sajva
PRIVACY

Privacy and cookie policy

This page describes what personal data Sajva collects, why, how long we keep it, and what rights you have — whether you're visiting sajva.ai, filling in our contact form, or using Sajva as an employee of one of our customers.

Last updated: August 2026

In short

  • We only collect what we need to answer your enquiry or run the service — nothing is sold or shared with third parties for marketing.
  • sajva.ai itself sets no cookies of its own. The Sajva app uses two cookies, both required for sign-in and language preference — no tracking, no advertising, no banner needed.
  • The app and database run on AWS within the EU (Ireland). This marketing website is, during a transition period, hosted outside the EU — see section 6.
  • Material you upload into the service is your own — we're your data processor for it, not the controller. It's deleted when you delete it yourself, and no later than 30 days after your agreement ends.
  • You have the right to access, correct and delete your data — contact info@sajva.ai.

1. Who is the data controller

Sajva AB (org. no. 559591-2212), Stockholm, is the data controller for the processing of your personal data when you visit sajva.ai, contact us, or use an account with us — with one exception, described in section 2.3, where we act as a data processor on behalf of our customer instead.

Questions about this policy or about how we handle your data can be sent to info@sajva.ai.

2. What data we collect

Which data depends on how you interact with us.

  • 2.1 Contact form (book a demo): first name, last name, email, company, phone number and number of employees if you provide them, plus any message you write. Legal basis: our legitimate interest in answering your enquiry (see sections 3 and 4).
  • 2.2 Account in the service: email address, password (stored as a hash, never in plain text), role within the company, MFA setting, and last sign-in time. Legal basis: performance of the contract with the company you represent.
  • 2.3 Material you upload into the service: ESG questionnaires, answers, source documents, and what is extracted from them. This is your own working data — we process it as your data processor, not as the controller. If the documents contain personal data about your own employees or suppliers, you — not Sajva — are the controller for that data.
  • 2.4 Activity log: who did what inside a customer account — answers approved, documents added, roles changed, sign-ins and sign-outs — together with the IP address the action was taken from. This is the customer's own audit trail; the legal basis is our legitimate interest in traceability and information security.
  • 2.5 Contacts we reach out to. We collect name, role, company, work email and phone number from company websites, public registers and industry association member lists, and use them to contact you in your professional capacity about our service, our webinars and our research. Legal basis: legitimate interest in business-to-business marketing directed to you in your professional role. We keep the data for 24 months after our last contact. You can object at any time — email info@sajva.ai and we will remove you and not contact you again.
  • 2.6 Webinar registrations. Name, email, company and role when you register; attendance and any questions you ask. Used to run the webinar, send the link, reminders, recording and materials, and to follow up on interest. Legal basis: performance of the registration, and legitimate interest for the follow-up. Kept 24 months. Our webinars run on Microsoft Teams; Microsoft processes registration and attendance data on our behalf, within the EU/EEA.
  • 2.7 Survey responses. Your answers about how your company handles sustainability questionnaires, and your email address if you choose to give it. Answers are reported only in aggregate and never in a way that identifies a company. Legal basis: legitimate interest for the aggregated research; your consent for the email address. Individual responses are deleted 12 months after the report is published; the email address after 24 months or when you ask us to.
  • 2.8 Cookies: see section 9.

3. Why we process the data

CategoryPurposeLegal basis
Contact formRespond to your enquiry and book a demoLegitimate interest
Account dataGive you access to the service and bill the right companyPerformance of a contract
Uploaded materialProvide AI-suggested answers with source referencesData processing agreement with you (see section 8)
Activity logTraceability, security, and support for your own auditLegitimate interest
Contacts we reach out toContact you in your professional capacity about our service, webinars and researchLegitimate interest
Webinar registrationsRun the webinar and follow up on interestPerformance of the registration / legitimate interest
Survey responsesAggregated research on how companies handle sustainability questionnairesLegitimate interest / consent (email address)

AI-suggested answers are generated via Amazon Bedrock (see section 6). Your material is not used to train, fine-tune, or improve any AI model — neither one Sajva operates nor one run by our AI providers. We configure our AI providers, where contractually and technically available, to disable training on customer inputs and outputs.

4. How long we keep data

We don't keep data longer than it's needed. Most of the periods below are enforced in code and run automatically every day.

DataKeptWhy
Sign-in sessionUntil it expires (up to 7 days of inactivity)Deleted the moment it stops working
Password reset / MFA / email verification codeUntil used or expiredA spent one-time value is only ever a risk once kept
Contact form (demo request)12 monthsCovers a Swedish SME's full budget year — beyond that the interest has lapsed
Activity log / audit trail24 months (never less than 12)A questionnaire answered in March is reviewed by the recipient the following spring
AccountFor as long as it exists — deleted or emptied on request (see section 8)An account ends on instruction, not on a clock
Questionnaires, answers, documents you uploadedDeleted within 30 days after your subscription or agreement ends — or immediately when you delete them yourselfGives you a grace period to retrieve your material before it's removed
Contacts we reach out to (prospect list)24 months after our last contactAn outreach attempt nobody answered is no longer a live interest
Webinar registrations24 monthsCovers follow-up spanning more than one season
Survey responses12 months after the report is published (email address: 24 months)Individual responses are only needed while the report is compiled and reviewable
Application logs12 monthsOperational security baseline

The full, continuously maintained version of this table, including the reasoning behind each period, lives in our product documentation and can be shared with customers and their auditors on request.

