Privacy policy.

This privacy policy describes the information PepperVault AB (company registration number: 559416-3726) processes and uses to support the app, website and other products and features offered by PepperVault AB (“PepperVault” or “we”, “us”, “our”) (“PepperVault App” or “app”) process personal data in accordance with the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016. General Data Protection Regulation (“GDPR”) and any other Swedish laws and regulations applicable in the field of data protection. This privacy policy explains how we use the personal data that we collect from you (“Customer”, “Practitioner” or “you”) when you use our services as stated in our Terms of Use. It also describes your rights toward us and how you can exercise your rights.

PepperVault is acting as a data processor when it processes personal data on behalf of you. When PepperVault uses personal data for improvement of its own services and marketing, it is acting as a data controller. PepperVault hereby informs you of our use of your personal data in accordance with GDPR and the Swedish data protection law.

Table of contents

What data do we collect?

How do we collect your data?

How will we use your data?

What legal grounds do we have for storing your personal data?

Consent

Fulfillment, of the agreement

Legal obligations

Legitimate interest

How will we store your data?

Technical safeguards

What are your data protection rights?

What are cookies?

How do we use cookies?

What type of cookies do we use?

How to manage your cookies?

How do we respond to legal requests or prevent harm?

Privacy policies of other websites

Do we transfer personal data to others or third countries?

Changes to our privacy policy

Applicable law and jurisdiction

How to contact us

How to contact the appropriate authorities

What data do we collect?

To ensure that you have an ability to register the documentation securely and efficiently in the PepperVault, we collect the following data:

  • Content and information that you provide the app including when you sign up for an account and create content. This includes information in or about the content you provide (like metadata), such as the location of a photo or the date a file was created. That includes:

    • Your personal identification information (name, phone number, address, and e-mail)

    • Any pictures, videos, documents and sound files that you upload to the journal

    • Your usage of the app. We collect information about how you use our products and the frequency of your usage; it includes features you use, the actions you take and the content you view.

    • Location of your uploads. In an effort to prevent defamation we geotag your picture, video, documents, and sound uploads. Your location can be determined by

      • GPS and other sensor data from your device

      • IP address

      • Information about things around your device such as Wi-Fi access points and cell towers.

  • Device information. PepperVault AB collects information from your computers and phones that you use to interact with our products. This information includes:

    • Device attributes. That is, information such as the operating system, hardware and software versions, and file names and types.

    • Device signals. Information about nearby Wi-Fi access points and cell towers.

    • Device operations. That is, information about operations and behaviors performed while using the app.

    • Data from device settings. Information you allow us to receive through device settings you turn on, such as access to your GPS location, camera or photos.

    • Network and connections. Specifically, information such as the name of your mobile operator or ISP, language, time zone, mobile phone number and IP address so we can ensure that you are the one submitting the content to the app.

How do we collect your data?

You provide PepperVault App AB with the data we collect when you:

  • Download and create an account with PepperVault App AB.

  • Voluntarily create content using our “new journal entry” feature.

  • Provide feedback on our website and app.

  • Use of view our website via your browser’s cookies.

  • Engage with the app’s features.

  • Upload images, videos, documents and sound files.

How will we use your data?

We use the data you provide us with in the following ways:

  • Organize your journals chronologically to facilitate sharing, including with authorities, to recount your experiences.

  • To maintain a record of your activities within our products, allowing you the option to share it with authorities at your discretion.

  • Enable you to document your experiences with a precise timeline. For instance we gather timestamps when you create a new journal entry or make edits, enhancing the credibility of your records.

  • Improve our product. By understanding how you interact with our products we can improve our features within the app and on our website.

  • If you grant us permission to use your location when creating content, we can enhance your credibility by associating your geographical location with the experiences you share. Tracking your location serves to verify your identity, establishing a transparent link between the information you provide - such as text, videos, images, sound files, and documents - and the places you regularly visit, including your home, the homes of friends and family, your workplace, or the surrounding areas of your residence.

