Privacy Policy
Privacy Policy
Last updated 10 September 2026
Last updated 10 September 2026
Controller and contact
Papinian is the controller for the processing described here. Questions about personal data and requests to exercise rights may be sent to contact@papinian.se. Full legal-entity details and a dedicated privacy contact still require owner approval before public launch.
Contact form
When you submit the form, we process your name, email address, optional telephone number, client type, enquiry area, message, language and technical information needed for secure delivery. We use this to receive, assess and answer your enquiry. The form has no document-upload function. Do not include sensitive personal data, legal documents or complete identity numbers in the message.
Legal basis
Depending on the context, processing is based on Papinian's legitimate interest in handling incoming communications or on steps taken at your request before a possible contract. Sending an enquiry does not mean that an engagement has been accepted.
Microsoft 365 and email delivery
The form sends the information server-to-server through Microsoft Graph to a Microsoft 365 mailbox used by Papinian. The message may be stored in the sender mailbox's Sent Items and the recipient mailbox. Microsoft then processes data as a processor under the applicable agreements. Processing or access outside the EU/EEA may occur and must be covered by applicable safeguards.
Microsoft Bookings
The booking button is an external link; Microsoft Bookings is not embedded on Papinian's website. After you follow the link, Microsoft Bookings and Exchange process information you provide, such as contact details, selected time and booking information. Microsoft's own terms and privacy information apply within the booking service.
Server logs and abuse prevention
The hosting provider may create ordinary server logs containing items such as IP address, time, requested resource and technical browser information for operations and security. The contact form rate limiter keeps a salted hash of the network identifier in server memory. It is used only to limit abuse and expires with the rate-limit window or a process restart; the form does not store the raw address in its own database.
Retention and deletion
Personal data is kept only as long as needed to handle the contact, meet legal duties and, where necessary, establish or defend legal claims. Messages in Microsoft 365 follow Papinian's approved email and matter-management routines. No fixed deletion period has yet been approved; the owner must approve a documented schedule before public activation.
Your rights
Under the GDPR, where the conditions apply, you may request access, correction, deletion, restriction or portability and object to processing based on legitimate interests. You may also complain to the Swedish Authority for Privacy Protection. Rights are not absolute, and Papinian may need to verify a request.