Privacy

Privacy Policy

This policy explains how Amare Supply Chain Consulting AB processes personal data when you visit this website, contact us, or engage us for consulting services.

Last updated: 22 August 2026

1. Data controller

Amare Supply Chain Consulting AB (organisation number 559597-4709), with its registered office in Stockholm, Sweden, is the data controller for the processing described in this policy.

Privacy enquiries and requests can be sent to abel@ascc.se.

2. Personal data we process

  • Contact details, such as your name, email address, company, and role.
  • Information you include in a contact-form message, email, request for proposal, or other correspondence.
  • Information needed to manage a client or supplier relationship, including contracts, project records, invoices, and payment information.
  • Limited technical information produced when the website is accessed, such as IP address, browser information, timestamps, and security logs.

Please do not submit sensitive personal data through the contact form unless it is strictly necessary and specifically requested.

3. Why we use personal data and our legal bases

Responding to enquiries

We use your contact details and message to respond, assess your request, and communicate with you. The legal basis is our legitimate interest in handling business enquiries. Where your request concerns a possible agreement, processing may also be necessary to take steps before entering into a contract.

Providing and administering services

We process client and project information to enter into and perform contracts, deliver consulting services, manage relationships, and administer payment.

Legal and accounting obligations

We retain records where necessary to comply with Swedish accounting, tax, and other legal obligations.

Website operation and security

Limited technical data may be processed based on our legitimate interest in operating, securing, troubleshooting, and protecting the website and its users.

4. How long we keep data

  • General enquiries that do not lead to an engagement are normally deleted within 12 months after the matter is closed.
  • Client and project records are retained for the duration of the relationship and afterwards only as long as needed for follow-up, legal claims, or another stated purpose.
  • Accounting records and supporting documentation are retained for seven years after the end of the relevant calendar year, as required by Swedish law.
  • Technical security logs are retained only for the period needed for security and troubleshooting, subject to the hosting provider's applicable retention settings.

Data may be retained longer where required by law or necessary to establish, exercise, or defend legal claims.

5. Who receives personal data

Access is limited to people who need the information. We may use service providers for website hosting, email, IT support, document storage, accounting, or professional advice. Providers that process personal data on our behalf must follow our instructions, protect the data, and be covered by appropriate contractual obligations.

We may also disclose information where required by law, a court, or a competent public authority.

6. International transfers

We aim to use processing within the EU/EEA. If a provider processes personal data outside the EU/EEA, the transfer must rely on a lawful safeguard, such as an adequacy decision or the European Commission's standard contractual clauses, together with additional protections where required.

7. Your rights

Depending on the circumstances, you may have the right to:

  • request access to your personal data;
  • have inaccurate or incomplete data corrected;
  • request erasure or restriction of processing;
  • object to processing based on legitimate interests;
  • receive data you provided in a portable format where applicable; and
  • withdraw consent where processing is based on consent.

Send requests to abel@ascc.se. We may need to verify your identity. Requests are normally handled within one month, subject to the extensions permitted by the GDPR.

8. Complaints

You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). Information and contact details are available at imy.se.

9. Automated decisions and marketing

We do not use contact-form data for automated decision-making or profiling. We do not currently use it for email marketing.

10. Changes to this policy

We may update this policy when our services, suppliers, or legal obligations change. The current version and its update date will always be published on this page.