  • PepperVault AB does not sell your information for ad purposes or partner with for profit companies to sell services, but we do sell and use your information for research purposes in order to better improve policies and legislation surrounding domestic abuse. By anonymizing your data, we can provide governments, municipalities, social services, police, and women’s shelters (among others) with better and more accurate statistics about domestic abuse. For example, PepperVault AB can regionally provide municipalities with what type of abuse is most prevalent by using the information from our users in their area.

  • To promote safety and security. We use your information to verify accounts and activity to prevent spam and harmful conduct. For example, we use the information you provide to investigate abuse in our app and violations of our terms and conditions.

  • Research and innovate for the public good. PepperVault AB’s goal is to empower domestically abused women. At our core, we conduct and support research to combat domestic violence and improve gender equality. For example, we analyze the information our users collectively provide to uncover patterns in domestic abuse and inform governments and legislators of the need for improved policies, funding, and overall resource allocation.

What legal grounds do we have for storing your personal data?

PepperVault AB will only process data if we have a lawful basis for doing so. We adhere to a stringent policy on the processing of personal data, ensuring that such processing aligns with a lawful basis. Our privacy policy is designed in accordance with the General Data Protection Regulation (GDPR) Article 6 and the European legal framework, specifically Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

As outlined in Article 6 of the GDPR, explicit consent serves as a primary legal ground for processing personal data. By using our app and engaging with its features, you expressly provide informed consent for the collection and storage of your personal information. This consent is instrumental in facilitating the functionalities and services offered by PepperVault AB. Our commitment to compliance with the GDPR and other relevant regulations ensures a transparent and lawful basis for the processing of your personal data.

PepperVault AB may process personal data based on the following legal grounds in GDPR. 

Consent

In the event PepperVault AB foresees the need to process your personal data for a purpose which, pursuant to applicable laws and regulations, should be based on your consent (on grounds of Art. 6(1)(a) GDPR), we will contact you in advance, to inform you about the processing for which your consent is required before the consent is collected. You may withdraw your consent at any time.


Fulfillment, of the agreement

To fulfill our agreement with you (including to provide our services to you or to respond to your requests, such as a request for customer service). The legal ground for this is that the processing is necessary for the performance of an agreement or contract to which the Data subject is party or to take steps at the request of the Data subject prior to entering into an agreement or contract (Art. 6(1)(b) GDPR).

Legal obligations

To comply with legal obligations to report to authorities and third parties. The legal ground is that processing is necessary for compliance of a legal obligation to which the data processor and the data controller are subject (Art. 6(1)(c) GDPR). PepperVault may process personal data in relation to claims handling, debt collection and legal processes. We may also process personal data for the prevention of fraud, misuse of our services and for data, system and network security.

Legitimate interest

PepperVault processes your personal data primarily to pursue our legitimate interest to run, maintain and develop our organization. We may also contact you via e-mail, newsletters, or letters, in order to inform you about our services, offers and events. The legal ground for this is that the processing is necessary and that PepperVault has a legitimate interest (Art. 6(1)(f) GDPR) that is not overridden by the fundamental interests and freedoms of the Data subjects.

PepperVault is a data controller when it processes personal data for the purposes of improving the services and trend analysis. We may send you “customer satisfaction forms” that we will ask you if you would like to complete and submit to us. Wherever possible, we use aggregated, non-personally identifiable data.

How will we store your data?

In accordance with our privacy policy, PepperVault AB employs Google Firebase Cloud Storage as the chosen platform for storing user data. Google Firebase Cloud Storage is a secure and reliable cloud storage solution that adheres to industry-standard security measures.

Key points regarding how PepperVault will store user data on Google Firebase Cloud Storage:

  • Data Security: User data is stored securely on Google Firebase Cloud Storage, which employs encryption protocols to safeguard the confidentiality and integrity of the stored information.

  • Access Controls: Access to user data is strictly controlled and limited to authorized personnel who require access for legitimate purposes related to the provision of our services.

