Privacy and cookie policy
This page describes what personal data Sajva collects, why, how long we keep it, and what rights you have — whether you're visiting sajva.ai, filling in our contact form, or using Sajva as an employee of one of our customers.
Last updated: August 2026
In short
- We only collect what we need to answer your enquiry or run the service — nothing is sold or shared with third parties for marketing.
- sajva.ai itself sets no cookies of its own. The Sajva app uses two cookies, both required for sign-in and language preference — no tracking, no advertising, no banner needed.
- The app and database run on AWS within the EU (Ireland). This marketing website is, during a transition period, hosted outside the EU — see section 6.
- Material you upload into the service is your own — we're your data processor for it, not the controller. It's deleted when you delete it yourself, and no later than 30 days after your agreement ends.
- You have the right to access, correct and delete your data — contact info@sajva.ai.
1. Who is the data controller
Sajva AB (org. no. 559591-2212), Stockholm, is the data controller for the processing of your personal data when you visit sajva.ai, contact us, or use an account with us — with one exception, described in section 2.3, where we act as a data processor on behalf of our customer instead.
Questions about this policy or about how we handle your data can be sent to info@sajva.ai.
2. What data we collect
Which data depends on how you interact with us.
- 2.1 Contact form (book a demo): first name, last name, email, company, phone number and number of employees if you provide them, plus any message you write. Legal basis: our legitimate interest in answering your enquiry (see sections 3 and 4).
- 2.2 Account in the service: email address, password (stored as a hash, never in plain text), role within the company, MFA setting, and last sign-in time. Legal basis: performance of the contract with the company you represent.
- 2.3 Material you upload into the service: ESG questionnaires, answers, source documents, and what is extracted from them. This is your own working data — we process it as your data processor, not as the controller. If the documents contain personal data about your own employees or suppliers, you — not Sajva — are the controller for that data.
- 2.4 Activity log: who did what inside a customer account — answers approved, documents added, roles changed, sign-ins and sign-outs — together with the IP address the action was taken from. This is the customer's own audit trail; the legal basis is our legitimate interest in traceability and information security.
- 2.5 Contacts we reach out to. We collect name, role, company, work email and phone number from company websites, public registers and industry association member lists, and use them to contact you in your professional capacity about our service, our webinars and our research. Legal basis: legitimate interest in business-to-business marketing directed to you in your professional role. We keep the data for 24 months after our last contact. You can object at any time — email info@sajva.ai and we will remove you and not contact you again.
- 2.6 Webinar registrations. Name, email, company and role when you register; attendance and any questions you ask. Used to run the webinar, send the link, reminders, recording and materials, and to follow up on interest. Legal basis: performance of the registration, and legitimate interest for the follow-up. Kept 24 months. Our webinars run on Microsoft Teams; Microsoft processes registration and attendance data on our behalf, within the EU/EEA.
- 2.7 Survey responses. Your answers about how your company handles sustainability questionnaires, and your email address if you choose to give it. Answers are reported only in aggregate and never in a way that identifies a company. Legal basis: legitimate interest for the aggregated research; your consent for the email address. Individual responses are deleted 12 months after the report is published; the email address after 24 months or when you ask us to.
- 2.8 Cookies: see section 9.
3. Why we process the data
| Category | Purpose | Legal basis |
|---|---|---|
| Contact form | Respond to your enquiry and book a demo | Legitimate interest |
| Account data | Give you access to the service and bill the right company | Performance of a contract |
| Uploaded material | Provide AI-suggested answers with source references | Data processing agreement with you (see section 8) |
| Activity log | Traceability, security, and support for your own audit | Legitimate interest |
| Contacts we reach out to | Contact you in your professional capacity about our service, webinars and research | Legitimate interest |
| Webinar registrations | Run the webinar and follow up on interest | Performance of the registration / legitimate interest |
| Survey responses | Aggregated research on how companies handle sustainability questionnaires | Legitimate interest / consent (email address) |
AI-suggested answers are generated via Amazon Bedrock (see section 6). Your material is not used to train, fine-tune, or improve any AI model — neither one Sajva operates nor one run by our AI providers. We configure our AI providers, where contractually and technically available, to disable training on customer inputs and outputs.
