Privacy Policy
Last updated: 2026-08-31
Dario Dario ("we", "us", "our") respects your privacy. This policy explains how we collect, use, and protect personal data in accordance with the EU General Data Protection Regulation (GDPR) and Swedish law.
1. Data controller
Dario Dario
Östermalmsgatan 26A, 114 26
Stockholm, Sweden
Company reg.: 559576-4415
Email: hello@dariodario.com
2. What we collect
- Contact. When you email us or submit a form: name, email, company, and the message you send.
- Newsletter. If you subscribe: email address and the time of signup.
- Client portal. If you sign in: email, authentication data, and session information.
- Technical data. Logs, IP address, browser type, and approximate location, to operate and secure the service.
- Analytics. Aggregated usage statistics via PostHog (EU region) — pageviews, referrer, device type, country, and which features are used. The analytics are cookieless: nothing is stored on your device and no identifier follows you between visits. If you sign in, usage is linked to your account ID (a random UUID), never to your email address.
3. Purposes and legal basis
- Responding to inquiries — legal basis: legitimate interest and, where applicable, contract.
- Sending the newsletter — legal basis: consent, which you may withdraw at any time.
- Providing the client portal — legal basis: contract.
- Security, operations, and improvement — legal basis: legitimate interest.
- Legal obligations — e.g. accounting and tax law.
4. Recipients and processors
We share data with vendors who process it on our behalf under data processing agreements. Current subprocessors include:
- Cloudflare (hosting, CDN, security)
- Supabase (database and authentication)
- Google (OAuth sign-in)
- PostHog (product analytics, EU region)
- Email service provider for outbound and support
5. Transfers outside the EEA
Some vendors may process data outside the EEA. Where this happens, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision (e.g. the EU-US Data Privacy Framework).
6. Retention
We retain data only as long as necessary for the stated purpose: inquiries up to 24 months, newsletter subscriptions until you unsubscribe, client accounts for the duration of the engagement, and financial records per Swedish bookkeeping law (typically 7 years).
7. Your rights
You have the right to:
- access the data we hold about you,
- request correction of inaccurate data,
- request erasure ("the right to be forgotten"),
- request restriction of processing,
- object to processing based on legitimate interest,
- request data portability,
- withdraw consent at any time.
You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se.
8. Cookies and analytics tools
We use only the cookies needed to operate the site. No advertising or profiling cookies are set, and our web analytics set no cookies at all.
- Strictly necessary. Session and
language preference (e.g.
dd_intl). Required for the site to function. - PostHog (web analytics). Sets no cookies and stores nothing on your
device — no cookies, no localStorage, no sessionStorage.
No ePrivacy/PECR consent is therefore required. The
statistics are aggregated and cannot follow you between
visits. Data is processed inside the EU (PostHog EU
region). Legal basis: legitimate interest in
understanding how the service is used. We honour your
browser's
Do Not Tracksetting — with it on, you are not recorded at all.
9. Changes
We may update this policy. The latest version is always published here, with the date at the top.
10. Contact
Questions about this policy or how we handle your data? Email us at hello@dariodario.com.