Deeyam LogoDeeyam

Find the right expert. Solve your problem. Connect with verified professionals for 1-on-1 scheduled consultations.

Explore

  • Find an Expert
  • Mock Interviews
  • Career Mentorship
  • Become an Expert

Resources

  • How It Works
  • About Us
  • Contact Support
  • Cookie Policy

Contact & Support

support@deeyam.com
+46 (0)8 123 456 78

Customer support responds within 1 business day

Secure Checkout & Stripe Destination Charges

Funds held in escrow until consultation completion.

Secured by Stripe

Deeyam is operated by Asimovx technologies AB (Org. nr: 556XXX-XXXX, VAT: SE556XXXXXXXX01), Kungsgatan 12, 111 35 Stockholm, Sweden.

© 2026 Asimovx technologies AB. All rights reserved.
Terms of ServiceExpert AgreementPrivacy Policy (GDPR)Cancellation & Refund PolicyProhibited ServicesCookie Policy
EU Regulation 2016/679 (GDPR) & Swedish Data Law

Privacy Policy & Data Processing Notice

How Asimovx technologies AB processes, protects, and retains personal data on the Deeyam platform.

Last Updated: September 16, 2026•Jurisdiction: Sweden / European Union•Document Ref: SE-GDPR-2026-V2

Notice Concerning Legal Review & Statutory Compliance

This document is a structured, production-oriented privacy and data processing disclosure drafted for formal review by qualified Swedish legal counsel (advokat or jurist). Neither this document nor platform documentation constitutes legal advice or guarantees statutory compliance, as GDPR determinations depend upon actual technical configurations, physical data flows, and ongoing operational practices.

1. Data Controller Identity

Under Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679 - "GDPR"), the primary Data Controller for personal data processed through Deeyam is:

Legal EntityAsimovx technologies AB
Swedish Corporate ID (Org.nr)556XXX-XXXX
Registered AddressKungsgatan 12, 111 35 Stockholm, Sweden
VAT Registration NumberSE556XXXXXXXX01
Privacy & DPO Inquiriesprivacy@deeyam.com
General Customer Supportsupport@deeyam.com

2. Processing Activities & Retention Schedule

In accordance with GDPR Article 13 and Article 30, the table below delineates the specific categories of personal data processed, the specific operational purpose, the applicable legal basis under GDPR Article 6(1), and the strictly defined data retention period.

Processing PurposeCategories of DataLegal Basis (GDPR Art. 6)Retention Period
Account Creation & AuthenticationPlatform user profiles, credentials & identityFull name, email address, password hash (argon2/bcrypt), profile picture, professional title/bio, timezone, preferred language.Art. 6(1)(b)Contract Performance (Platform Terms)Maintained for the duration of the active account plus a 30-day grace period post-account deletion request to facilitate dispute resolution and operational purging.
Consultation Bookings & Session Metadata1:1 schedule facilitation & technical routingScheduled time slot, service title, calendar event IDs, WebRTC peer connection telemetry (IP address, packet loss, bandwidth).
Ephemeral Media Streams: Audio and video streams are transmitted point-to-point via WebRTC mesh / relay servers and are NOT recorded or persisted by default.
Art. 6(1)(b)Contract Performance & Art. 6(1)(f) Legitimate Interest (service quality)90 days for technical session diagnostics, network connection logs, and scheduling disputes. Purged automatically upon expiry.
Financial & Statutory BookkeepingPayment receipts, commission invoices & payoutsInvoice ID, transaction amounts, Swedish VAT breakdown (moms), Stripe charge/transfer IDs, payer/payee billing identity, timestamp.Art. 6(1)(c)Legal Statutory Obligation (Bokföringslagen (1999:1078))Retained strictly for the statutory period mandated by Swedish bookkeeping legislation (currently the remaining calendar year plus 7 years under Bokföringslagen 1999:1078).*Non-financial metadata, user messaging, and user profiles are expressly excluded from this statutory retention period and are erased earlier.
Security Monitoring & Error DiagnosticsAbuse prevention, rate limiting & server healthIP address, User-Agent header, request URL paths, HTTP status codes, timestamp, crash stack traces.Art. 6(1)(f)Legitimate Interest (Network and information security, Art. 32 GDPR)Rolling retention window of 14 to 30 days, after which server logs are automatically overwritten or anonymized.
Consent-Based Analytics & PreferencesPlatform performance & interface enhancementsAggregated click patterns, navigation flows, cookie identifiers, UI theme preferences.Art. 6(1)(a)Explicit Consent (Swedish LEK & GDPR)Valid for up to 12 months or until consent is withdrawn by the user via our Cookie Settings modal.

