Do not submit ERP exports, customer records, payroll or banking data, financial datasets, credentials, or other confidential files. Secure transfer instructions are supplied after qualification.
1. Who is responsible for your information
Sapientia Finance AB is the controller for personal data used to operate this website, answer business enquiries, and administer its own customer relationships.
Organisation number: 559052-6777
VAT number: SE559052677701
Business address: c/o S Zuberovic, Trollesundsvägen 58C, 124 30 Bandhagen, Sweden
Privacy contact: contact@sapientiafinance.com
2. Scope of this policy
This policy covers personal data processed through business enquiries, prospective and active B2B engagements, and visits to this website. Where Sapientia Finance AB processes personal data contained in a customer dataset solely on the customer’s documented instructions, the parties’ roles and any required data-processing terms will be established in the written engagement.
3. Information we may process
- Business identity and contact details, such as name, role, employer, business email address, and correspondence.
- Enquiry and engagement information, such as a non-confidential project description, quotation, instructions, contract or marketplace reference, delivery feedback, and billing records.
- Technical information made available by hosting or security systems after deployment, such as IP address, timestamps, request details, and security events.
- Customer project files received through the agreed secure channel. Depending on the customer’s data, these files may contain personal data relating to its staff, customers, suppliers, or other business contacts.
4. Why we process information and our lawful bases
- Enquiries and scoping: to respond, assess fit, and prepare a quotation. We rely on legitimate interests in handling B2B enquiries and, where applicable, steps requested before entering a contract.
- Service delivery and administration: to perform the agreed work, communicate, provide deliverables, and manage the relationship. We rely on contract where the individual is a contracting party and otherwise on legitimate interests in fulfilling the customer engagement.
- Billing and records: to invoice, account, and retain records required by law. We rely on contractual necessity and legal obligations.
- Security and legal claims: to protect systems and information, investigate incidents, prevent misuse, and establish or defend legal claims. We rely on legitimate interests and applicable legal obligations.
We do not use consent as the ordinary basis for handling B2B enquiries or delivering contracted services.
5. Website, cookies, enquiry form, and email
The website provides a project-enquiry form. It sends the information you submit to the approved Sapientia Finance business mailbox through the existing hosting and email environment. The form does not accept file uploads or write enquiry content to a local website database. The website uses no analytics, advertising trackers, account registration, or online checkout and does not itself set analytics or advertising cookies. Hosting and email providers may process limited technical logs and message metadata for operation and security.
The enquiry form and ordinary email are only for an initial, non-sensitive project description. Confidential ERP, customer, payroll, banking, financial, or other customer data must not be submitted through the form or attached to ordinary email.
6. Customer project data and secure transfer
After qualification, Sapientia Finance supplies separate secure-transfer instructions. Tresorit Professional is the selected encrypted transfer service and multi-factor authentication is enabled. Selection of a service does not by itself state that every contractual or data-protection review has been completed; project-specific requirements will be confirmed in writing before files are accepted.
Project files are used only for the agreed service, kept in access-restricted and job-isolated work areas, integrity-checked on intake, and reviewed before delivery. These measures reduce risk but cannot guarantee absolute security. Processing of real customer files remains unavailable until the required at-rest protection and pilot approvals are complete.
7. Service providers and recipients
We may use providers for business email, website hosting, secure transfer, infrastructure, accounting, and professional advice where necessary. Tresorit Professional is the selected secure-transfer provider. Providers may process information only for their contracted purpose and are assessed before use where the engagement requires it. We may also disclose information where law requires it or where necessary to establish or defend legal claims.
8. International transfers
A provider’s location or support arrangements may involve processing outside Sweden or the European Economic Area. Before a relevant transfer is used for customer work, we assess the arrangement and, where required, use an applicable transfer mechanism such as an adequacy decision or approved standard contractual clauses, together with appropriate supplementary safeguards. Specific provider and transfer details can be addressed in the engagement documentation.
9. Retention
We retain enquiry and relationship information only while needed for the purposes above, including reasonable follow-up, accounting, legal, and claims requirements. The default retention period for customer source files, working files, and local final-deliverable copies is 30 days after final delivery, after which they are scheduled for deletion. A customer may request a shorter period, which will be recorded for the engagement. A different period will apply only where agreed in writing or required by law.
10. Your data-protection rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict, or receive certain personal data, and to object to processing based on legitimate interests. Where processing is based on consent, you may withdraw that consent. These rights are not absolute and legal exceptions may apply.
To exercise a right, email contact@sapientiafinance.com. We may need proportionate information to verify your identity. If you believe personal data has been handled incorrectly, you may complain to the Swedish Authority for Privacy Protection (IMY).
11. Changes and contact
We may update this policy when our services, providers, or legal obligations change. The date above identifies the current version. Questions about this policy should be sent to contact@sapientiafinance.com. Sapientia Finance AB has not appointed a data protection officer; use this business privacy contact.