Privacy Policy
1 Who we are
Varentio is a service operated by Labs Software Sweden AB.
- Company
- Labs Software Sweden AB
- Registration number
- 559589-9914
- Address
- Sandkilsvägen 9B, 184 42 Åkersberga, Sweden
- Privacy enquiries
- privacy@varentio.com
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Privacy enquiries are handled directly at the address above.
2 Our two roles
This determines which parts of this policy apply to you.
We are the controller for data relating to the Varentio platform itself: website visitors, sign-in attempts, account administration and billing. This policy describes that processing.
We are a processor for data our customers store inside their own Varentio workspace — their employees, their customers, their suppliers, their production records. We process that data only on the documented instructions of the customer, who is the controller of it. That processing is governed by a separate Data Processing Agreement, not by this policy.
If your employer uses Varentio and you have questions about data held in their workspace, contact your employer. They decide what is stored and for how long.
3 What we collect, and when
Visiting the website
Our web server records standard technical information for every request: IP address, browser and operating system identifier, requested and referring page, and the date and time of the request. This is necessary to operate a web server securely. It is not linked to an identified person unless you subsequently sign in.
Attempting to sign in
Varentio is invitation-only. There is no public registration. If you attempt to sign in, we record your IP address and the time of the attempt, whether it succeeded or failed, two-factor verification attempts, and password reset requests if you make one.
This applies whether or not you hold a valid account. Recording failed attempts from unknown parties is how we detect intrusion attempts.
Holding an account
If you have been invited and hold an account, we process the identifying and contact details supplied when your account was created, your role and permissions, the workspace you belong to, and your sign-in history.
Files uploaded to a workspace
Documents attached to records inside a workspace are stored in a directory that is not reachable over the web, accessible only through the application and subject to your permissions. Such files belong to the customer's workspace, so we act as processor for them.
5 Bot protection on sign-in pages
Our sign-in and password reset pages use Google reCAPTCHA to prevent automated attacks. What this means in practice:
- Google receives your IP address and information about your browser when these pages load, even if no challenge is displayed to you
- Google processes this data for its own purposes, under its own privacy policy
- Google LLC is established in the United States, so this involves a transfer of personal data outside the EU/EEA
This affects the sign-in page and the password reset page only. No other page on our site contacts Google.
Legal basis: our legitimate interest in protecting accounts from automated attacks (Article 6(1)(f)). Transfers rely on the European Commission's standard contractual clauses and Google's participation in the EU-US Data Privacy Framework.
We are evaluating a replacement that does not involve a third party. This section will be updated if that changes.
6 Why we process your data
| Purpose | Legal basis |
|---|---|
| Operating and securing the service | Legitimate interest — Art. 6(1)(f) |
| Detecting and preventing intrusion attempts | Legitimate interest — Art. 6(1)(f) |
| Providing the service to account holders | Contract — Art. 6(1)(b) |
| Invoicing and accounting records | Legal obligation — Art. 6(1)(c) |
We do not use your data for marketing, profiling or automated decision-making, and we do not sell it.
7 How long we keep it
Deletion is automatic. Our servers run a scheduled job every night that removes data once it passes the periods below. These are not aspirations; they are what the system does.
| Data | Retention |
|---|---|
| Web server access logs | Up to 15 days |
| Sign-in attempt records used for rate limiting | 30 days |
| Password reset attempt records | 30 days |
| Sign-in history (successful and failed) | 90 days |
| Two-factor verification attempts | 90 days |
| Expired password reset tokens | 30 days after expiry |
| Remembered device records | 30 days after expiry |
| Active session records | 7 days after last activity |
| Administrator access to customer workspaces | 24 months |
The last entry is deliberately long. When our staff access a customer workspace for support purposes, that access is logged and retained so the customer can audit it.
Account data is retained for as long as the account exists. Accounting records are retained for seven years, as required by the Swedish Bookkeeping Act. Data inside a customer workspace is retained according to the customer's instructions, not ours.
8 Backups
We take daily backups so the service can be restored after a failure. Backups are retained for 7 days.
Backups are used only for restoring the service. We do not search them, analyse them, or use them to look anyone up.
This means that when data is deleted from the live system, a copy may persist in a backup until that backup ages out. If a restore ever becomes necessary, deletions are re-applied afterwards.
9 Where your data is processed
Varentio runs on servers operated by GleSYS AB in a data centre in Stockholm, Sweden. We operate our own server infrastructure rather than building on a third-party platform, which keeps the number of parties with access to your data deliberately small.
| Party | Role | Location |
|---|---|---|
| GleSYS AB | Server infrastructure | Sweden |
| Loopia AB | Domain and email hosting | Sweden |
| SMTP2GO | Delivery of system email | European Union |
| Google LLC | Bot protection on sign-in pages | United States |
With the exception of the bot protection described in section 5, your data does not leave the EU/EEA.
We will update this list before adding any new party, and customers under a Data Processing Agreement will be notified in advance as that agreement requires.
10 Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you
- Rectify data that is inaccurate or incomplete
- Erase your data, where no legal obligation requires us to keep it
- Restrict processing while a dispute is resolved
- Object to processing based on legitimate interest, including the security logging described in section 3
- Data portability — receive your data in a machine-readable format
- Withdraw consent, where processing is based on consent
To exercise any of these, email privacy [at] varentio [dot] com. We respond within one month.
If your data sits inside an employer's workspace, we will forward your request to them, as they are the controller for that data.
11 How we protect your data
Access to the service requires an invitation; there is no public sign-up. Accounts are protected by two-factor authentication. Access within a workspace is governed by role-based permissions, and every workspace is isolated from every other at the database level.
All traffic is encrypted in transit using TLS. Repeated failed sign-in attempts are rate limited. Passwords are stored using one-way hashing and cannot be recovered by us or by anyone else.
No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the Swedish Authority for Privacy Protection within 72 hours and inform affected individuals where the law requires it.
12 Complaints
If you believe we have handled your data unlawfully, please contact us first — most issues are resolved quickly.
You also have the right to lodge a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
imy@imy.se · www.imy.se
13 Changes to this policy
This policy is versioned. When we change it, we increase the version number and update the date at the top of this page. Material changes affecting account holders will be communicated by email. Previous versions are available on request.