3. Stripe Connect Roles & Payment Data Flows

We integrate Stripe Connect (using Destination Charges architecture) to process payments from clients and facilitate split payouts to independent experts. Under GDPR, Stripe’s legal role varies depending on the specific activity:

Client Payment Authorization & Processing

When a client inputs card details, they are tokenized directly via Stripe Elements. Asimovx technologies AB never receives or stores raw PANs, CVVs, or full cardholder data. For the execution of the payment transaction, Stripe acts as a Data Processor on our behalf.

Fraud Monitoring (Stripe Radar)

Stripe analyzes transaction signals across its global merchant network to detect fraudulent patterns. For this fraud detection and risk scoring processing, Stripe acts as an Independent Data Controller under its own global privacy commitments.

Expert KYC / AML Compliance

When independent experts onboard to receive payouts, Stripe collects identity documentation, national tax IDs, and bank details to satisfy statutory Anti-Money Laundering (AML) and Know-Your-Customer (KYC) directives. For these regulatory verification activities, Stripe acts as an Independent Data Controller.

Billing Descriptors

Transactions will appear on client statements under the descriptor format DEEYAM* [EXPERT], providing clear identification of the marketplace intermediary and specific expert consultation.

4. Data Processors & Subprocessor Directory

We engage third-party subprocessors to deliver specialized cloud infrastructure, authentication, email delivery, and media transport. In accordance with GDPR Article 28, all subprocessors are bound by executed Data Processing Agreements (DPAs) with strict security covenants.

Stripe Payments Europe, Ltd. / Stripe Inc.

Payment processing, customer card tokenization, destination charges payouts, fraud detection (Stripe Radar), and Expert KYC/AML verification

Location: Ireland / USA•Transfer Safeguards: EU-U.S. Data Privacy Framework / Standard Contractual Clauses (SCCs)
Article 28 GDPR DPA active with Stripe

Supabase Inc.

Managed PostgreSQL database hosting, user authentication, and data persistence

Location: EU Region (Frankfurt / Ireland)•Transfer Safeguards: EU Data Residency / Standard Contractual Clauses (SCCs)
Article 28 GDPR DPA active

Vercel Inc.

Frontend and serverless API execution hosting

Location: EU Edge / USA•Transfer Safeguards: EU-U.S. Data Privacy Framework / SCCs with supplementary technical measures
Article 28 GDPR DPA active

LiveKit Inc. / WebRTC Signaling

Real-time 1-on-1 audio/video peer session signaling and media routing

Location: EU Relay Mesh / USA•Transfer Safeguards: Standard Contractual Clauses (SCCs). Streams are ephemeral; not recorded or stored by default.
Article 28 GDPR DPA active

Resend / Postmark

Transactional notifications (booking confirmations, calendar invites, password resets)

Location: EU Gateway / USA•Transfer Safeguards: Standard Contractual Clauses (SCCs)
Article 28 GDPR DPA active
International Data Transfers: Where data is transferred outside the European Economic Area (EEA), transfers are governed by either the EU-U.S. Data Privacy Framework adequacy decision or the European Commission's Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) paired with supplementary technical, contractual, and organizational safeguards.

