Home / Privacy policy
Legal — GDPR
Privacy policy.
What we collect, why we have it, and how to get it removed. Written to be read, not to be skipped.
This policy explains what personal data The Contact collects, why we collect it, how long we keep it and what rights you have. It applies to thecontact.se and to enquiries you send us by email, phone or social media.
1. Who is responsible
The Contact, based in Stockholm, Sweden, is the data controller for the personal data described here. That means we decide why and how your data is processed, and we are the ones you hold accountable for it. You can reach us at info@thecontact.se or 073 360 88 83.
2. What we collect
We deliberately collect as little as possible. There is no account system on this site, no login, and no payment processing.
Enquiry data
The name, email address, phone number, selected service and message you submit through the contact form, or send us directly by email or phone.
Client data
If we work together: contact details for the people we deal with, project correspondence, and the billing information required to invoice you.
Creator data
If you are an influencer or creator working with us: your contact details, social handles, publicly available audience statistics, agreed rates and the information needed to pay you.
Technical data
Standard server logs kept by our host, including IP address, browser type and the time of the request. These exist for security and troubleshooting, not for profiling.
We do not collect special category data — nothing about health, religion, political opinions, ethnicity or sexual orientation — and we ask that you do not send us any.
3. Why we process it, and on what legal basis
To answer you
When you contact us we use your details to reply and to discuss the work. Legal basis: legitimate interest in responding to someone who approached us, or steps taken prior to entering a contract.
To deliver the work
Running campaigns, building websites, briefing creators, reporting on results. Legal basis: performance of a contract.
To meet legal obligations
Invoices and accounting records. Legal basis: legal obligation under Swedish bookkeeping law.
To keep the site working
Server logs and spam filtering on the contact form. Legal basis: legitimate interest in a secure, functioning website.
We do not use your data for advertising, we do not build behavioural profiles, and we do not make automated decisions that produce legal effects for you.
4. Cookies and tracking
This site sets no cookies of its own. There is no advertising pixel, no analytics tag and no cross-site tracking. Fonts are loaded from Google Fonts, which means your browser makes a request to Google’s servers when the page loads; Google receives your IP address as part of that request. If we add analytics in future, this policy will be updated first and consent will be requested where the law requires it.
5. Who else sees your data
We do not sell personal data, and we do not share it with advertisers. We do rely on a small number of service providers who process data on our behalf under written agreements:
Web3Forms
Delivers contact form submissions to our inbox.
Google Workspace
Hosts our email, so anything you send us is stored there.
Netlify
Hosts the website and keeps the server logs described above.
Clients and creators
In a campaign, the brand and the creator necessarily see each other’s relevant details. We tell you before that happens.
We may also disclose data where we are legally required to, for example in response to a valid order from a public authority.
6. Transfers outside the EU/EEA
Some of the providers above are based in the United States, so your data may be processed outside the EEA. Where that happens, transfers are covered by the European Commission’s Standard Contractual Clauses or an equivalent safeguard under Chapter V of the GDPR. You can ask us for details of the safeguards that apply.
7. How long we keep it
Enquiries that do not lead to work are deleted within 12 months. Client and creator records are kept for the duration of the relationship and for a reasonable period afterwards. Accounting records are kept for seven years, as Swedish bookkeeping law requires. Server logs are kept for a short period by our host and then discarded.
8. Security
The site is served over HTTPS, access to our email and project files is protected by two-factor authentication, and only the people who need your data have access to it. No system is perfectly secure, but if a breach occurs that is likely to put your rights at risk, we will notify the supervisory authority within 72 hours and inform you where the law requires it.
9. Your rights
Under the GDPR you can ask us to give you a copy of the data we hold about you, correct anything inaccurate, delete it, restrict how we use it, or transfer it to another provider in a machine-readable format. Where we rely on legitimate interest, you can object to that processing at any time.
Email info@thecontact.se to exercise any of these. We will respond within one month, free of charge. If you are unhappy with how we handled it, you can complain to Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy.se.
10. Children
This site is aimed at businesses and is not directed at children. We do not knowingly collect data from anyone under 16. Where a campaign involves a creator under 18, we require verified parental or guardian consent before any personal data is processed.
11. Changes to this policy
If we change how we handle personal data we will update this page and change the date below. Material changes affecting people we already hold data on will be communicated directly.
12. Contact
The Contact — Stockholm, Sweden
info@thecontact.se
073 360 88 83
Last updated: 20 August 2026
