Your rights come first
We collect name, address, email and phone in order to enter into an agreement with you, and health information in the form you fill in before the course.
Six things you have a right to
They apply at all times, and you do not have to explain why you are using them.
- See what we hold
- You can request a copy of all the personal data we process about you.
- Have it corrected
- If something is wrong or incomplete, you have the right to have it corrected or completed.
- Be erased
- If we are processing data incorrectly, or no longer need it, you have the right to have it removed. We would then no longer be able to deliver the course to you.
- Take your data with you
- Data you provided yourself can be supplied in a machine-readable format, so you can take it elsewhere.
- Restrict processing
- You can ask us to use the data only for certain specified purposes.
- Complain
- If you believe we handle your data wrongly you can turn to the Swedish Authority for Privacy Protection, imy.se.
Write to info@vitalisera.se or call +46 8 400 155 99. We may need to establish that you are who you say you are before releasing anything.
Who is responsible
What we collect, and why
We process your personal data in order to enter into and fulfil an agreement with you as a participant.
What we need is first name, surname, email address, postal address and phone number. Before the course you also complete a health questionnaire that is stored as a document, so that we can meet you in the right way.
Parts of that questionnaire concern health, which is sensitive personal data. It is handled with particular care and on a legal basis.
The contact form receives your name, email address and the subject and message you choose to provide, so that we can handle your enquiry.
The forms are protected by Cloudflare Turnstile. When the check loads, the first time you fill in or submit a form, Cloudflare receives your IP address, a TLS fingerprint, the User-Agent (information about your browser) and our site key, to detect and stop bots. This happens independently of your choice in the consent box, and no cookie is set. Read more in Cloudflare’s information about Turnstile.
Analytics load only if you press Accept in the consent box. Before you choose, and after Decline, no analytics load and no cookies are set. After Accept, Google Analytics measures visits, Google Ads and Meta connect a registration to the advertisement that led here, and Microsoft Clarity measures how the page is used.
Without your consent we use none of this for marketing.
Who sees it
We do not pass your data to other companies or organisations unless required by law or necessary in order to meet our obligations to you.
Partners, suppliers and subcontractors may receive data, but only to the extent needed for us to run the course, handle enquiries and protect the forms. Never more than necessary.
After Accept, Google, Meta and Microsoft receive information about your visit through their cookies. Cloudflare receives the bot check’s technical information.
We never sell or pass on personal data for anyone else's marketing.
How long we keep it
Other data, such as contact details and what you wrote in your registration of interest, we keep for the term of the agreement and a reasonable time thereafter, in most cases no longer than a year after the agreement ended.
Your health form and your life story are stored as documents in our Google Drive. Some time after the course we ask you what should happen to them: you can let us keep them, receive them as a PDF and let us keep them, or receive them as a PDF and have us delete them. If you choose deletion, the document is moved to the bin and is no longer accessible to us; we keep the note that you were asked and what you answered, because we need to be able to show that we followed your choice.
Longer retention can occur where the law requires it, or where the data is needed to establish or defend a legal claim.
The cookies set after Accept stay in your browser: Google Analytics (_ga, _ga_8DWN42FG57) for about 400 days; Google Ads (_gcl_au) for about 90 days and, on doubleclick.net, test_cookie for about 15 minutes and IDE for about 390 days; Meta (_fbp) for about 90 days; Microsoft Clarity (_clck) for about 365 days and (_clsk) for about a day, plus on clarity.ms MUID for about 390 days and the session cookie SM during the visit.
How it is protected
We have put technical, organisational and administrative security measures in place against unauthorised access and other unlawful processing, and review them regularly.
Legal basis
We process only the data needed to enter into or fulfil the agreement with you. If we need to process anything beyond that we obtain your consent, or establish that the processing has another valid legal basis.
Measurement with Google, Meta and Microsoft Clarity is based on your consent, which you can change on the cookies page.