5. Cookies & Local Storage (Swedish LEK Compliance)

In accordance with Chapter 9, Section 28 of the Swedish Electronic Communications Act (Lag (2022:482) om elektronisk kommunikation - LEK), cookies and local storage items are classified as follows:

  • Strictly Necessary Storage: Essential for user authentication, security tokens (CSRF protection), and load balancing. These do not require prior consent under Swedish law as they are strictly necessary to deliver the requested service.
  • Non-Essential Trackers & Analytics: Used solely to analyze platform performance. No non-essential cookies or telemetry scripts are initialized or loaded until the user provides affirmative, informed consent via our cookie consent banner.

You can review, modify, or revoke your consent preferences at any time by clicking the Cookie Policy or launching the cookie preference center in the footer.

6. Automated Decision-Making & Profiling (GDPR Art. 22)

We do not employ automated decision-making or profiling systems that produce legal effects concerning you or similarly significantly affect you under Article 22 of the GDPR.

Marketplace search rankings and expert recommendations are generated based on transparent, objective parameters including explicit search filters, schedule availability, expert category tags, and verified client review averages.

7. Your Rights Under GDPR (Articles 15–22)

As a data subject located within the European Economic Area, you hold statutory rights enforceable against Asimovx technologies AB:

Right of Access (Art. 15)

Obtain confirmation of processing and a machine-readable copy of your personal data.

Right to Rectification (Art. 16)

Request immediate correction of inaccurate or incomplete personal records.

Right to Erasure / "To Be Forgotten" (Art. 17)

Request erasure where data is no longer necessary, excluding records legally required by Bokföringslagen.

Right to Restriction of Processing (Art. 18)

Request that data processing be temporarily restricted while disputes or claims are verified.

Right to Data Portability (Art. 20)

Receive your profile and booking records in a structured, commonly used JSON/CSV format.

Right to Object & Withdraw Consent (Art. 21 & 7(3))

Object to legitimate interest processing or withdraw cookie/marketing consent without penalty.

Statutory Response Timeframe: Under GDPR Article 12(3), we respond to all verified data subject requests within one calendar month (30 days) of receipt. Where requests are particularly complex or numerous, this period may be extended by up to two additional months; in such cases, we will formally notify you of the reasons for the extension within the initial one-month window.
To exercise any right, email our Data Protection team at: privacy@deeyam.com

8. Incident Notification & Swedish Supervisory Authority

In the event of a confirmed personal data breach, Asimovx technologies AB enforces an incident response protocol adhering to GDPR Articles 33 and 34:

  • 72-Hour Authority Notification (Art. 33): We will notify the Swedish supervisory authority (Integritetsskyddsmyndigheten - IMY) without undue delay and, where feasible, within 72 hours of becoming aware of a breach posing risks to data subjects.
  • Data Subject Communication (Art. 34): If a breach is likely to result in a high risk to individual rights and freedoms, affected users will be informed directly without undue delay.

Swedish Lead Supervisory Authority Contact:

Integritetsskyddsmyndigheten (IMY) (Swedish Authority for Privacy Protection)

Postal Address: Box 8114, 104 20 Stockholm, Sweden

Telephone: +46 (0)8 657 61 00

Official Email: imy@imy.se

Website: https://www.imy.se

9. Profile Accuracy & Anti-Impersonation

To ensure trust and safety across the Deeyam platform, all users must provide strictly truthful and accurate information regarding their identity, credentials, certifications, titles, and professional experience.

Strict Prohibition: We enforce a strict zero-tolerance policy against misleading claims, fabricated credentials, academic dishonesty, and impersonation. Any violation of this policy will result in immediate profile termination, suspension of services, and potential reporting to relevant authorities where applicable.

While we process identity and credential data to verify experts and facilitate a safe marketplace, any deliberate misrepresentation constitutes a material breach of our terms and compromises the integrity of our platform.

← Return to Homepage
Terms of ServiceCancellation PolicyCookie Policy