← Back to login

Privacy Policy

Last updated: September 14, 2026

DRAFT — not yet reviewed by a lawyer. This describes what the application actually does with data today, but must be reviewed by qualified legal counsel before being relied on or shown to real customers.

This Privacy Policy explains how Fire Life Safety Inspections ("we," "us," "our") collects, uses, and protects your personal data when you use our Service at firelifesafetyinspections.se, in accordance with the EU General Data Protection Regulation (GDPR).

1. Who we are (data controller)

Fire Life Safety AB, a Swedish limited company (aktiebolag) founded by Mike Wahren, operating Fire Life Safety Inspections, is the data controller responsible for your personal data. Contact: [YOUR EMAIL]. Organisationsnummer: [ORG NUMMER].

2. What data we collect

  • Account data: name, email address, and password (stored hashed, never in plain text).
  • Inspection data: site/building information, device details, photos you upload, voice notes and their transcriptions, and inspection status notes you enter.
  • Generated content: AI-generated inspection reports produced from the above.
  • Technical data: basic usage data (e.g. login timestamps, error logs) needed to operate and maintain the Service securely.

We do not knowingly collect special categories of personal data (e.g. health data) unless it is incidentally present in an inspection photo — please avoid including people's faces or personal identifying information in inspection photos where not necessary.

3. Why we process your data (legal basis)

PurposeLegal basis (GDPR Art. 6)
Providing your account and the ServicePerformance of a contract
Generating AI report drafts from your field dataPerformance of a contract
Improving and maintaining the ServiceLegitimate interest
Sending service-related emails (e.g. password resets)Performance of a contract
Complying with legal obligationsLegal obligation

4. Who we share data with (processors)

We use the following third-party service providers ("processors") to operate the Service. They process data on our behalf and do not use your data for their own purposes.

  • Anthropic (Claude API) — processes your field data (device types, locations, conditions, and notes — not raw audio, since voice notes are transcribed to text in your browser before saving) to generate draft inspection reports. Anthropic is based in the United States, so this involves a transfer of personal data outside the EU/EEA; such transfers rely on appropriate safeguards, including Standard Contractual Clauses.
  • Resend — sends transactional emails on our behalf (password resets, inspection due/overdue reminders). Your email address and the relevant message content (e.g. a site name and due date) pass through Resend to deliver these emails.
  • [YOUR HOSTING PROVIDER — e.g. Vercel/Railway] — hosts the Service and stores your data on our behalf. [PLACEHOLDER: fill in once deployed.]

We do not sell your personal data to third parties, and we do not use your data for advertising purposes.

5. Cookies

We use a small number of cookies, all strictly necessary to operate the Service (no advertising or tracking cookies, and no cookie-consent banner is needed for these under GDPR/ePrivacy since they're functionally required):

  • session — keeps you signed in.
  • pending_2fa — set only mid-login, for accounts with two-factor authentication enabled, until the code is verified.
  • locale — remembers your chosen display language (English/Swedish).

6. How long we keep your data

We retain your account and inspection data for as long as your account is active, so you can access your inspection history. If you delete your account (via Settings › Privacy & data), your account record and all associated sites, devices, inspections, reports, and photos are deleted immediately and permanently — not a soft delete, and not on a delay — except where we are legally required to retain data longer (e.g. for tax or compliance record-keeping purposes).

7. Your rights under GDPR

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data.
  • Delete your data ("right to be forgotten"), subject to legal retention requirements.
  • Restrict or object to certain processing.
  • Data portability — receive your data in a structured, machine-readable format.
  • Withdraw consent at any time, where processing is based on consent.
  • Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, if you believe your data has been mishandled.

Access, deletion, and data portability are available immediately, self-service, from Settings › Privacy & data — no request or waiting period needed. For any other rights above, or questions, contact us at [YOUR EMAIL].

8. Automated decision-making

AI-generated report drafts (device findings, compliance status suggestions, recommended actions) are produced automatically, but they are never a final, unreviewed decision: the Service explicitly marks every draft as a SAMPLE and requires a qualified, licensed inspector to review and confirm it before it is issued to a client or relied on as an official compliance record (see Terms of Service, Section 3). We do not use automated processing to make decisions about you (e.g. your account status) that produce legal or similarly significant effects without human involvement.

9. Data breach notification

If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority (Integritetsskyddsmyndigheten, IMY) without undue delay, and within 72 hours of becoming aware of it where feasible, as required by GDPR. Where a breach is likely to result in a high risk to you specifically, we will also notify you directly without undue delay.

10. Security

We take reasonable technical and organizational measures to protect your data, including encrypted connections (SSL/TLS) and access controls. However, no system is completely secure, and we cannot guarantee absolute security.

11. Photos and third-party data

Inspection photos may incidentally contain images of property, equipment, or people at inspected sites. You are responsible for ensuring you have the appropriate authority or permission to capture and upload such photos as part of your inspection work.

12. Children's privacy

The Service is intended for professional use by adults (fire safety inspectors and related professionals). We do not knowingly collect data from individuals under 18.

13. Changes to this Policy

We may update this Privacy Policy from time to time. We will update the "Last updated" date above and notify you of material changes where appropriate.

14. Contact us

For any privacy questions or to exercise your GDPR rights, contact us at [YOUR EMAIL].