ethira

Legal · Privacy

Privacy policy.

How Ethira AB processes personal data under the GDPR: as controller for our own organisation, and as processor for customer-controlled platform data, extension telemetry, and inference content.

Last updated: 21 August 2026

01

Who we are

Ethira AB (“Ethira”, “we”, “us”) is a Swedish limited company with its registered office at Luntmakargatan 26, 111 37 Stockholm, Sweden. For the processing described in this policy as controller activity, Ethira AB is the data controller under Regulation (EU) 2016/679 (the GDPR).

Privacy and data-subject requests: privacy@ethira.dev. General: hello@ethira.dev. Company number 559531-1480. Website: https://www.ethira.dev.

02

Scope of this policy

This policy covers personal data processed in connection with our marketing website, sales and customer-account administration, recruitment and employment, and our own vendor relationships. It also explains where we act as a processor.

It does not replace a customer’s own privacy notice, and it is not the data processing agreement (DPA) for the Ethira platform. Access to the platform is contracted separately. If a platform agreement or DPA conflicts with this policy on tenant data, that contract controls.

Ethira is the living graph of an organisation’s ICT estate: vendors, systems, agents, and data flows, so security, legal, and GRC can see how AI and data move. This policy describes personal-data processing around that product and this website.

03

Controller and processor

Controller. We determine the purposes and means of processing for our own organisation: operating this website; marketing and sales; account-level customer administration and billing; recruitment; employment; and managing our suppliers.

Processor. Where a customer: or, for the browser extension, the employer or organisation that deploys it: determines why and how personal data is processed, that organisation is the controller and Ethira acts as processor. That includes customer-controlled platform data, browser-extension telemetry, and content sent for AI/LLM inference on the customer’s instructions.

04

Data we process as controller

The categories below are typical. We do not collect more than we need for the purpose at hand.

  • Website visitors. Technical logs such as IP address, user agent, timestamps, and pages requested, as needed to operate, secure, and diagnose the site. Non-essential analytics only with consent (see Cookies).
  • Prospects and contacts. Name, work email, company, role, message content, demo-booking details, and records of correspondence. Sources include forms on this site, email, events, and referrals.
  • Customers (account-level). Account, administrator, and billing contacts: identity, work contact details, organisation, contract and invoice data, and support correspondence. This is data about our customer relationship, not the customer’s own platform content.
  • Newsletter subscribers. Email address and the consent record for the subscription.
  • Candidates. CV and application materials, interview notes, and communications. See Retention for how long unsuccessful applications are kept.
  • Employees. HR, payroll, and workplace data needed to run the company, under employment law and internal policy.
  • Our vendors. Contact and contract data about people who represent Ethira’s own suppliers, not vendors that appear in a customer’s graph except where those people also deal with us directly.
06

Platform data

When an organisation uses the Ethira platform, that organisation is typically the controller of personal data in its tenant: inventory and graph records it chooses to hold, user accounts it provisions, and related operational content. Ethira processes that customer-controlled data only on documented instructions: the DPA and product configuration, to provide a living picture of the customer’s ICT estate.

Ethira personnel access tenant data only as needed to deliver, secure, and support the service. We do not use customer platform content to market to the individuals who appear in a customer’s graph.

07

Browser-extension telemetry

Some customers deploy an Ethira browser extension. Telemetry from that extension is a processor activity. The customer or employer that deploys the extension is the controller.

This processing can be high-risk. Ethira maintains a data protection impact assessment (DPIA) for it and reviews that assessment as the extension and its data flows change. Data is processed locally on the device first; selected telemetry is then shared with Ethira as configured by the controller. We do not use extension telemetry for our own independent purposes.

08

AI and LLM inference

Where the platform sends content to a large-language-model provider so a customer can analyse or generate output, Ethira acts as processor of that inference content. The LLM provider acts as our sub-processor.

