CloudBlocks / Privacy policy
Privacy policy
Last updated:
This privacy policy explains how CloudBlocks AB processes personal data when you visit cloudblocks.se, contact us, book a meeting, buy our products, hire us for web and app development, or use our apps and integrations with third-party platforms such as Google, Meta (Facebook and Instagram) and TikTok. We comply with the EU General Data Protection Regulation (GDPR, Regulation (EU) 2016/679) and supplementary Swedish law.
1. Who is responsible for your data
CloudBlocks AB (organisation number 559520-4370)
Lindekullegatan 41B, 441 65 Alingsås, Sweden
Email: info@cloudblocks.se · Phone: +46 700 600 143
CloudBlocks AB is the controller of the processing described in this policy. Web and app development is delivered by our studio Devise IT's in Alingsås (info@deviseits.com). For any privacy question, contact us at the address above.
2. What data we process and why
| Situation | Data | Purpose | Legal basis (GDPR) |
|---|---|---|---|
| You visit the website | IP address, browser type, date/time, pages requested (server logs) | Deliver the website securely, prevent abuse, fix errors | Legitimate interest, Art. 6(1)(f) |
| You use the contact form or email/call us | Name, email, phone, chosen topic, your message | Answer your question and follow up | Legitimate interest, Art. 6(1)(f); or steps before a contract, Art. 6(1)(b) |
| You book a meeting | Name, email, phone, company (optional), topic, message (optional), chosen time and language | Book, confirm and hold the meeting; send the calendar invitation and Google Meet link | Steps before a contract, Art. 6(1)(b), and legitimate interest, Art. 6(1)(f) |
| You buy our products | Name, delivery address, email, phone, order and payment details | Deliver your order, handle returns, complaints and warranty | Contract, Art. 6(1)(b) |
| Bookkeeping | Invoices, order and payment records | Meet accounting requirements | Legal obligation, Art. 6(1)(c) (Swedish Bookkeeping Act) |
| We deliver a web or app project | Contact details of client representatives, project communication | Plan, deliver and support the project | Contract, Art. 6(1)(b); legitimate interest, Art. 6(1)(f) |
| You connect an account to our apps and integrations | See section 3 | Provide the features you chose to use | Contract, Art. 6(1)(b), and consent where applicable, Art. 6(1)(a) |
| Optional cookies (analytics/marketing) | See our cookie policy | Understand and improve the website | Consent, Art. 6(1)(a) |
Contact form and meeting booking: your details are sent over an encrypted connection to our web server, which forwards them to us by email and sends you a confirmation. For bookings, the web server stores the booking (time, name, email and phone) to prevent double bookings and deletes it automatically 30 days after the meeting. If the meeting is held on Google Meet, an event with your contact details is created in our Google Calendar.
We never sell your personal data, and we do not use automated decision-making or profiling that has legal or similarly significant effects on you.
3. Apps and integrations with Google, Meta and TikTok
We develop and operate apps and integrations that connect to third-party platforms — for example to manage business profiles, publish posts to several social channels at once, read insights or schedule meetings. An integration is only connected to an account when you (or your organisation) actively sign in with the platform and approve the permissions shown.
Data we may access
- Basic account information: name, email address, profile picture and account ID.
- Google: calendar events and free/busy information (Google Calendar and Google Meet), and business profile information, posts and reviews (Google Business Profile) — only the permissions you approve.
- Meta (Facebook and Instagram): Pages and business accounts you manage, content you choose to publish, and comments and insights for those Pages and accounts.
- TikTok: basic profile information, videos you choose to publish and insights for your account.
- Access tokens needed for the integration to work.
How we use this data
- The data is used only to provide and improve the features you have chosen to use — for example showing your insights, publishing content you approved or creating a meeting.
- We do not sell the data, do not use it for advertising and do not share it with third parties except as needed to provide the service, comply with the law or protect security.
- We do not use data obtained from these platforms to train generalised AI or machine-learning models.
