Privacy Policy
What we collect, why, who ever sees it, and how you stay in control. Written to be read — if anything is unclear, ask us.
1. Who we are and what this covers
The data controller is SMARCH Ideell Förening, Org.nr: 802556-6095, a Swedish nonprofit association registered in Stockholm, Sweden ("we", "us", "our").
This policy explains how we handle your personal data when you visit https://smarch.se, create an account, submit an application, or take part in team matching and the team programme.
Key points:
- Legal basis: we process your data to run the service you signed up for — based on legitimate interest in operating a participant-centred team matching platform and, where applicable, your explicit consent.
- Scope: this policy follows the GDPR and primarily serves people in Sweden and the wider EU/EEA.
- We never sell personal data. Smarch is a nonprofit — your data is not a revenue stream, and it never will be.
2. What we collect
2.1 About you
- Full name and email address
- Phone number (optional)
- Date of birth — you must be at least 18
- General location in Sweden
2.2 Your application
Your survey answers are the application — there is no CV upload and no cover letter. The survey covers:
- Skills, experience and education
- Work eligibility status — for example, the legal right to work in Sweden
- Goals, ways of working and team preferences
- Availability and commitment
- Optional portfolio links
2.3 Your profile
- Profile image (optional — stored on AWS S3 in the EU)
- Account settings and preferences
2.4 Technical data
- IP address, browser and device information, access times
- Usage data collected through internal tools only — no third-party analytics
2.5 Programme records
- Your Smarch case number, matching status and history
- Messages and communication within the platform
3. How we use it
- Running your application: managing your account, your survey, and your place in the queue — which is ordered by how long people have been searching, so the wait is fair.
- Matching: forming complementary teams based on skills, motivation and ways of working. When you are matched, relevant profile information is shared with your teammates so collaboration can start.
- Supporting teams: running the programme — deliverables, meetings, feedback and staff support.
- Communication: service emails about your application, your team and the platform. These are transactional, not marketing.
- Improving the programme: internal analysis of how the platform is used. Internal tools only.
- Safety and legal: keeping the platform secure, preventing fraud and misuse, and meeting our legal obligations.
4. AI-assisted analysis
We use AI tools — Anthropic's Claude — to analyse survey responses and support matching quality. What this means in practice:
- Only anonymised survey answers and case numbers are analysed. Names, emails and phone numbers are never shared with AI providers.
- Matching decisions are made by people. AI supports the analysis; our staff review and decide.
- This processing involves data transfer to the United States, under the safeguards described in Section 6.
- You consent to this processing when you submit your survey responses.
6. International transfers
Your data primarily stays in the EU/EEA — hosting, database and image storage all run in EU regions. Two exceptions involve transfer outside the EU/EEA:
- United States: AI analysis (Anthropic) — anonymised data only — and some processing by our email provider.
For these transfers we rely on Standard Contractual Clauses approved by the European Commission, provider-level data protection measures, and minimisation — as little personal data as possible crosses any border.
7. How long we keep it
7.1 While you are active
- During your application: until your case is resolved — matched, or closed.
- While you are in the queue, in team formation, or collaborating in a team.
7.2 If you delete your account
Your survey responses and answers are deleted — this is your right to erasure, and we honour it. We keep one minimal administrative record: your name, email, application status, completion percentage and key dates. This keeps our statistics honest and lets us recognise returning accounts. Nothing from your actual answers is kept.
7.3 Inactive accounts
- Accounts inactive for 3 years are flagged for review.
- We contact you before anything is deleted — you can reactivate or request immediate deletion.
8. Security
- Encryption in transit (SSL/TLS) and at rest — database and file storage.
- Access controls: personal data is available to staff on a need-to-know basis only.
- Regular security updates, secure cloud infrastructure, and incident response procedures.
If a breach affects your personal data, we notify you and the supervisory authority within 72 hours, as the GDPR requires.
10. Your rights
Under the GDPR you have the right to:
- Access — request a copy of your personal data.
- Rectification — correct inaccurate or incomplete data.
- Erasure — have your personal data deleted ("right to be forgotten").
- Restriction — limit processing in certain circumstances.
- Portability — receive your data in a machine-readable format.
- Objection — object to processing based on legitimate interest.
- Withdraw consent — for any consent-based processing, at any time.
- Complain — lodge a complaint with a data protection authority.
Exercising your rights is free and simple: use the contact form and mention "data protection inquiry". We respond within 30 days.
Supervisory authority: in Sweden, Integritetsskyddsmyndigheten (IMY) — www.imy.se. You can also contact the data protection authority in your own EU/EEA country.
11. Changes to this policy
If this policy changes, we post the update here with a new "Last updated" date. Significant changes are announced by email or a notice on the website before they take effect.
12. Contact
Questions, concerns, or a rights request? We answer them.
SMARCH Ideell Förening
Org.nr: 802556-6095
Registered seat: Stockholm, Sweden