  • Compliance with Legal Standards: PepperVault AB ensures that the storage of user data on Google Firebase Cloud Storage complies with applicable data protection laws and regulations, including the General Data Protection Regulation (GDPR) and other relevant standards.

  • Data Minimization: PepperVault practices data minimization, storing only the necessary user data required for the app’s functionalities and services.

  • Purpose Limitation: User data stored on Google Firebase Cloud Storage is used solely for the specified and legitimate purposes outlined in our privacy policy.

  • Data Retention: PepperVault retains user data for the duration necessary to fulfill the purposes for which it was collected. 

  • Third Party Service Providers: PepperVault AB may engage third party service providers, such as Google Firebase Cloud Storage, that adhere to stringent security and privacy standards to ensure the safe storage of user data.

Technical safeguards

Our company securely stores your data using Google Cloud storage solutions and Firebase. Google Cloud’s infrastructure has built-in protections to ensure that your information, identity, apps, and devices are protected. Additionally, Google Cloud encrypts the data in transit between their facilities, which ensures that it can only be accessed by authorized representatives.

PepperVault AB, in accordance with GDPR, retains your data for the duration necessary to enhance and improve your journals. We follow principles of data minimization, ensuring we collect and keep information solely for its intended purpose. Once the purpose is fulfilled, and legal obligations are met, we commit to promptly deleting or anonymizing the data.

In some cases, for academic research and statistical purposes in the public interest, certain data may be retained for an extended duration, as stipulated by Article 89(1) and Article 6(1)(e) GDPR, however always in compliance with applicable laws and regulations. In such instances, all data undergo anonymization, ensuring the complete removal of any links between the data and the respective individuals.

What are your data protection rights?

PepperVault AB would like to make sure that you are fully aware of all of your data protection rights. Every user is entitled to the following:

  • The right to access: You have the right to request PepperVault AB for copies of your personal data without any costs or fees for you. Please note that we may charge you a small fee for this service in the event we receive repeated requests from you during a short period of time and if the requests may be considered unreasonable.

  • The right of rectification: You have the right to request that PepperVault AB corrects any information you believe to be inaccurate. You also have the right to request PepperVault AB to complete information you believe is incomplete.

  • The right to erasure: You have the right to request that PepperVault AB erase your personal data, under certain conditions. 

  • The right to restrict processing: You have the right to request that PepperVault AB restricts the processing of your personal data, under certain conditions. 

  • The right to object to processing: You have the right to object to PepperVault AB’s processing of your personal data, under certain conditions. 

  • The right to data portability: You have the right to request that PepperVault AB transfer the data that we have collected to another organization, or directly to you, under certain conditions.

  • The right to a withdrawal of the information collected about you and in which way the personal data is processed: You may do this by requesting a registry extract from PepperVault. If you make a request, we have a month to respond to you. If you would like to exercise any of these rights, please contact us via e-mail: privacy@peppervault.com

What are cookies?

Cookies are small pieces of text sent to your browser by a website you visit. They collect standard internet log information and visitor behavior information, which can make it easier for you to visit the site again and make the site more useful to you. We may collect information from you automatically through cookies or similar technology. We base our use of cookie files, which are not necessary but can be classified as analytical, to provide the services, on your explicit consent, cf. (Art 6(1)(a) GDPR).

We store cookie files on your computer, telephone (or other digital device which you may use to visit our digital channels) for the purpose of identifying your browser and to recognize your search history, settings and preferences. You will have the right to refuse our processing of personal data using cookie files. We use various technologies to collect and store analytics data and other information when you visit our website, including cookies, pixel tags and web beacons.

Cookies are small text files sent and saved on your device that allow us to identify visitors of our website and facilitate the use of the website and the services and to create aggregate information of our visitors. By sending the content of the cookie file back with each request to the website, the web server can keep track of the user’s identity or preferences. This helps us to improve the services and better serve our users. The cookie file can have several purposes, e.g. storing information about the users and their use of a website, user patterns, or enabling direct individualized advertising. The cookies will not harm your device or files.