- No human reads your data unless you have given explicit consent, it is necessary for security purposes or to comply with the law, or the data has been aggregated and anonymised.
Google API Services — Limited Use disclosure: CloudBlocks AB's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We also comply with the Meta Platform Terms and the TikTok Developer Terms of Service.
Revoking access and deleting data
You can revoke our access at any time: in your Google Account (Third-party apps), in Facebook under Settings → Business Integrations, in Instagram under Settings → Website permissions → Apps and websites, and in TikTok under Settings → Security → Manage app permissions. When access is revoked, or when you ask us, we delete the data and tokens within 30 days. See our Data deletion page.
4. Spam protection
The contact form and meeting booking are protected by a simple maths question checked on our own server, plus hidden checks that stop automated bots. No cookies and no third parties are involved. To stop repeated abuse, we store a pseudonymised (one-way encrypted) version of your IP address for at most one hour, after which it is deleted automatically. The legal basis is our legitimate interest in keeping the forms free of spam (Art. 6(1)(f)).
5. Who we share data with
- Processors — web hosting, email, IT services and Google Workspace (Calendar and Google Meet) — that process data on our behalf under data processing agreements.
- Logistics and delivery partners — to deliver your order.
- Marketplaces and payment providers — e.g. Amazon and Shopify for purchases made there; they are responsible for their part of the purchase.
- Platforms you connect — Google, Meta and TikTok receive the content you choose to publish through our integrations, under their own terms.
- Accountants and authorities — when required by law, e.g. the Swedish Tax Agency.
6. Transfers outside the EU/EEA
We aim to process personal data within the EU/EEA. Some providers (e.g. Google, Meta, TikTok, Amazon and Shopify) may process data outside the EU/EEA. When that happens we make sure the transfer is lawful — for example under an EU Commission adequacy decision (such as the EU–US Data Privacy Framework for certified companies) or the EU Standard Contractual Clauses with supplementary safeguards.
7. How long we keep data
- Enquiries by email and forms: as long as needed to handle your question, and at most 24 months after our last contact unless it leads to a customer relationship.
- Meeting bookings: the booking record on the web server is deleted 30 days after the meeting; the calendar event and email correspondence are kept as described above.
- Customer and order data: during the customer relationship and complaint period (generally up to 3 years under the Swedish Consumer Sales Act).
- Accounting records: 7 years after the end of the financial year, as required by the Swedish Bookkeeping Act.
- Data from connected platforms: while the integration is active; deleted within 30 days of revoking access or requesting deletion.
- Server logs: a short time for security purposes, normally no longer than 30 days. Pseudonymised IP address (spam protection): at most 1 hour.
8. Your rights
Under the GDPR you have the right to:
- Access — get a copy of the personal data we hold about you (Art. 15).
- Rectification — have incorrect data corrected (Art. 16).
- Erasure — have your data deleted when it's no longer needed or the processing is unlawful (Art. 17).
- Restriction — have processing limited in certain situations (Art. 18).
- Data portability — receive data you gave us in a machine-readable format (Art. 20).
- Object — object to processing based on legitimate interest, and always to direct marketing (Art. 21).
- Withdraw consent — at any time, without affecting processing done before (Art. 7(3)). For cookies, use .
To use your rights, email info@cloudblocks.se. We reply within one month and may need to confirm your identity.
9. Complaints
If you believe we handle your data incorrectly, please contact us first. You also have the right to lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
www.imy.se · imy@imy.se
If you live in another EU/EEA country, you can also complain to the data protection authority there.
10. Cookies
By default we only use what is strictly necessary. Optional cookies are only used with your consent. See our cookie policy.
11. Security
We protect personal data with appropriate technical and organisational measures, including encrypted connections (HTTPS), access control, secure storage of access tokens and carefully selected providers.
12. Children
Our services are not directed at children under 13, and we do not knowingly collect their personal data.
13. Changes to this policy
We may update this policy, for example when we launch new services. The date at the top shows when it was last changed. Significant changes will be announced on the website.