Skip to content
CleanDesignGroup

Home  /  Privacy policy

Privacy policy.

How we handle personal information at CleanDesignGroup AB, plain language version. Last reviewed: April 2026. Applies to all visitors and clients worldwide.

1. Who we are

CleanDesignGroup AB is the legal entity that operates the CleanDesignGroup studio and the cleandesigngroup.com website. We are registered in Sweden, organisation number SE556987432101, with our office at Oslogatan 15, 164 31 Kista, Sweden. For all privacy and data protection inquiries, please write to help@cleandesigngroup.com. We are the data controller for the personal information described below.

2. What this policy covers

This policy describes how we collect, use, store, and share personal information when you visit cleandesigngroup.com, submit a brief through the contact form, complete a checkout, or otherwise interact with our studio. It applies to information that identifies you personally, such as your name, email address, phone number, and the contents of the brief you submit.

3. Information we collect

Information you give us. When you submit a brief through the contact form, we collect the name, email address, phone number, company, country, indicative budget, and message contents you provide. When you proceed to checkout, we additionally collect the country and any address information required for invoicing. When you commission an engagement, we collect the information needed for the engagement letter and the project itself.

Information collected automatically. When you visit cleandesigngroup.com we record standard server-log information — IP address, browser type, referring page, and pages visited — for security monitoring and aggregate analytics. We use a small set of cookies described in our cookie policy, including an optional analytics cookie that records page-view information in an aggregated form.

Information from third parties. When you complete a payment, Stripe — our payment processor — collects card details, billing address, and other information necessary to process the transaction. We never see or store full card numbers; Stripe sends us a confirmation of payment and a payment token used for refunds and reconciliation.

4. How we use your information

We use the personal information you provide to respond to your brief, to prepare and deliver an engagement letter, to deliver the design work you commission, to issue and reconcile invoices, and to communicate with you about active projects. We use server-log information for security monitoring, troubleshooting, and aggregate analytics. We do not use your personal information for behavioural advertising, profiling, or automated decision-making. We do not sell your personal information to anyone.

5. Legal basis for processing (GDPR)

If you are based in the European Union, the United Kingdom, or another jurisdiction with GDPR-equivalent law, we rely on the following legal bases for processing your personal information. We process information you submit through the contact form on the basis of your consent and our legitimate interest in responding to inbound business inquiries. We process information for active engagements on the basis of contractual necessity. We process invoice and payment information on the basis of our legal obligations under Swedish tax law. We process server-log information on the basis of our legitimate interest in operating a secure website.

6. Who we share information with

We share personal information only with the parties necessary to operate the studio and deliver the engagements we are contracted for. Our payment processor is Stripe, Inc. (United States, with European subsidiaries), who processes card details on our behalf. Our email is hosted by Fastmail Pty Ltd. (Australia, with European servers). Our website is hosted on infrastructure within the European Union. Our cloud file storage is provided by a single European provider, contracted under a standard data processing agreement. We do not share personal information with marketing platforms, advertising networks, or analytics aggregators beyond the limited cookies described in our cookie policy.

7. International transfers

Most of our service providers store and process information within the European Economic Area. Where information is transferred outside the EEA — most notably to Stripe in the United States — we rely on the European Commission’s Standard Contractual Clauses and, where applicable, supplementary measures, to ensure your information is protected to an equivalent standard.

8. How long we keep information

We retain inbound brief submissions for 24 months, after which they are deleted unless they have led to an active engagement. We retain engagement records (engagement letters, project files, correspondence) for 7 years to comply with Swedish bookkeeping requirements. We retain server logs for 90 days. We retain invoicing and payment records for 7 years to comply with Swedish tax law. If you ask us to delete your information earlier, we will do so unless we are legally required to retain it.

9. Your rights

If you are based in the European Union, the United Kingdom, or another GDPR-equivalent jurisdiction, you have the right to access the personal information we hold about you; to ask us to correct inaccurate information; to ask us to delete information we no longer need; to ask us to restrict or object to certain kinds of processing; to ask for your information in a portable format; and to withdraw consent for any processing you previously consented to. To exercise any of these rights, write to help@cleandesigngroup.com. We will respond within thirty days. If you are unhappy with our response, you have the right to complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) or your local equivalent.

10. Security

We protect your information with appropriate technical and organisational measures: encrypted transport for all web traffic and email, access controls on our cloud storage, encrypted backups, regular security review of our hosting infrastructure, and a documented data-breach response plan. No system is perfectly secure, but we take reasonable precautions and we will notify affected individuals and the relevant authority within seventy-two hours of becoming aware of any breach involving personal information.

11. Children

Our services are intended for businesses and professional clients. We do not knowingly collect personal information from individuals under sixteen years of age. If you believe we have inadvertently collected information from a minor, please write to us and we will delete it.

12. Changes to this policy

We may update this privacy policy occasionally to reflect changes in our practice, the law, or our service providers. Material changes will be notified at the top of this page; we will record the last-reviewed date with each revision. For substantial changes affecting active clients, we will additionally write to you directly by email.

13. Contact

For any question or concern about how we handle your personal information, please write to help@cleandesigngroup.com or by post to CleanDesignGroup AB, Oslogatan 15, 164 31 Kista, Sweden.