A web beacon is a technology that allows for identifying readers of websites and e-mails e.g. for identifying whether an e-mail has been read.

For more information please visit https://allaboutcookies.org/

How do we use cookies?

PepperVault AB uses cookies to improve your experience on our website, including:

  • Understanding how you use our website.

  • Understanding your preferences pertaining to location and language.

What type of cookies do we use?

There are number of different cookies, however our website uses:

  • Functionality: Our company uses these cookies so we recognize you on our website and remember your previously selected preferences. This could include the language you prefer and the location you are in.

How to manage your cookies?

You can set your browser to not accept cookies. This website https://allaboutcookies.org/ walks you through how and tells you how to remove cookies from your browser. Please be mindful that our website may not function as a result.

How do we respond to legal requests or prevent harm?

PepperVault is committed to responding to legal requests in a transparent and lawful manner. In the event of a legal request, such as a search warrant, court order, or subpoena related to user accounts and content, we may access, preserve, and share information with regulators or law enforcements as required by law. 

Moreover, we take measures to prevent harm, aligning with GDPR principles. This includes addressing instances of illegal activity, preventing and addressing fraud, and mitigating the risk of harm or death.

Privacy policies of other websites

PepperVault AB’s website and app contains useful links from other websites that could be of resource to you. But note that our privacy policy applies only to our website and app, so if you click on a link to another website you should read their privacy policy.

Do we transfer personal data to others or third countries?

PepperVault may transfer personal data to third parties such as courts, authorities and opponents. PepperVault uses Google Firebase (hosting) and Gmail and Google Forms for sending e-mails.

The transfer may only take place if necessary for PepperVault to fulfill its engagement and/or to protect the interests of users. PepperVault may process personal data in order to comply with money laundering regulations. If PepperVault is involved in a merge, engages cooperation, partners, acquisition or asset sale, we may transfer your personal data to the third party involved. PepperVault shall ensure that any personal data is afforded equivalent protection as prescribed in this privacy policy and in accordance with GDPR. PepperVault may also transfer personal data to others within PepperVault’s business operation, coordinators, co-operation partners and providers, as well as third parties, including but not limited to suppliers, cloud service providers, consultants, and authorities. PepperVault shall, however, only transfer personal data if PepperVault has a legal ground under GDPR to do so and continue to ensure the confidentiality of all personal data.

PepperVault may also transfer personal data to a third country, i.e., a country outside the EU/EEA,, or to an international organization according to applicable laws and data regulations. Third parties may be based anywhere in the world, which could include countries that may not offer the same legal protections for personal data as the Data subject’s country of residence. PepperVault will follow local data protection requirements and its internal global privacy standards and PepperVault will apply the necessary safeguards under the applicable law of the country transferring the personal data for such transfers. You are encouraged to get further information about the legal aspects of third-party transfers: www.imy.se.
More information regarding the transfers of personal data may be obtained by contacting us on any of the addresses indicated below.

Changes to our privacy policy

PepperVault AB keeps its privacy policy under regular review and places updates on our website and in our app. This privacy policy was last updated on January 18, 2024.

Applicable law and jurisdiction

Swedish law shall be applicable and the Swedish courts shall have jurisdiction subject always to mandatory laws and regulations of users in the country concerned.

How to contact us

If you have any questions or concerns about PepperVault AB, our privacy policy, the data we collect and store, or if you would like to exercise one or more of your data protection rights, please feel free to e-mail us at privacy@peppervault.com Full contact details:
PepperVault AB company registration number: 559416-3726,
Registered postal address: Helgögatan 21, 802 55 Gävle, Sweden

How to contact the appropriate authorities

If you would like to report a complaint or if you feel that PepperVault AB have not addressed your concern in a satisfactory manner, you may e-mail Integritetsskyddsmyndigheten in Sweden (IMY); imy@imy.se