Integritetspolicy
We are a Swedish law firm advising businesses on AI, data protection and EU regulation. We take the same care with your personal data that we ask our clients to take with theirs. This policy (the “Privacy Policy”) provides information on the collection, use, sharing and processing of personal data in connection with your use of Lawgent’s website (the “Site”), platform, products, features, technologies and plug-ins exchanging information with Lawgent (“Services”) and/or any other digital service that links to this Privacy Policy. The Privacy Policy also covers interactions you have with Lawgent during in-person meetings or at events, and in the context of other offline sales and marketing activities, and describes your rights and how you can exercise them with regards to these processing activities.
Last updated: 22 August 2026. Controller: Lawgent AB, reg. no. 559426-9507.
1. Scope of this Privacy Policy
1.1 This Privacy Policy applies when Lawgent is the data controller responsible for processing personal data of:
- visitors and users of the Lawgent Site and Services, including any other digital service that links to this Privacy Policy;
- attendees of Lawgent events, webinars and surveys;
- customers and prospective customers and their representatives; and
- suppliers, service providers, business partners and any third party, including prospects, and their representatives.
1.2 The terms “personal information” and “personal data” mean any and all information that relates to an identified individual or to an identifiable individual. For example, this could include inter alia your name, address, email address, business contact details, title or information gathered through your interactions with us via our websites, services, competitions, surveys and/or at events.
2. What we collect
2.1 Information you give us: your name, contact details, employer and role, and whatever you choose to tell us about your matter, including any documents you send.
2.2 Information collected when you use our website: your IP address, browser and device type, and which pages you visit.
2.3 Information from other sources: public registers such as Bolagsverket, publicly available professional sources such as LinkedIn and company websites, and referrals from clients or business contacts.
2.4 Giving us your information is voluntary, but without it we cannot answer your enquiry or act for you.
2.5 Please do not send sensitive information or identity documents through the website contact form. Contact us first and we will agree on a secure channel.
2.6 Chat, call-back and WhatsApp: if you contact us through the chat window on the Site, the call-back function or WhatsApp, we receive the content of your message, your telephone number or chat identifier, any name or profile information you have chosen to display, and the time of the exchange. These channels are run by external providers and your message passes through their systems before it reaches us.
2.7 WhatsApp in particular: in the EEA the service is provided by WhatsApp Ireland Limited, which acts as an independent controller for the messaging service under its own privacy policy. We have no data processing agreement with it for that service and cannot control how it handles your telephone number, your profile information or the metadata of your messages. Messages are encrypted in transit but remain readable on the devices at each end.
2.8 Please treat chat, call-back and WhatsApp as channels for a first contact only. Do not send documents, personal identity numbers, health information or the details of a legal matter through them before we have confirmed an engagement in writing and agreed a secure channel with you.
3. Why we use it, and our legal basis
3.1 To answer your enquiry and hold the first consultation. Our basis is that the processing is necessary for steps taken at your request before entering into a contract, Article 6(1)(b) GDPR, or, where you write on behalf of a company, our legitimate interest in responding to business enquiries, Article 6(1)(f) GDPR.
3.2 To check for conflicts of interest and decide whether we can take on a matter. Our basis is our legitimate interest in avoiding conflicts and protecting the integrity of our practice, Article 6(1)(f) GDPR.
3.3 To carry out the engagement, including advice, correspondence, document handling and invoicing. Our basis is performance of a contract, Article 6(1)(b) GDPR, or, where our client is a company and you are its contact person, our legitimate interest in running the engagement, Article 6(1)(f) GDPR.
3.4 To send our newsletter and invitations to seminars and events. Our basis is your consent, Article 6(1)(a) GDPR. You can unsubscribe at any time using the link in the email or by writing to us.
3.5 To keep our accounts and meet tax and bookkeeping requirements. Our basis is a legal obligation, Article 6(1)(c) GDPR, in particular the Swedish Accounting Act (1999:1078).
3.6 To run and secure our website and to see how it is used. Our basis is our legitimate interest in keeping the site available and free from misuse, and your consent for analytics cookies, as described in clause 4.
3.7 To handle complaints and to establish, exercise or defend legal claims. Our basis is our legitimate interest in protecting our legal position, Article 6(1)(f) GDPR, and Article 9(2)(f) GDPR where sensitive information is involved.
3.8 Where we rely on our legitimate interest, we have weighed it against your rights. You can ask us about that assessment, and object to the processing, at any time.
4. Cookies
4.1 We use necessary cookies to make the website work. These are set without consent, as the law allows.
4.2 We use Google Analytics, with your IP address anonymised, to see how the site is used. These cookies are set only if you accept them in our cookie banner.
4.3 You can change or withdraw your choice at any time through the cookie settings on our website, or by blocking and deleting cookies in your browser.
