Last Updated: November 4, 2025
Our Commitment: GlennGPT is built with privacy and GDPR compliance at its core. We go beyond legal requirements to ensure your data is protected, transparent, and under your control.
The General Data Protection Regulation (GDPR) is a comprehensive data protection law enacted by the European Union in 2018. It establishes strict requirements for how organizations collect, process, store, and protect personal data of EU residents.
GDPR applies to any company processing personal data of EU residents, regardless of where the company is located. As a Swedish-based service, we are fully committed to GDPR compliance and Swedish data protection law.
We process data lawfully and transparently, clearly explaining what data we collect and why.
We collect data only for specific, explicit purposes and don't use it for anything else.
We only collect data that is necessary for providing the service you signed up for.
We keep your data accurate and up-to-date, with tools for you to correct it easily.
We don't keep data longer than necessary, with clear retention schedules.
We protect data with strong security measures, encryption, and access controls.
We document our compliance measures and can demonstrate GDPR compliance.
Unlike many AI services that store data in the US or distribute it globally, GlennGPT keeps 100% of your data within Sweden:
GDPR grants you comprehensive rights over your personal data. Here's what each right means in practice with GlennGPT:
What it means: You can request a copy of all personal data we hold about you.
How to exercise: Email privacy@aisamtal.se or use the "Export Data" feature in your account settings.
Response time: Within 30 days, delivered in JSON or CSV format.
What it means: You can correct inaccurate or incomplete personal data.
How to exercise: Update directly in your account settings, or contact us for assistance.
Response time: Changes take effect immediately when made in your account.
What it means: You can request deletion of your personal data under certain conditions.
How to exercise: Use "Delete Account" in settings or email privacy@aisamtal.se.
What happens:
What it means: You can limit how we process your data while resolving a dispute or verifying accuracy.
How to exercise: Contact privacy@aisamtal.se with specific restrictions requested.
Effect: We will mark your data as restricted and only process it with your consent or for legal claims.
What it means: You can receive your data in a machine-readable format to transfer to another service.
How to exercise: Use the "Export" feature or email privacy@aisamtal.se.
What you get: JSON format containing account info, conversation history, settings, and usage data.
What it means: You can object to processing based on legitimate interests or for direct marketing.
How to exercise: Email privacy@aisamtal.se specifying what processing you object to.
Response: We will stop processing unless we demonstrate compelling legitimate grounds.
We do not use automated decision-making or profiling that produces legal effects or significantly affects you. AI-generated content is always the result of your direct prompts, not autonomous decisions about you.
Every processing activity must have a legal basis under GDPR. Here's our complete legal basis map:
Processing necessary to provide the service you subscribed to:
Processing necessary for our legitimate business interests, balanced against your rights:
Processing required by Swedish or EU law:
Optional processing that requires your explicit consent:
Under GDPR Article 28, we maintain Data Processing Agreements (DPAs) with all third-party processors:
Our processors may use sub-processors. We maintain an updated list and ensure all sub-processors meet GDPR requirements through Standard Contractual Clauses or adequacy decisions.
GDPR Article 32 requires appropriate technical and organizational measures. Here's how we implement security:
In accordance with GDPR Article 33 and 34, we have established procedures for detecting, reporting, and investigating data breaches:
If a breach poses a high risk to your rights and freedoms, we will notify you directly with:
GDPR Article 25 requires privacy to be built into services from the ground up. Here's how we implement this:
While we prioritize European data processing, some limited transfers may occur:
Primary processing occurs in Sweden and Netherlands (Mollie), both within the EU. No additional safeguards needed.
In rare cases, sub-processors may involve data transfers outside the EU/EEA. These are protected by:
As a Swedish company, our lead supervisory authority is:
Swedish Authority for Privacy Protection (IMY)
Integritetsskyddsmyndigheten
Box 8114
104 20 Stockholm
Sweden
Website: www.imy.se
Email: imy@imy.se
Phone: +46 8 657 61 00
If you have concerns about our data practices that we haven't resolved, you have the right to lodge a complaint with IMY or your local data protection authority.
GDPR requires us to demonstrate compliance. We maintain:
GDPR compliance is not a one-time effort. We maintain ongoing compliance through:
For any questions about our GDPR compliance or to exercise your data rights:
Data Protection Officer: privacy@aisamtal.se
General Support: support@aisamtal.se
Website: https://aisamtal.se
We aim to respond to all GDPR-related inquiries within 30 days.
For more details about how we handle your data, please see our Privacy Policy and Terms of Service.
Last reviewed and verified for GDPR compliance: November 4, 2025