4. How long we keep data
We don't keep data longer than it's needed. Most of the periods below are enforced in code and run automatically every day.
| Data | Kept | Why |
|---|---|---|
| Sign-in session | Until it expires (up to 7 days of inactivity) | Deleted the moment it stops working |
| Password reset / MFA / email verification code | Until used or expired | A spent one-time value is only ever a risk once kept |
| Contact form (demo request) | 12 months | Covers a Swedish SME's full budget year — beyond that the interest has lapsed |
| Activity log / audit trail | 24 months (never less than 12) | A questionnaire answered in March is reviewed by the recipient the following spring |
| Account | For as long as it exists — deleted or emptied on request (see section 8) | An account ends on instruction, not on a clock |
| Questionnaires, answers, documents you uploaded | Deleted within 30 days after your subscription or agreement ends — or immediately when you delete them yourself | Gives you a grace period to retrieve your material before it's removed |
| Contacts we reach out to (prospect list) | 24 months after our last contact | An outreach attempt nobody answered is no longer a live interest |
| Webinar registrations | 24 months | Covers follow-up spanning more than one season |
| Survey responses | 12 months after the report is published (email address: 24 months) | Individual responses are only needed while the report is compiled and reviewable |
| Application logs | 12 months | Operational security baseline |
The full, continuously maintained version of this table, including the reasoning behind each period, lives in our product documentation and can be shared with customers and their auditors on request.
5. Who we share data with
We never sell personal data and never share it for marketing purposes. The providers who process data on our behalf are:
| Provider | Role | Region |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database and storage for the Sajva service | EU (Ireland, eu-west-1) |
| Amazon Bedrock | AI models for suggested answers and knowledge-base search | EU, via Bedrock's EU region profile |
| Amazon SES | Sending transactional email (e.g. password resets) | EU |
| Brave Search | Public web search for the optional public-sources feature in answers — only for customers who have switched it on | United States |
| Cloudflare | DNS and traffic routing (CDN) for sajva.ai | Global network |
| Microsoft (Teams) | Running webinars — registration, attendance, recording | EU/EEA |
| Resend | Sending email from the contact form (book a demo) | EU (Ireland, eu-west-1) |
All providers are bound by data processing agreements or equivalent standard contractual clauses. We never add a new sub-processor with access to a customer's material without it being reflected in our data processing agreement.
6. Where data lives, and transfers outside the EU/EEA
The Sajva service — application, database and AI processing — runs on AWS within the EU (Ireland, eu-west-1). Data relating to your account, your activity log and your uploaded material does not leave the EU/EEA.
One exception today: this marketing website (sajva.ai) is, during a transition period, hosted on infrastructure outside the EU/EEA, ahead of a planned move to the same EU-based infrastructure as the app. The website itself sets no cookies of its own. Submitting the contact form is briefly handled by the website's own server — for validation and abuse prevention — before being forwarded immediately to Resend (EU, see section 5) for delivery. No submission content is logged or stored on the website's server.
This transfer relies on the European Commission's adequacy decision for the US (the Data Privacy Framework) and, as a backstop, the European Commission's standard contractual clauses. The adequacy decision has been appealed to the Court of Justice of the EU (since October 2025) and is still under review — we're following that and will update this page if the outcome changes the basis for this transfer.
Our CDN provider Cloudflare handles traffic to the website technically as part of ordinary page delivery. Cloudflare is a sub-processor and is treated the same as our other providers in section 5.
We will update this page as soon as the marketing website has moved to EU infrastructure.
7. Security
All data is encrypted both in transit and at rest. Access is governed by roles you control yourselves, and every action in the service is logged for traceability. A full walkthrough of our security practices is on our security page.
If a personal-data breach occurs, we follow a documented incident response plan — who is contacted, in what order, and within what timeframe — including notifying the Swedish Authority for Privacy Protection (IMY) within 72 hours where required, notifying affected customers within 48 hours under our data processing agreement, and notifying affected individuals without undue delay. The plan can be shared with customers and their auditors on request.
8. Your rights
Under GDPR you have the right to:
- Access the data we hold about you
- Have inaccurate data corrected
- Request erasure of your data ("the right to be forgotten")
- Request that processing be restricted
- Receive your data in a structured, portable format
- Object to processing based on legitimate interest
- Lodge a complaint with the Swedish Authority for Privacy Protection (IMY), imy.se, if you believe we are processing your data incorrectly
If you're an employee of one of our customers and request deletion of your account, your sign-in credentials are removed immediately. Your name may remain, replaced by an anonymised label, in the customer's audit trail — otherwise the trail would stop showing who approved what for the customer's own compliance record, which would erase accountability rather than you. This is governed by our data processing agreement with the customer you're employed by, who is the controller for your employment-related use of the service.
If you're a customer and want to enter into a data processing agreement (DPA) for your use of the service, contact info@sajva.ai — it's included for every customer.
Contact us at info@sajva.ai to exercise any of your rights. We respond within one month, as required by GDPR.
10. Changes to this policy
We update this page when what we actually do changes — for example when the marketing website moves to EU infrastructure (see section 6). The date at the top shows when the page was last changed. We notify customers separately of material changes.
Questions about how we handle your data?
Reach out at info@sajva.ai and we'll get back to you as soon as we can.