Privacy Policy
Version 2026-09-30
For customers who accepted an earlier version, this version applies from 30 October 2026.
This policy explains how Amiqa Tech AB handles personal data when we decide why and how it is used: data about the people who use the Amiqa app, visitors to amiqa.io, and people who contact us. Data about a hotel's guests is handled under the hotel's instructions, as described in our Data Processing Agreement at amiqa.io/dpa. For that data, contact the hotel.
1. Who we are
Amiqa Tech AB, org. nr 559492-5744, Fatburs Kvarngata 24, 118 64 Stockholm, Sweden, is the controller. Contact us about privacy at support@amiqa.io. We apply the GDPR and the Swedish Data Protection Act (dataskyddslagen, 2018:218). Our supervisory authority is the Swedish Authority for Privacy Protection (IMY).
2. What we collect and why
| Data | Where it comes from | Why we use it | Legal basis (GDPR) | How long we keep it |
|---|---|---|---|---|
| Account details: name, work email, phone, role, hotel, login history | You, or a colleague who invites you; Google if you sign in with Google | To create and run your account, and keep it secure | Contract (Art. 6(1)(b)); legitimate interest in security (Art. 6(1)(f)) | While the account exists, plus 30 days |
| Billing details: company name, address, VAT number, invoices, payment status | You and our payment provider Stripe | To charge the subscription and keep accounting records | Contract; legal obligation (Swedish Bookkeeping Act, bokföringslagen 1999:1078) | Accounting records, including invoices: 7 years after the end of the calendar year in which the financial year ended. Other billing data: while the account exists |
| Support messages | You, by email or in the app | To answer and fix problems | Contract; legitimate interest | 24 months after the last message |
| Contact, demo and waiting-list requests from amiqa.io | You | To answer you and follow up about Amiqa | Legitimate interest (Art. 6(1)(f)) | 24 months after the last contact, or until you object |
| Technical and security data: IP address, browser, bot-check result, error and access logs | Your device and our servers | To keep the Services secure and working | Legitimate interest | Up to 90 days. Security audit logs of our infrastructure: 12 months |
| Analytics and advertising data on amiqa.io | Cookies, only if you accept them | To measure the website and our campaigns | Consent (Art. 6(1)(a)) | Google Analytics: event data 2 months, user-level data 14 months. The cookies expire after up to 2 years (Google Analytics) or 90 days (Meta) |
We do not use your personal data for automated decisions that have legal or similarly significant effects on you.
3. Who we share it with
We share personal data only with the providers below, which process it for us under data processing agreements, or when the law requires it.
| Provider | What for | Where |
|---|---|---|
| Amazon Web Services | Hosting and databases | EU (Stockholm, Frankfurt) |
| Vercel | Hosting the app and amiqa.io | EU (Stockholm); Vercel is a US company |
| Stripe | Subscription payments and invoices | EU and United States |
| Brevo | Account emails, such as verification and password reset | EU (France) |
| Email, sign in with Google, demo booking calendar, the waiting-list form | EU and United States | |
| Cloudflare | Bot protection on sign-up (Turnstile) | EU and United States |
| Google Analytics and Meta | Website analytics and advertising, only with your consent | United States |
Stripe, and Google when you sign in with Google, also act as independent controllers for part of this data under their own privacy policies.
If we sell or merge the business, personal data may be transferred to the buyer, under this policy.
4. Transfers outside the EU
Our own databases are in the EU. Some providers above are based in the United States. For those transfers we rely on the EU–US Data Privacy Framework where the provider is certified, and otherwise on the EU Standard Contractual Clauses. You can ask us for a copy of the safeguards at support@amiqa.io.
5. Cookies
We follow the Swedish Electronic Communications Act (lagen om elektronisk kommunikation, 2022:482): cookies that are not strictly necessary are used only with your consent. The Amiqa app uses only the cookies needed to keep you signed in and secure.
amiqa.io uses necessary cookies, plus analytics and advertising cookies (Google Analytics, Meta pixel) only after you accept them in the cookie banner. Until you choose, none of these tools loads. You can change your choice at any time with the "Cookies" link at the bottom of every page.
6. Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict or object to its use, or send it to you in a portable format. Where we rely on consent, you can withdraw it at any time. Write to support@amiqa.io. We answer within one month.
If you think we handle your data wrongly, you can complain to the Swedish Authority for Privacy Protection (IMY), imy.se, or to the authority in your own country.
7. Security
We protect personal data with measures that include encryption in transit, access limited by role, separation between customers, and monitoring. Our Data Processing Agreement describes them in detail.
8. Changes
We will post any update here with a new version date. For significant changes we will email account owners before they take effect.
Amiqa Tech AB · Fatburs Kvarngata 24, 118 64 Stockholm, Sweden · support@amiqa.io