Privacy Notice
Done.ai Group AB and subsidiaries · Version 1.1 · Last updated: August 2026
1. Who We Are
Done.ai Group AB (org. no. 559120-8870, Sweden) is a Swedish-listed fintech holding company with subsidiaries across Sweden, Norway, Denmark, and the United States. References to “Done.ai,” “we,” “us,” or “our” in this notice refer to the Done.ai Group entity that acts as data controller for your personal data. The relevant controller entity depends on which service or product you are using and is identified in the Contact section at the end of this notice.
This notice serves as the group-level Privacy Notice for Done.ai Group AB and all its subsidiaries. Individual subsidiaries may publish supplementary privacy notices for their specific services, which should be read together with this notice. Where a supplementary notice conflicts with this notice, the supplementary notice prevails in relation to the specific service it covers.
2. Scope of This Notice
This Privacy Notice applies to personal data we process about:
- visitors to our websites and digital platforms;
- current, prospective, and former customers and their authorised representatives;
- business contacts, partners, and suppliers;
- job applicants; and
- any other individuals whose personal data we handle in the course of our operations.
This notice does not cover information relating solely to legal entities, unless that information also relates to an identifiable natural person (for example, a sole trader or a named company representative).
3. Personal Data We Collect
Depending on your relationship with us, we may collect and process the following categories of personal data:
Identity and contact information
- Name, title, and job title;
- Email address, phone number, and postal address;
- User credentials (username, password, authentication tokens) for our platforms.
Relationship and transaction information
- Service agreements, order details, billing and invoicing records;
- Payment history and transaction data;
- Service usage records, logs, and helpdesk interactions.
Regulatory and compliance information
- Know-your-customer (KYC) and anti-money laundering (AML) data, including identity documents, information on ultimate beneficial owners and politically exposed persons (PEPs), and sanctions screening results;
- Regulatory filings or correspondence that include personal data.
Website and technical data
- IP address, browser type and version, operating system;
- Pages visited, referral URL, date and time of access;
- Cookie identifiers and device identifiers (see Section 9).
Marketing and communication data
- Marketing preferences and opt-in/opt-out records;
- Records of correspondence and interactions with us;
- Survey responses or event participation records.
Recruitment data
- CV or resume, cover letter, work history, and qualifications;
- References and assessment results;
- Information provided during the recruitment process.
We do not, as a rule, process special categories of personal data (such as health information, racial or ethnic origin, or political opinions). Where such processing is required in a specific context, we will provide a separate disclosure and obtain any necessary explicit consent.
4. How We Collect Personal Data
We collect personal data from the following sources:
- Directly from you — when you contact us, create an account, enter into a contract, apply for a role, or use our services;
- Automatically — when you visit our websites or use our platforms, through server logs, cookies, and similar technologies;
- From third parties — including publicly available business registers (such as the Norwegian Brønnøysund registers, the Swedish Bolagsverket, or the Danish CVR register), commercial business information providers, and sanctions databases;
- From other Done.ai Group companies — for internal administration and joint service delivery purposes.
5. Purposes and Legal Bases for Processing
We process personal data only where we have a valid legal basis under Article 6 of the GDPR and, where applicable, the Norwegian Personal Data Act (personopplysningsloven), the Swedish Data Protection Act (dataskyddslag 2018:218), and the Danish Data Protection Act (databeskyttelsesloven). The table below sets out our main processing activities and the applicable legal basis.
| Purpose | Examples | Legal Basis (GDPR Art. 6) |
|---|---|---|
| Contract performance | Onboarding customers, delivering services, billing | Art. 6(1)(b) — necessary for the performance of a contract |
| Legal and regulatory compliance | AML/KYC, tax reporting, sanctions screening, regulatory filings | Art. 6(1)(c) — compliance with a legal obligation |
| Legitimate interests | IT security, fraud prevention, business administration, internal reporting, direct marketing to B2B contacts, legal claims | Art. 6(1)(f) — legitimate interests pursued by us or a third party |
| Consent | Non-essential cookies, electronic marketing to consumers, specific contexts requiring consent | Art. 6(1)(a) — your freely given, specific, informed consent (withdrawable at any time) |
| Public task or vital interests | Responding to competent authority requests, protecting vital interests | Art. 6(1)(d)/(e) — where applicable |
Where we rely on legitimate interests, we have assessed that our interests are not overridden by your rights and freedoms. You may request a copy of that assessment. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing that took place before withdrawal.
6. Sharing Personal Data
We share personal data only to the extent necessary and permitted by applicable law. Where two or more Done.ai Group entities jointly determine the purposes and means of processing, they act as joint controllers in accordance with Article 26 GDPR. The essence of any such arrangement is available upon request. Recipients may include:
- Other Done.ai Group entities, for internal administrative, operational, and reporting purposes;
- Third-party service providers acting as data processors on our behalf, such as cloud infrastructure providers, IT vendors, analytics providers, and payment processors — these parties process data solely on our documented instructions;
- Regulated financial institutions and product partners involved in service delivery;
- Professional advisers including lawyers, auditors, and accountants;
- Competent authorities, regulators, and law enforcement where required by law or valid legal process;
- Purchasers or successors in the event of a merger, acquisition, or sale of all or part of our business.
We do not sell personal data to third parties. An up-to-date list of our sub-processors is available in our Sub-processors overview.