We currently use OpenAI and Anthropic under contractual terms that prohibit training on customer content and provide zero-retention (or equivalent non-storage of prompts and outputs beyond fulfilling the inference request), except as needed to provide the API and meet legal duties. Customer content is not used to train Ethira’s own models.

09

Cookies and analytics

Essential cookies and similar storage are limited to what is needed to load and secure the Site, plus your cookie-consent choice (localStorage key ethira_website_consent).

Analytics, advertising measurement, and visitor identification load only after you accept via the cookie banner. If you decline or ignore the banner, those tools are not loaded. You can withdraw consent at any time via Cookie settings in the footer.

  • PostHog (EU, Frankfurt): page views, autocaptured interactions, approximate geolocation, browser type, and referrer. No email or name is sent from this Site.
  • Snitcher (EU, AWS Frankfurt): B2B visitor identification that resolves the visiting company from IP and on-site behaviour. Results are aggregated at company level. See Snitcher's privacy policy.
  • Google Ads (gtag AW-18171778905): conversion and campaign measurement.
10

Newsletter and communications

  • Newsletter. Sent on the basis of consent. Unsubscribe with the link in each email or by writing to hello@ethira.dev.
  • Existing customer contacts. We may send relevant B2B product and service information on a legitimate-interest / soft-opt-in basis. You can object at any time via the same email address or an unsubscribe link.

We do not sell personal data.

11

Recipients

We share personal data with:

  • Service providers who host, email, bill, authenticate, or support our operations, under contract.
  • Professional advisers (legal, accounting) under confidentiality.
  • Authorities where required by law.
  • LLM providers named above, as sub-processors, when inference is requested in the product.

A current list of sub-processors is available on request to hello@ethira.dev, and is provided to customers under the DPA.

12

International transfers

Where we transfer personal data outside the EEA:

  • United States. We rely on the EU–US Data Privacy Framework where the recipient is certified, or on the European Commission’s Standard Contractual Clauses (SCCs), with supplementary measures where required.
  • United Kingdom. We rely on the European Commission’s adequacy decision for the UK.

Other transfers, if any, use an adequacy decision or SCCs.

13

Retention

We keep personal data only as long as needed for the purposes above, then delete or anonymise it, unless a longer period is required by law. Examples:

  • Billing and accounting records: 7 years, as required by the Swedish Bookkeeping Act (Bokföringslagen).
  • Unsuccessful candidates: 6 months, aligned with the Swedish Discrimination Act (Diskrimineringslagen), unless you consent to a longer talent-pool period.
  • Data-subject request records : typically 3 years, so we can demonstrate how we handled the request.
  • Newsletter: until you unsubscribe, plus a short period to honour the suppression list.
  • Website logs: a limited operational period, unless needed for a security investigation.

Processor data follows the customer’s instructions and the DPA, including deletion or return at the end of the service.

14

Your rights

Subject to the conditions in the GDPR, you may request access, rectification, erasure, restriction of processing, data portability, and objection to processing based on legitimate interests. We do not currently use automated decision-making that produces legal or similarly significant effects.

Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing that already took place.

To exercise these rights, email hello@ethira.dev. We may need to verify your identity. We will respond within one month, or within the further period allowed by the GDPR where a request is complex.

You may lodge a complaint with Integritetsskyddsmyndigheten (IMY), the Swedish supervisory authority, at https://www.imy.se, or with your local EEA supervisory authority.

If we process your data only as a processor, we will forward your request to the relevant controller where appropriate, or tell you how to contact them.

15

Security

We apply technical and organisational measures appropriate to the risk, including access control, encryption in transit, logging, and vendor due diligence. No method of transmission or storage is perfectly secure.

16

Children

The site and platform are directed at organisations and professionals. We do not knowingly collect personal data from children.

17

Changes

We will update this page when the policy changes and revise the “Last updated” date. Material changes may also be notified by email to account contacts or via the site.

18

Contact

Ethira AB
Luntmakargatan 26
111 37 Stockholm, Sweden

hello@ethira.dev
https://www.ethira.dev

Website terms of use: /terms.