1. About this policy
This GDPR Policy describes how ZORC.se, operated by ZORC AB (company registration no. 559481-8857), handles personal data in accordance with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679).
2. Data controller
ZORC AB (company registration no. 559481-8857), which operates ZORC.se, is the data controller for all processing of personal data carried out via ZORC.se and related services.
Contact: support@zorc.se
3. Cookies and tracking
We use cookies to improve your experience on the website.
- Strictly necessary cookies: required for basic functionality
- Analytics cookies: help us understand how the website is used (require consent)
- Marketing cookies: used to show relevant content (require consent)
4. Data processing agreements
We have data processing agreements (DPAs) with all sub-processors that handle personal data on our behalf.
5. Transfers outside the EU/EEA
Your data is stored within the EU/EEA (Stockholm). However, some of our processors and their sub-processors are established outside the EU/EEA, primarily in the United States and Singapore, and may process personal data in that capacity. For such transfers we apply appropriate safeguards under GDPR Chapter V:
- United States: the European Commission's adequacy decision for the EU–US Data Privacy Framework (2023), where the recipient is certified.
- Singapore (database processor Supabase Pte Ltd) and otherwise: the European Commission's Standard Contractual Clauses (SCCs), Decision (EU) 2021/914 pursuant to GDPR Art. 46.
You may request a copy of the safeguards via support@zorc.se. See also our Privacy Policy for a full list of processors.
6. Personal data breaches
In the event of a personal data breach, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours.
7. Data protection contact
Contact us at support@zorc.se for GDPR-related questions.
8. Supervisory authority
The Swedish Authority for Privacy Protection (IMY) is the supervisory authority in Sweden. Website: www.imy.se