5. AI tools
5.1 We use AI assisted tools for research, drafting support and administration. We do not put client confidential information into tools that use it to train their models.
5.2 Everything an AI tool produces is reviewed by one of our lawyers before it is used. We never make a decision about you by automated means alone.
6. Who we share information with
6.1 We share personal data only where it is necessary, and only with recipients who are bound by confidentiality: our own colleagues, our IT, hosting, email and CRM providers, our accountant and auditor, our insurers and advisers, and, where a matter requires it, external counsel, courts, authorities and counterparties.
6.2 We never sell personal data and we never share it for third party advertising.
6.3 Where a supplier handles personal data on our behalf, we have a written data processing agreement with them as required by Article 28 GDPR.
6.4 Our Services may contain links to other websites not operated or controlled by Lawgent, including social media services (“third-party sites”). The information that you share with third-party sites will be governed by the specific privacy policies and terms of service of the third-party sites and not by this Privacy Policy. By providing these links we do not imply that we endorse or have reviewed these sites. Please contact the third-party sites directly for information on their privacy practices and policies.
6.5 Lawgent may also share your personal data if required to do so by law or in the good faith belief that such action is necessary to (i) comply with a legal obligation, including to meet national security or law enforcement requirements, (ii) protect and defend our rights or property, (iii) prevent fraud, (iv) act in urgent circumstances to protect the personal safety of users of the Services, or the public, or (v) protect against legal liability.
6.6 Chat and call-back providers: the chat window and the call-back function on the Site are operated by external suppliers who process the content of your messages on our behalf under a written data processing agreement as described in clause 6.3.
6.7 WhatsApp: WhatsApp Ireland Limited is not our processor. It determines its own purposes for the messaging service and acts as an independent controller. When you choose to contact us on WhatsApp you also enter into a relationship with WhatsApp that is governed by its own privacy policy and not by this Privacy Policy, in the same way as the third-party sites described in clause 6.4.
7. Transfers outside the EU and EEA
7.1 We keep personal data within the EU and EEA wherever we can. If a supplier processes data outside the EU and EEA, Lawgent always ensures that the same high level of protection applies to your personal data according to the relevant data protection laws, even when the data is internationally transferred. Your rights in respect to your personal data are not affected when data is internationally transferred.
7.2 Such appropriate safeguards include, but are not limited to:
7.2.1 Adequacy decisions. If the relevant authority, for example the EU Commission, has decided that the country to which your personal data are transferred has an adequate level of protection, which corresponds to the level of protection afforded by the relevant data protection laws. This means for example that the personal data is still protected from unauthorised disclosure, and that you may still exercise your rights with regard to your personal data.
7.2.2 Standard Contractual Clauses. The relevant authority’s standard clauses have been entered into between Lawgent and the recipient of the personal data. This means that the recipient guarantees that the level of protection for your personal data afforded by the relevant data protection laws still applies, and that your rights are still protected. In these cases, we also assess whether there are laws in the recipient country that affect the protection of your personal data. Where necessary, we take technical and organisational measures so that your data remain protected during the transfer to the relevant country.
7.2.3 Derogation. In limited circumstances, we may rely on an exception, or derogation, under the applicable data protection laws, to transfer your personal data to such country despite the absence of an adequacy decision or standard contractual clauses, such as relying on your explicit consent to that transfer or because it is necessary for the establishment, exercise or defence of legal claims, including regulatory, administrative or any out of court procedure, and seeking advice.
7.2.4 Data Privacy Framework. If the transfer is covered by a relevant data privacy framework, such as the EU-US Data Privacy Framework, which is an opt-in certification scheme for US companies, administered by the US Department of Commerce. Data privacy frameworks include sets of enforceable principles and requirements that a certified company must meet, ensuring that your data is still being sufficiently protected.
7.3 Where you contact us through WhatsApp, WhatsApp Ireland Limited may transfer personal data to Meta group companies outside the EU and EEA under safeguards that it determines. Those transfers are outside our control and are not covered by the safeguards described in this clause 7. If you would prefer that your data stays with suppliers we have contracted with, use email, the contact form or the telephone instead.
8. How long we keep it
8.1 Enquiries that do not lead to an engagement: 12 months from our last contact.
8.2 Client files and correspondence: 10 years from the closing of the matter, which matches the general limitation period in Sweden. Longer where the matter concerns rights that last longer, such as property or intellectual property.
8.3 Accounting material, including invoices: 7 financial years, as the Accounting Act requires.
8.4 Newsletter subscriptions: until you unsubscribe.
8.5 Website logs: 12 months.
8.6 We keep information for longer only where the law requires it, or where it is relevant to a legal claim.
8.7 Chat, call-back and WhatsApp messages: for as long as we need them to deal with the enquiry. If the enquiry leads to an engagement the relevant content is moved into the matter file and kept under clause 8.2. If it does not, it is deleted under clause 8.1.
