How Asimovx technologies AB processes, protects, and retains personal data on the Deeyam platform.
This document is a structured, production-oriented privacy and data processing disclosure drafted for formal review by qualified Swedish legal counsel (advokat or jurist). Neither this document nor platform documentation constitutes legal advice or guarantees statutory compliance, as GDPR determinations depend upon actual technical configurations, physical data flows, and ongoing operational practices.
Under Article 4(7) of the General Data Protection Regulation (Regulation (EU) 2016/679 - "GDPR"), the primary Data Controller for personal data processed through Deeyam is:
In accordance with GDPR Article 13 and Article 30, the table below delineates the specific categories of personal data processed, the specific operational purpose, the applicable legal basis under GDPR Article 6(1), and the strictly defined data retention period.
| Processing Purpose | Categories of Data | Legal Basis (GDPR Art. 6) | Retention Period |
|---|---|---|---|
| Account Creation & AuthenticationPlatform user profiles, credentials & identity | Full name, email address, password hash (argon2/bcrypt), profile picture, professional title/bio, timezone, preferred language. | Art. 6(1)(b)Contract Performance (Platform Terms) | Maintained for the duration of the active account plus a 30-day grace period post-account deletion request to facilitate dispute resolution and operational purging. |
| Consultation Bookings & Session Metadata1:1 schedule facilitation & technical routing | Scheduled time slot, service title, calendar event IDs, WebRTC peer connection telemetry (IP address, packet loss, bandwidth). Ephemeral Media Streams: Audio and video streams are transmitted point-to-point via WebRTC mesh / relay servers and are NOT recorded or persisted by default. | Art. 6(1)(b)Contract Performance & Art. 6(1)(f) Legitimate Interest (service quality) | 90 days for technical session diagnostics, network connection logs, and scheduling disputes. Purged automatically upon expiry. |
| Financial & Statutory BookkeepingPayment receipts, commission invoices & payouts | Invoice ID, transaction amounts, Swedish VAT breakdown (moms), Stripe charge/transfer IDs, payer/payee billing identity, timestamp. | Art. 6(1)(c)Legal Statutory Obligation (Bokföringslagen (1999:1078)) | Retained strictly for the statutory period mandated by Swedish bookkeeping legislation (currently the remaining calendar year plus 7 years under Bokföringslagen 1999:1078).*Non-financial metadata, user messaging, and user profiles are expressly excluded from this statutory retention period and are erased earlier. |
| Security Monitoring & Error DiagnosticsAbuse prevention, rate limiting & server health | IP address, User-Agent header, request URL paths, HTTP status codes, timestamp, crash stack traces. | Art. 6(1)(f)Legitimate Interest (Network and information security, Art. 32 GDPR) | Rolling retention window of 14 to 30 days, after which server logs are automatically overwritten or anonymized. |
| Consent-Based Analytics & PreferencesPlatform performance & interface enhancements | Aggregated click patterns, navigation flows, cookie identifiers, UI theme preferences. | Art. 6(1)(a)Explicit Consent (Swedish LEK & GDPR) | Valid for up to 12 months or until consent is withdrawn by the user via our Cookie Settings modal. |
We integrate Stripe Connect (using Destination Charges architecture) to process payments from clients and facilitate split payouts to independent experts. Under GDPR, Stripe’s legal role varies depending on the specific activity:
When a client inputs card details, they are tokenized directly via Stripe Elements. Asimovx technologies AB never receives or stores raw PANs, CVVs, or full cardholder data. For the execution of the payment transaction, Stripe acts as a Data Processor on our behalf.
Stripe analyzes transaction signals across its global merchant network to detect fraudulent patterns. For this fraud detection and risk scoring processing, Stripe acts as an Independent Data Controller under its own global privacy commitments.
When independent experts onboard to receive payouts, Stripe collects identity documentation, national tax IDs, and bank details to satisfy statutory Anti-Money Laundering (AML) and Know-Your-Customer (KYC) directives. For these regulatory verification activities, Stripe acts as an Independent Data Controller.
Transactions will appear on client statements under the descriptor format DEEYAM* [EXPERT], providing clear identification of the marketplace intermediary and specific expert consultation.
We engage third-party subprocessors to deliver specialized cloud infrastructure, authentication, email delivery, and media transport. In accordance with GDPR Article 28, all subprocessors are bound by executed Data Processing Agreements (DPAs) with strict security covenants.
Payment processing, customer card tokenization, destination charges payouts, fraud detection (Stripe Radar), and Expert KYC/AML verification
Managed PostgreSQL database hosting, user authentication, and data persistence
Frontend and serverless API execution hosting
Real-time 1-on-1 audio/video peer session signaling and media routing
Transactional notifications (booking confirmations, calendar invites, password resets)
We do not employ automated decision-making or profiling systems that produce legal effects concerning you or similarly significantly affect you under Article 22 of the GDPR.
Marketplace search rankings and expert recommendations are generated based on transparent, objective parameters including explicit search filters, schedule availability, expert category tags, and verified client review averages.
As a data subject located within the European Economic Area, you hold statutory rights enforceable against Asimovx technologies AB:
Obtain confirmation of processing and a machine-readable copy of your personal data.
Request immediate correction of inaccurate or incomplete personal records.
Request erasure where data is no longer necessary, excluding records legally required by Bokföringslagen.
Request that data processing be temporarily restricted while disputes or claims are verified.
Receive your profile and booking records in a structured, commonly used JSON/CSV format.
Object to legitimate interest processing or withdraw cookie/marketing consent without penalty.
To ensure trust and safety across the Deeyam platform, all users must provide strictly truthful and accurate information regarding their identity, credentials, certifications, titles, and professional experience.
While we process identity and credential data to verify experts and facilitate a safe marketplace, any deliberate misrepresentation constitutes a material breach of our terms and compromises the integrity of our platform.