as IP address, user agent, timestamps, and pages requested, as needed to operate, secure, and diagnose the site. Non-essential analytics only with consent (see Cookies).
- Prospects and contacts. Name, work email, company, role, message content, demo-booking details, and records of correspondence. Sources include forms on this site, email, events, and referrals.
- Customers (account-level). Account, administrator, and billing contacts: identity, work contact details, organisation, contract and invoice data, and support correspondence. This is data about our customer relationship, not the customer’s own platform content.
- Newsletter subscribers. Email address and the consent record for the subscription.
- Candidates. CV and application materials, interview notes, and communications. See Retention for how long unsuccessful applications are kept.
- Employees. HR, payroll, and workplace data needed to run the company, under employment law and internal policy.
- Our vendors. Contact and contract data about people who represent Ethira’s own suppliers, not vendors that appear in a customer’s graph except where those people also deal with us directly.
Legal bases
Where we act as controller, we rely on one or more of the following GDPR bases:
- Contract (Art. 6(1)(b)), to take steps at your request before a contract, and to perform a contract with you or your organisation, including demos, support, and billing.
- Legitimate interests (Art. 6(1)(f)) : to operate and secure the website; to understand B2B demand; and to send relevant product or service information to existing customer contacts on a soft-opt-in basis, where we have assessed that our interest does not override your rights. You may object at any time.
- Consent (Art. 6(1)(a)): newsletter subscription; non-essential cookies and analytics; and longer candidate retention where you agree to join a talent pool.
- Legal obligation (Art. 6(1)(c)) : Swedish bookkeeping and other mandatory records, and responding to lawful requests from authorities.
Where we process special-category data (uncommon on this site; possible in recruitment if you volunteer it), we do so only with a valid Art. 9 condition, typically explicit consent or employment-law necessity.
Platform data
When an organisation uses the Ethira platform, that organisation is typically the controller of personal data in its tenant: inventory and graph records it chooses to hold, user accounts it provisions, and related operational content. Ethira processes that customer-controlled data only on documented instructions: the DPA and product configuration, to provide a living picture of the customer’s ICT estate.
Ethira personnel access tenant data only as needed to deliver, secure, and support the service. We do not use customer platform content to market to the individuals who appear in a customer’s graph.
Browser-extension telemetry
Some customers deploy an Ethira browser extension. Telemetry from that extension is a processor activity. The customer or employer that deploys the extension is the controller.
This processing can be high-risk. Ethira maintains a data protection impact assessment (DPIA) for it and reviews that assessment as the extension and its data flows change. Data is processed locally on the device first; selected telemetry is then shared with Ethira as configured by the controller. We do not use extension telemetry for our own independent purposes.
AI and LLM inference
Where the platform sends content to a large-language-model provider so a customer can analyse or generate output, Ethira acts as processor of that inference content. The LLM provider acts as our sub-processor.
We currently use OpenAI and Anthropic under contractual terms that prohibit training on customer content and provide zero-retention (or equivalent non-storage of prompts and outputs beyond fulfilling the inference request), except as needed to provide the API and meet legal duties. Customer content is not used to train Ethira’s own models.
Newsletter and communications
- Newsletter. Sent on the basis of consent. Unsubscribe with the link in each email or by writing to hello@ethira.dev.
- Existing customer contacts. We may send relevant B2B product and service information on a legitimate-interest / soft-opt-in basis. You can object at any time via the same email address or an unsubscribe link.
We do not sell personal data.
Recipients
We share personal data with:
- Service providers who host, email, bill, authenticate, or support our operations, under contract.
- Professional advisers (legal, accounting) under confidentiality.
- Authorities where required by law.
- LLM providers named above, as sub-processors, when inference is requested in the product.
A current list of sub-processors is available on request to hello@ethira.dev, and is provided to customers under the DPA.
International transfers
Where we transfer personal data outside the EEA:
- United States. We rely on the EU–US Data Privacy Framework where the recipient is certified, or on the European Commission’s Standard Contractual Clauses (SCCs), with supplementary measures where required.
- United Kingdom. We rely on the European Commission’s adequacy decision for the UK.
Other transfers, if any, use an adequacy decision or SCCs.
Retention
We keep personal data only as long as needed for the purposes above, then delete or anonymise it, unless a longer period is required by law. Examples:
- Billing and accounting records: 7 years, as required by the Swedish Bookkeeping Act (Bokföringslagen).
- Unsuccessful candidates: 6 months, aligned with the Swedish Discrimination Act (Diskrimineringslagen), unless you consent to a longer talent-pool period.
- Data-subject request records : typically 3 years, so we can demonstrate how we handled the request.
- Newsletter: until you unsubscribe, plus a short period to honour the suppression list.
- Website logs: a limited operational period, unless needed for a security investigation.
Processor data follows the customer’s instructions and the DPA, including deletion or return at the end of the service.
Your rights
Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. We do not currently use automated decision-making that produces legal or similarly significant effects.
Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that already took place.
To exercise these rights, email hello@ethira.dev. We may need to verify your identity. We will respond within one month, or within the further period allowed by the GDPR where a request is complex.
You may lodge a complaint with Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority, at https://www.imy.se, or with your local EEA supervisory authority.
If we process your data only as a processor, we will forward your request to the relevant controller where appropriate, or tell you how to contact them.
Security
We apply technical and organisational measures appropriate to the risk, including access control, encryption in transit, logging, and vendor due diligence. No method of transmission or storage is perfectly secure.
Children
The site and platform are directed at organisations and professionals. We do not knowingly collect personal data from children.
Changes
We will update this page when the policy changes and revise the “Last updated” date. Material changes may also be notified by email to account contacts or via the site.
Contact
Ethira AB
Luntmakargatan 26
111 37 Stockholm, Sweden
hello@ethira.dev
https://www.ethira.dev
Website terms of use: /terms.