9. Security
9.1 We protect personal data with technical and organisational measures appropriate to the risk, including access controls, encryption and confidentiality undertakings for everyone who works with us. Everything you tell us is also covered by our professional duty of confidentiality.
9.2 If a personal data breach occurs and it is likely to put your rights at risk, we notify the Swedish Authority for Privacy Protection, and you, as the GDPR requires.
10. Your rights
10.1 You have several rights under the applicable data protection laws, including the GDPR, related to your control over your personal data and to receive information directly from us on how we process personal data about you. In the following you can read about your rights.
10.2 Right to information and access. You have the right to be informed of how we process your personal data. We do this through this Privacy Policy and by answering your questions. You can request information regarding whether we are processing your personal data and ask to receive a copy of your personal data (“data extract”), so called data subject access. Through the data extract you will receive information about what personal data Lawgent holds about you and how we process it.
10.3 Right to rectification. If you believe that your personal data is inaccurate or incomplete, you have the right to ask for it to be corrected or completed.
10.4 Right to restriction. If you believe that your personal data is inaccurate, that our processing is unlawful or that we do not need the information for a specific purpose, you have the right to request that we restrict the processing of such personal data. You also have the possibility to request that we stop processing your personal data while we assess your request. If you object to our processing per your right described directly below, you may also request us to restrict processing of that personal data while we make our assessment.
10.5 Right to object. You have the right to object to the processing of your personal data which is based on our legitimate interest, Article 6(1)(f) GDPR, by referencing your personal circumstances. If we cannot demonstrate compelling and legitimate grounds to continue processing the personal data, we must cease the processing. You can also always object to our processing of your personal data for direct marketing purposes. If you do so, we will turn off marketing for you, and stop sending it to you.
10.6 Right to be forgotten. In some cases, you have the right to have us delete personal data about you. For example, you can request us to delete personal data that we (i) no longer need for the purpose it was collected for, or (ii) process based on your consent and you revoke your consent. There are situations where Lawgent is unable to delete your data, for example, when the data is still necessary to process for the purpose for which the data was collected, Lawgent’s interest to process the data overrides your interest in having them deleted, or because we have a legal obligation to keep it.
10.7 Right to transfer your personal data (data portability). If we process your personal data to fulfil a contract or on the basis of your consent, you may, in certain cases, be able to obtain the personal data for use elsewhere, for example by obtaining a copy of it in a machine readable format and transmitting it to another data controller.
10.8 Right to withdraw consent. In those cases where we process your personal data based on your consent, you have the right to withdraw your consent at any time. When you withdraw your consent, we will stop any processing of personal data which is based on your consent. Where your consent relates to the use of cookies and similar tracking technologies on our Site, you may withdraw your consent at any time via our consent management platform accessible via the cookie banner on our Site. For further information please see our Cookie Policy.
10.9 Right to lodge a complaint. If you have objections or concerns about how we process your personal data, you have the right to contact, or lodge a complaint with, the relevant authority for privacy protection, which is the supervisory authority for our personal data processing. In Sweden this is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, imy@imy.se, +46 8 657 61 00, www.imy.se.
10.10 To exercise your rights, please contact us at any time. We reserve the right to limit our facilitating such requests to that which is required by applicable law.
10.11 In order to protect your personal data from unauthorised access or deletion, we may require you to verify your identity before we will process any request to know or delete personal data. If we cannot verify your identity, and, where applicable, proof of residency, to our satisfaction, we will not provide or delete your personal data. You may submit a request to exercise your rights through an authorised agent. Such an agent must present signed written authority to act on your behalf and must be able to verify your identity, and, where applicable, proof of residency, to our satisfaction.
10.12 Rest assured that we will not discriminate against you for making any such request. Your right to access and delete your personal data is important to us, and we will take reasonable steps to verify and process your request promptly.
10.13 Please be aware that even if we delete your personal data, certain residual data may still remain in our backups or archives for a limited period in accordance with our data retention policies and applicable laws.
10.14 If you have any questions or concerns about this process or our data deletion practices, please feel free to contact us.
11. Changes to this policy
11.1 We may update this Privacy Policy from time to time. When the Privacy Policy is updated, we will post an updated version on this page, unless another type of notice is required by applicable law or contractual agreement. By continuing to use our Services or providing us with personal data after we have posted an updated Privacy Policy, or notified you by other means, you consent to the revised Privacy Policy.
12. Contact
12.1 If you have any questions about our Privacy Policy or any other privacy related issue, please contact us at law@lawgent.se.
12.2 Controller’s contact information:
Lawgent AB
Registration number 559426-9507
Stampgatan 14, 411 01 Gothenburg, Sweden
law@lawgent.se