Transcendo
Privacy

Privacy policy

How Transcendo AB handles personal data – on transcendo.se, when we are in contact with you, and in client engagements.

Who is responsible?

Transcendo AB (Swedish company registration number 559081-7556), Norrköping, Sweden, is the data controller for the processing described here. If you have questions about how we handle your personal data, email info@transcendo.se.

No cookies

This website uses no cookies and stores nothing else in your browser. The fonts are served from our own server, so no information about your visit is sent to Google or anyone else.

Our previous website used Google Analytics. If you visited it before September 2026, cookies from it (__utma and __utmz) may remain in your browser. We do not read them, and the new website asks your browser to remove them.

When you visit the website

As on most websites, the hosting provider records each visit in a log: IP address, time, the page viewed, the page you came from and the browser you use. We use the logs to keep the website running and secure and for simple visitor statistics, such as visits per page and country. We do not try to find out who you are. The legal basis is our legitimate interest in a secure, working website and in knowing how it is used. The logs are kept by the hosting provider and only for as long as they are needed for operations, security and statistics.

When we are in contact with you

We process what comes up in the contact – by email, by phone or in person – such as name, role, company, email address, phone number and the content of what we write or talk about:

  • Enquiries, proposals and other business contacts, including with partners and subcontractors: to respond and manage the contact (legitimate interest).
  • When we reach out to you: name, role and work contact details, from our network, your company's website or professional networks such as LinkedIn, to tell you what Transcendo can help with (legitimate interest). Tell us, and we will not contact you again.

Emails and notes belong to the matter or engagement they concern and are kept for as long as it is.

Work contact details of clients, former clients, partners and others we have come to know through our work are kept for as long as the relationship is current. Purchase cycles in our industry are long and new engagements often come from people we worked with several years ago, so we set no short outer limit. Instead, we review our contacts once a year and remove those who have left a role where working together is realistic and those we have had no contact with for five years. What we keep is name, role, company, work contact details and what we have done together – nothing private.

If we have reached out to someone we do not already know, without getting a reply, we keep the details for at most two years, so that we can follow up without starting from scratch.

If you tell us you do not want to hear from us, we remove you from the list and keep only what is needed to recognise you – name, company and email address – with a note that you do not wish to be contacted. We keep that for as long as it is needed to honour that promise.

Client engagements

For contact persons at our clients we process name, role, contact details, agreements and correspondence in order to prepare proposals, enter into and perform the engagement agreement, deliver and invoice. The legal basis is our legitimate interest when the client is a company or an organisation, and the agreement when you are the client yourself, for example as a sole trader. Invoices and other accounting records are kept until the end of the seventh year after the calendar year in which the financial year ended, as required by the Swedish Bookkeeping Act (legal obligation). Agreements and engagement documentation are kept for as long as they may be needed to show what was agreed and delivered, at most ten years after the end of the engagement.

In engagements we often get access to personal data about the client's employees, customers or suppliers, for example in analyses of operations and costs. We then process that data on the client's behalf: the client is the controller, we are the processor, and the client's instructions, our data processing agreement and the client's own privacy policy apply to that data. The same applies when we work as a subcontractor to another consulting firm – then its client, or the consulting firm, is responsible. When the engagement ends we return or delete the data as agreed.

We only put personal data from engagements into AI tools when the engagement agreement allows it and the provider is our data processor. Such material is deleted no later than 60 days after final delivery.

References

The testimonials on this website are published with the consent of the people quoted. If you are quoted and want your testimonial removed, email us and we will remove it.

Who receives the data?

We use a few providers that process data on our behalf: hosting of the website (Miss Hosting AB), email, calendar and documents (Microsoft 365), our accounting firm for annual accounts and tax returns, and other IT services and AI support. Some of them are run by US companies, so data may be transferred to the United States. The transfer is protected by the European Commission's standard contractual clauses and in some cases also by the EU–US Data Privacy Framework. Email us if you want to know who the providers are or how the transfer is protected.

In engagements we sometimes work with other consultants. We then share only the data needed for the engagement, and in line with the agreement with the client.

We do not sell personal data. Data may be disclosed if we are required to by law or by a decision of a public authority.

Your rights

You have the right to know what data we hold about you and to get a copy, to have errors corrected, to have data deleted or the processing restricted, to object to processing based on legitimate interest – and always to us contacting you with offers – and to receive data you have provided in a machine-readable format (data portability). You can withdraw consent at any time; this does not affect processing that has already taken place. Not all rights apply in every situation – we must keep accounting records, for example. Email info@transcendo.se. If you are not satisfied with how we handle your data, you can contact the Swedish Authority for Privacy Protection (IMY), imy.se.

Data we process on a client's behalf is the client's responsibility, so please contact the client in the first instance. You are welcome to contact us anyway, and we will help you on.