V Varentio Sign in

On this page

  1. Who we are
  2. Our two roles
  3. What we collect
  4. Cookies
  5. Bot protection
  6. Why we process your data
  7. How long we keep it
  8. Backups
  9. Where data is processed
  10. Your rights
  11. How we protect your data
  12. Complaints
  13. Changes to this policy

Privacy Policy

Version 1.0 · Effective 2026-09-04

1 Who we are

Varentio is a service operated by Labs Software Sweden AB.

Company
Labs Software Sweden AB
Registration number
559589-9914
Address
Sandkilsvägen 9B, 184 42 Åkersberga, Sweden
Privacy enquiries
privacy@varentio.com

We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 of the GDPR. Privacy enquiries are handled directly at the address above.

2 Our two roles

This determines which parts of this policy apply to you.

We are the controller for data relating to the Varentio platform itself: website visitors, sign-in attempts, account administration and billing. This policy describes that processing.

We are a processor for data our customers store inside their own Varentio workspace — their employees, their customers, their suppliers, their production records. We process that data only on the documented instructions of the customer, who is the controller of it. That processing is governed by a separate Data Processing Agreement, not by this policy.

If your employer uses Varentio and you have questions about data held in their workspace, contact your employer. They decide what is stored and for how long.

3 What we collect, and when

Visiting the website

Our web server records standard technical information for every request: IP address, browser and operating system identifier, requested and referring page, and the date and time of the request. This is necessary to operate a web server securely. It is not linked to an identified person unless you subsequently sign in.

Attempting to sign in

Varentio is invitation-only. There is no public registration. If you attempt to sign in, we record your IP address and the time of the attempt, whether it succeeded or failed, two-factor verification attempts, and password reset requests if you make one.

This applies whether or not you hold a valid account. Recording failed attempts from unknown parties is how we detect intrusion attempts.

Holding an account

If you have been invited and hold an account, we process the identifying and contact details supplied when your account was created, your role and permissions, the workspace you belong to, and your sign-in history.

Files uploaded to a workspace

Documents attached to records inside a workspace are stored in a directory that is not reachable over the web, accessible only through the application and subject to your permissions. Such files belong to the customer's workspace, so we act as processor for them.

4 Cookies

We use one cookie:

NamePurposeDuration
PHPSESSID Maintains your session while you use the service Deleted when you close your browser

This cookie is strictly necessary to operate the service and does not require consent. It carries no advertising or tracking function.

We do not use analytics, advertising or tracking cookies. We do not embed third-party fonts, social media widgets or tracking pixels. This is why you will not see a cookie banner on our site.

Additional cookies may be set by the security measure described in section 5 when you visit a sign-in page.

5 Bot protection on sign-in pages

Our sign-in and password reset pages use Google reCAPTCHA to prevent automated attacks. What this means in practice:

  • Google receives your IP address and information about your browser when these pages load, even if no challenge is displayed to you
  • Google processes this data for its own purposes, under its own privacy policy
  • Google LLC is established in the United States, so this involves a transfer of personal data outside the EU/EEA

This affects the sign-in page and the password reset page only. No other page on our site contacts Google.

Legal basis: our legitimate interest in protecting accounts from automated attacks (Article 6(1)(f)). Transfers rely on the European Commission's standard contractual clauses and Google's participation in the EU-US Data Privacy Framework.

We are evaluating a replacement that does not involve a third party. This section will be updated if that changes.

6 Why we process your data

PurposeLegal basis
Operating and securing the serviceLegitimate interest — Art. 6(1)(f)
Detecting and preventing intrusion attemptsLegitimate interest — Art. 6(1)(f)
Providing the service to account holdersContract — Art. 6(1)(b)
Invoicing and accounting recordsLegal obligation — Art. 6(1)(c)

We do not use your data for marketing, profiling or automated decision-making, and we do not sell it.

7 How long we keep it

Deletion is automatic. Our servers run a scheduled job every night that removes data once it passes the periods below. These are not aspirations; they are what the system does.

DataRetention
Web server access logsUp to 15 days
Sign-in attempt records used for rate limiting30 days
Password reset attempt records30 days
Sign-in history (successful and failed)90 days
Two-factor verification attempts90 days
Expired password reset tokens30 days after expiry
Remembered device records30 days after expiry
Active session records7 days after last activity
Administrator access to customer workspaces24 months

The last entry is deliberately long. When our staff access a customer workspace for support purposes, that access is logged and retained so the customer can audit it.

Account data is retained for as long as the account exists. Accounting records are retained for seven years, as required by the Swedish Bookkeeping Act. Data inside a customer workspace is retained according to the customer's instructions, not ours.

8 Backups

We take daily backups so the service can be restored after a failure. Backups are retained for 7 days.

Backups are used only for restoring the service. We do not search them, analyse them, or use them to look anyone up.

This means that when data is deleted from the live system, a copy may persist in a backup until that backup ages out. If a restore ever becomes necessary, deletions are re-applied afterwards.

9 Where your data is processed

Varentio runs on servers operated by GleSYS AB in a data centre in Stockholm, Sweden. We operate our own server infrastructure rather than building on a third-party platform, which keeps the number of parties with access to your data deliberately small.

PartyRoleLocation
GleSYS ABServer infrastructureSweden
Loopia ABDomain and email hostingSweden
SMTP2GODelivery of system emailEuropean Union
Google LLCBot protection on sign-in pagesUnited States

With the exception of the bot protection described in section 5, your data does not leave the EU/EEA.

We will update this list before adding any new party, and customers under a Data Processing Agreement will be notified in advance as that agreement requires.

10 Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you
  • Rectify data that is inaccurate or incomplete
  • Erase your data, where no legal obligation requires us to keep it
  • Restrict processing while a dispute is resolved
  • Object to processing based on legitimate interest, including the security logging described in section 3
  • Data portability — receive your data in a machine-readable format
  • Withdraw consent, where processing is based on consent

To exercise any of these, email privacy [at] varentio [dot] com. We respond within one month.

If your data sits inside an employer's workspace, we will forward your request to them, as they are the controller for that data.

11 How we protect your data

Access to the service requires an invitation; there is no public sign-up. Accounts are protected by two-factor authentication. Access within a workspace is governed by role-based permissions, and every workspace is isolated from every other at the database level.

All traffic is encrypted in transit using TLS. Repeated failed sign-in attempts are rate limited. Passwords are stored using one-way hashing and cannot be recovered by us or by anyone else.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights, we will notify the Swedish Authority for Privacy Protection within 72 hours and inform affected individuals where the law requires it.

12 Complaints

If you believe we have handled your data unlawfully, please contact us first — most issues are resolved quickly.

You also have the right to lodge a complaint with the Swedish supervisory authority:

Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
imy@imy.se · www.imy.se

13 Changes to this policy

This policy is versioned. When we change it, we increase the version number and update the date at the top of this page. Material changes affecting account holders will be communicated by email. Previous versions are available on request.

Labs Software Sweden AB · 559589-9914 · Sandkilsvägen 9B, 184 42 Åkersberga Terms Privacy Home