5. Who we share data with

We never sell personal data and never share it for marketing purposes. The providers who process data on our behalf are:

ProviderRoleRegion
Amazon Web Services (AWS)Hosting, database and storage for the Sajva serviceEU (Ireland, eu-west-1)
Amazon BedrockAI models for suggested answers and knowledge-base searchEU, via Bedrock's EU region profile
Amazon SESSending transactional email (e.g. password resets)EU
Brave SearchPublic web search for the optional public-sources feature in answers — only for customers who have switched it onUnited States
CloudflareDNS and traffic routing (CDN) for sajva.aiGlobal network
Microsoft (Teams)Running webinars — registration, attendance, recordingEU/EEA
ResendSending email from the contact form (book a demo)EU (Ireland, eu-west-1)

All providers are bound by data processing agreements or equivalent standard contractual clauses. We never add a new sub-processor with access to a customer's material without it being reflected in our data processing agreement.

6. Where data lives, and transfers outside the EU/EEA

The Sajva service — application, database and AI processing — runs on AWS within the EU (Ireland, eu-west-1). Data relating to your account, your activity log and your uploaded material does not leave the EU/EEA.

One exception today: this marketing website (sajva.ai) is, during a transition period, hosted on infrastructure outside the EU/EEA, ahead of a planned move to the same EU-based infrastructure as the app. The website itself sets no cookies of its own. Submitting the contact form is briefly handled by the website's own server — for validation and abuse prevention — before being forwarded immediately to Resend (EU, see section 5) for delivery. No submission content is logged or stored on the website's server.

This transfer relies on the European Commission's adequacy decision for the US (the Data Privacy Framework) and, as a backstop, the European Commission's standard contractual clauses. The adequacy decision has been appealed to the Court of Justice of the EU (since October 2025) and is still under review — we're following that and will update this page if the outcome changes the basis for this transfer.

Our CDN provider Cloudflare handles traffic to the website technically as part of ordinary page delivery. Cloudflare is a sub-processor and is treated the same as our other providers in section 5.

We will update this page as soon as the marketing website has moved to EU infrastructure.

7. Security

All data is encrypted both in transit and at rest. Access is governed by roles you control yourselves, and every action in the service is logged for traceability. A full walkthrough of our security practices is on our security page.

If a personal-data breach occurs, we follow a documented incident response plan — who is contacted, in what order, and within what timeframe — including notifying the Swedish Authority for Privacy Protection (IMY) within 72 hours where required, notifying affected customers within 48 hours under our data processing agreement, and notifying affected individuals without undue delay. The plan can be shared with customers and their auditors on request.

8. Your rights

Under GDPR you have the right to:

  • Access the data we hold about you
  • Have inaccurate data corrected
  • Request erasure of your data ("the right to be forgotten")
  • Request that processing be restricted
  • Receive your data in a structured, portable format
  • Object to processing based on legitimate interest
  • Lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se, if you believe we are processing your data incorrectly

If you're an employee of one of our customers and request deletion of your account, your sign-in credentials are removed immediately. Your name may remain, replaced by an anonymised label, in the customer's audit trail — otherwise the trail would stop showing who approved what for the customer's own compliance record, which would erase accountability rather than you. This is governed by our data processing agreement with the customer you're employed by, who is the controller for your employment-related use of the service.

If you're a customer and want to enter into a data processing agreement (DPA) for your use of the service, contact info@sajva.ai — it's included for every customer.

Contact us at info@sajva.ai to exercise any of your rights. We respond within one month, as required by GDPR.

9. Cookies

sajva.ai (this website) sets no cookies of its own. Language is chosen by the URL (sajva.ai/sv vs. /en), not by a cookie.

When you sign in to the Sajva service itself, two cookies are used, both required for the service to work:

CookiePurposeDurationType
__Host-sajva_sessionKeeps you signed inUp to 7 days, or until you sign outNecessary — stored encrypted, inaccessible to JavaScript
sajva_localeRemembers your language choice in the appUntil you change language againNecessary / functional

We use no cookies for marketing, tracking, or third-party analytics. Because we only use cookies strictly necessary for the service to function, Swedish e-communications law does not require a consent banner — but you're always welcome to reach out if you have questions about this.

Our CDN provider Cloudflare may, in exceptional cases, set its own technical cookies (for example to protect against traffic abuse) under its own terms.

10. Changes to this policy

We update this page when what we actually do changes — for example when the marketing website moves to EU infrastructure (see section 6). The date at the top shows when the page was last changed. We notify customers separately of material changes.

Questions about how we handle your data?

Reach out at info@sajva.ai and we'll get back to you as soon as we can.