C5 HOUSE AB

Privacy Policy

Last updated: March 2026

1. Introduction

C5 House AB ("C5 House", "we", "us", or "our"), corporate registration number 559574-7204, registered in Malmö, Sweden, is committed to protecting your personal data. This Privacy Policy explains how we collect, use, share, and protect personal data when you visit our website, use our services, communicate with us, or otherwise interact with us.

C5 House AB is the data controller responsible for the processing of your personal data as described in this policy, and we process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable Swedish data protection legislation.

2. Contact Details

If you have questions about this Privacy Policy or our processing of your personal data, you can contact us at:

Email: info@c5house.com

3. Personal Data We Collect

Depending on how you interact with us, we may collect the following categories of personal data:

Data you provide to us directly, such as your name, email address, phone number, postal address, company name and role, and the content of any messages you send us (for example through contact forms, email, or phone).

Data collected when you use our services, such as account details, order and transaction history, invoicing and payment information, and correspondence relating to the services we provide to you.

Data collected automatically when you visit our website, such as IP address, browser type and version, device information, pages visited, time and date of visits, and other usage data collected through cookies and similar technologies (see Section 9).

Data from third parties, such as publicly available business registers, credit reference agencies (where relevant for business transactions), or business partners, where permitted by law.

We do not intentionally collect special categories of personal data (such as health data or data revealing political opinions) and ask that you do not send us such data unless it is necessary and you have a lawful reason to do so.

4. Purposes and Legal Bases for Processing

We process your personal data for the following purposes and on the following legal bases:

To provide and administer our services and fulfil agreements with you. This includes managing accounts, processing orders, invoicing, and providing customer support. Legal basis: performance of a contract (Article 6(1)(b) GDPR), or our legitimate interest where you represent a corporate customer.

To communicate with you. This includes responding to enquiries and providing information you have requested. Legal basis: our legitimate interest in responding to and managing communications (Article 6(1)(f) GDPR), or steps taken at your request prior to entering into a contract.

To comply with legal obligations. This includes bookkeeping and accounting obligations under the Swedish Accounting Act (Bokföringslagen) and tax legislation. Legal basis: compliance with a legal obligation (Article 6(1)(c) GDPR).

For marketing purposes. This includes sending newsletters and information about our services, where permitted. Legal basis: your consent (Article 6(1)(a) GDPR) or our legitimate interest in marketing to existing customers. You can opt out of marketing communications at any time.

To improve our website and services. This includes analysing how our website is used. Legal basis: our legitimate interest in improving our offering, or your consent where required for non-essential cookies.

To establish, exercise, or defend legal claims. Legal basis: our legitimate interest in protecting our legal rights (Article 6(1)(f) GDPR).

Where we rely on legitimate interest, we have assessed that our interest is not overridden by your interests or fundamental rights and freedoms. You may contact us for more information about these assessments.

5. How We Share Your Personal Data

We do not sell your personal data. We may share personal data with:

Service providers (data processors) who process data on our behalf, such as IT and hosting providers, email and communication tools, payment providers, and accounting services. These providers may only process your data in accordance with our instructions and are bound by data processing agreements.

Professional advisers, such as auditors, lawyers, and insurers, where necessary.

Public authorities, such as the Swedish Tax Agency or law enforcement, where we are required to do so by law.

Business partners, where necessary to deliver services you have requested and where we have a lawful basis to do so.

6. Transfers Outside the EU/EEA

We primarily process personal data within the EU/EEA. If personal data is transferred to a country outside the EU/EEA (for example, because a service provider or its subprocessors are located there), we ensure an adequate level of protection through an adequacy decision by the European Commission, the European Commission's Standard Contractual Clauses together with supplementary measures where needed, or another valid transfer mechanism under Chapter V of the GDPR. You may contact us to obtain more information about such transfers and the safeguards applied.

7. Retention of Personal Data

We retain personal data only for as long as necessary for the purposes for which it was collected, or as required by law. As a general guide: accounting records are retained for seven years in accordance with the Swedish Accounting Act; data relating to agreements is retained for the duration of the agreement and thereafter as long as necessary to handle potential claims; enquiries from non-customers are retained only as long as needed to handle the matter; and marketing data is retained until you withdraw consent or object. When personal data is no longer needed, it is deleted or anonymized.

8. Your Rights

Under the GDPR, you have the following rights regarding your personal data:

Right of access – to obtain confirmation of whether we process your personal data and to receive a copy of it.

Right to rectification – to have inaccurate personal data corrected and incomplete data completed.

Right to erasure – to have your personal data deleted in certain circumstances, for example where the data is no longer necessary for the purposes for which it was collected.

Right to restriction of processing – to request that we limit the processing of your data in certain circumstances.

Right to data portability – to receive personal data you have provided to us in a structured, commonly used, machine-readable format, where processing is based on consent or contract and carried out by automated means.

Right to object – to object to processing based on legitimate interest, including profiling, and to object at any time to processing for direct marketing purposes.

Right to withdraw consent – where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of processing prior to withdrawal.

To exercise your rights, contact us using the details in Section 2. We will respond without undue delay and at the latest within one month, which may be extended by two further months where necessary given the complexity or number of requests.

If you believe our processing of your personal data infringes data protection law, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se, or with the supervisory authority in the EU/EEA country where you live or work.

9. Cookies and Similar Technologies

Our website uses cookies and similar technologies. Essential cookies are used to make the website function properly, while analytics and marketing cookies are only used with your consent. You can manage your cookie preferences through the cookie banner on our website or your browser settings. For more information, please see our separate Cookie Policy at Cookie Policy.

10. Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized access, loss, alteration, or destruction, taking into account the nature of the data and the risks involved. These measures include access controls, encryption where appropriate, and staff confidentiality obligations. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify IMY and, where required, affected individuals in accordance with the GDPR.

11. Automated Decision-Making

We do not make decisions based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you.

12. Third-Party Links

Our website may contain links to third-party websites. This Privacy Policy does not apply to those websites, and we are not responsible for their processing of personal data. We encourage you to review the privacy policies of any third-party sites you visit.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time, for example to reflect changes in our processing activities or legal requirements. The latest version will always be available on our website, and the date of the most recent update is shown at the top of this policy. In the event of material changes, we will inform you in an appropriate manner, for example by email or a notice on our website.