7. International Transfers
Personal data is primarily processed within the EU/EEA. Where we transfer personal data to countries outside the EU/EEA — for example, because a service provider or group entity is located there — we ensure that appropriate safeguards are in place. These safeguards include:
- transfer to countries that the European Commission has recognized as providing an adequate level of data protection;
- use of the European Commission’s Standard Contractual Clauses (SCCs); or
- other valid transfer mechanisms under Chapter V of the GDPR.
Where transfers occur to countries without an adequacy decision, we apply SCCs together with supplementary technical and organizational measures where necessary. You may request further information about the specific transfer mechanisms we use by contacting us.
8. Your Rights
Under the GDPR and applicable national data protection legislation, you have the following rights in relation to your personal data:
- Right of access — to confirm whether we process your personal data and to receive a copy;
- Right to rectification — to have inaccurate or incomplete data corrected;
- Right to erasure — to request deletion where there is no valid ground for continued processing;
- Right to restriction — to request that we limit processing in certain circumstances;
- Right to data portability — to receive personal data you have provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract;
- Right to object — to object to processing based on legitimate interests, or to object to direct marketing at any time (the latter is an absolute right);
- Right to withdraw consent — at any time, without affecting the lawfulness of prior processing;
- Rights regarding automated decision-making — we do not make decisions about you based solely on automated processing that produce legal or similarly significant effects, unless required by law and subject to appropriate safeguards.
To exercise any of these rights, please use the contact details at the end of this Privacy Notice. We may need to verify your identity before responding. We will respond within one month of receipt of your request, extendable by a further two months for complex or numerous requests, with prior notice.
If you consider that we are processing your personal data unlawfully, you have the right to lodge a complaint with the relevant supervisory authority:
- Norway: Datatilsynet (www.datatilsynet.no)
- Sweden: Integritetsskyddsmyndigheten / IMY (www.imy.se)
- Denmark: Datatilsynet (www.datatilsynet.dk)
- Or the supervisory authority in your country of residence or place of work.
9. Cookies and Website Tracking
Our websites use cookies and similar tracking technologies. Cookies are small text files placed on your device that help us operate the site, understand how it is used, and — with your consent — deliver personalized content and targeted marketing.
We use the following categories of cookies:
- Strictly necessary cookies — essential for the website to function; no consent is required;
- Functional cookies — enhance usability and personalisation; enabled on the basis of legitimate interest or consent;
- Analytics cookies — help us understand visitor behaviour; enabled only with your consent;
- Marketing and advertising cookies — used to deliver relevant advertising across sites; enabled only with your explicit consent.
You can manage your cookie preferences at any time via the cookie consent panel on our website or through your browser settings. Withdrawing consent for non-essential cookies will not prevent you from using the site’s core functionality. Some third-party cookies (for example, from embedded video or social media services) may involve transfers of data outside the EU/EEA. For more detail, see our Cookie Policy.
Marketing emails we send may include tracking pixels or similar technologies that indicate whether an email was opened and which links were clicked. You can opt out of marketing communications at any time by using the unsubscribe link in the message or by contacting us directly.
10. Retention
We retain personal data only for as long as necessary for the purposes for which it was collected, and in accordance with applicable legal, regulatory, accounting, and contractual requirements. Key principles are:
- Data processed in connection with a contractual relationship is generally retained for the duration of that relationship and for a further period corresponding to the applicable statutory limitation period (typically three to ten years, depending on the jurisdiction and nature of the potential claim);
- AML/KYC records are retained for a minimum of five years after the end of the business relationship, as required under Norwegian hvitvaskingsloven, Danish hvidvaskingsloven, and applicable EU AML directives;
- Data processed on the basis of consent is retained until consent is withdrawn, subject to any overriding legal obligation to retain;
- Website and server log data is typically retained for up to 12 months;
- Recruitment data for unsuccessful applicants is deleted within six months of the close of the recruitment process, unless you have consented to retention for future openings.
Specific retention schedules are maintained internally. You may request further information about the retention period applicable to your personal data by contacting us.
11. Information Security
We implement technical and organizational measures appropriate to the risk, in order to protect personal data against unauthorized access, accidental loss, destruction, alteration, or disclosure. The nature and scope of these measures are reviewed and updated on a regular basis in line with applicable requirements under GDPR Article 32.
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, affected individuals, in accordance with GDPR Articles 33 and 34.
12. AI Processing
Done.ai uses artificial intelligence and machine learning technologies in its products and internal processes. Where personal data is used in AI-based processing, we apply appropriate safeguards, including pseudonymization where direct identification of individuals is not necessary for the processing purpose. We do not use personal data to train AI models in a manner incompatible with the original purpose of collection. Individuals are informed when they are interacting with an AI system in a context where that is not self-evident.
13. Changes to This Notice
We may update this Privacy Notice from time to time to reflect changes in our processing activities, applicable law, or business operations. The current version is always available on our website. Where changes are material, we will notify affected individuals by an appropriate means (such as email notification or a prominent website notice) before the changes take effect.
14. Contact
For questions about this Privacy Notice, to exercise your data subject rights, or to raise a concern about how we handle your personal data, please contact us at:
Done.ai Group AB
Attn: Chief Compliance Officer / Data Protection
Email: privacy@done.ai
Website: www.done.ai
This notice was last reviewed and approved: August 2026.