Legal
Privacy Policy
What personal data we handle, in which role, and why the answer for your CRM data is "we read it and never keep it".
Version 1.2 · In force from 24 August 2026.
The short version
- We do not store your CRM data. Contacts, companies, deals and activity are read on demand and discarded when you close the chart.
- What we store about your organisation is an encrypted access token, your portal's configuration, who holds a seat, and subscription status.
- Our systems run in the EU (Azure, Sweden Central). Billing runs through Stripe.
- This website sets no cookies, runs no analytics and loads nothing from a third party.
- We do not sell personal data, and we do not use your data to train AI models.
1. Who is responsible
| Legal entity | Lucas Rehn (sole trader, enskild firma), trading as Rehnable |
| Organisation number | 199905287398 |
| VAT number | SE990528739801 |
| Address | Hagarydsvägen 41, 586 63 Linköping, Sweden |
| Privacy contact | hello@rehnable.com |
We act in two different roles, and the distinction matters for your rights:
- As controller for the personal data we handle to run our own business — the people who contact us, administrators of customer accounts, and billing contacts. Sections 2–8 cover this.
- As processor for the personal data in your HubSpot account that Rehnable reads and writes on your instruction. You are the controller of that data. Section 9 and the processing terms cover this.
2. What we process as controller
| Category | Data | Source |
|---|---|---|
| Contact and correspondence | Name, email address, company, and the content of what you write to us | You, by emailing us |
| Account administration | HubSpot portal ID, HubSpot user IDs of seat holders, and the name and email address shown for those users when an administrator assigns seats | Your HubSpot account, via the API |
| Billing | Billing contact, company details, VAT number, subscription status and invoice history. Card details are handled by Stripe and never reach us | You, through Stripe checkout |
| Technical logs | Request metadata, timestamps, error information, portal ID. Logs do not contain CRM record content | Generated when the service runs |
3. Why, and on what legal basis
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Providing the service, authenticating users, managing seats | Performance of a contract (Art. 6.1 b), or our legitimate interest in serving our business customer (Art. 6.1 f) |
| Support and correspondence | Legitimate interest in answering the people who contact us (Art. 6.1 f) |
| Billing and payment | Performance of a contract (Art. 6.1 b) and legal obligation (Art. 6.1 c) |
| Accounting records | Legal obligation — Swedish Bookkeeping Act (Art. 6.1 c) |
| Security, error diagnosis, abuse prevention | Legitimate interest in a secure and functioning service (Art. 6.1 f) |
| Service announcements to administrators | Legitimate interest in informing customers of changes that affect them (Art. 6.1 f) |
We do not use your data for advertising, we do not profile you, and we do not make automated decisions with legal effect about anyone.
4. What we never store
This list is part of the architecture, not a policy promise that could quietly change — the application has no database table for any of it:
- Contact records, names or email addresses from your CRM
- Company records and their properties
- Deals, amounts, stages or forecasts
- Emails, calls, meetings or any activity content
- The org chart structure itself — it lives in your HubSpot account as associations
- Team assignments — they live on your contacts as a property
- Payment card details
If our database were fully compromised, an attacker would learn which HubSpot accounts use Rehnable and which user IDs hold seats. They would not obtain your customers' records.
5. Recipients and subprocessors
| Provider | Purpose | Location |
|---|---|---|
| Microsoft Azure (Microsoft Ireland Operations Ltd) | Hosting of the application, database and encryption keys | Sweden Central, EU |
| Stripe | Payment processing and subscription management | EU/US, under the safeguards described below |
HubSpot is not our subprocessor. HubSpot is your provider under your contract; Rehnable accesses your HubSpot account with the authorisation you grant at installation.
Otherwise we disclose personal data only where required by law, or to professional advisers under a duty of confidentiality. We do not sell personal data, and we do not use it to train AI models.
6. Transfers outside the EU/EEA
Our own infrastructure is in the EU. Payment processing through Stripe may involve processing outside the EU/EEA; where it does, transfers rely on the European Commission's Standard Contractual Clauses or another valid transfer mechanism under Chapter V of the GDPR. No CRM data is transferred to Stripe under any circumstances — Stripe receives billing data only.
7. How long we keep things
| CRM data | Not retained at all — read on demand, held in the browser while the chart is open |
| Access token for your account | Deleted when we see the uninstall in HubSpot's app-lifecycle journal, normally within about a minute; if that check fails, at the next refusal to renew the credential instead |
| Portal configuration and seats | While you are installed, and afterwards so a reinstall works — deleted on request |
| Correspondence | Up to 24 months after the last message, unless it is part of a contractual record |
| Accounting records | Seven years, as required by the Swedish Bookkeeping Act |
| Technical logs | Short-lived operational retention, normally under 90 days |
8. Security
- Access tokens are encrypted at rest (AES-GCM) with keys held in Azure Key Vault, and are never sent to the browser.
- All traffic runs over TLS.
- Authentication is delegated to HubSpot: the editor session starts from a request HubSpot itself signed, validated on our servers.
- Access to production systems is limited to the personnel who operate the service, which at present means one person.
- We do not hold ISO 27001 or SOC 2 certification, and we say so rather than implying otherwise. The primary control is architectural: the sensitive data never arrives.
Report a suspected vulnerability to hello@rehnable.com. We will confirm receipt, work the issue, and tell you what we did.
9. Cookies and tracking
This website sets no cookies, runs no analytics, embeds no fonts, scripts or images from third parties, and does not track you across sites. There is no consent banner because there is nothing to consent to.
The application itself uses two strictly necessary mechanisms, and nothing else:
- a short-lived cookie during the installation flow, to protect that flow against cross-site request forgery;
- a session token that authenticates your editor session while it is open.
10. Your rights
Where we are the controller, you may request access to your personal data, rectification, erasure, restriction of processing, portability, and you may object to processing based on legitimate interest. Contact hello@rehnable.com and we will respond within one month.
If your data is in a customer's HubSpot account — for example if you are a contact belonging to a company that uses Rehnable — that company is the controller. Direct your request to them; we will assist them, but we cannot act on their data without their instruction, and we hold no copy of it.
You may lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, or with the supervisory authority in your own country.
11. Data processing terms (GDPR Article 28)
These terms apply where we process personal data on behalf of a customer, and form part of the terms of service. A separate signable data processing agreement with the same content is available on request.
11.1 Subject matter and duration
Processing consists of reading personal data from the customer's HubSpot account to render an org chart, and writing changes to that account when a user of the customer performs an action. Processing lasts for as long as Rehnable is installed.
11.2 Nature, purpose and scope
Reading, structuring and displaying contact, company and deal data; writing associations, property values, lists and tasks. No storage of customer personal data takes place on the processor's systems. Data is retrieved for a request, delivered to the authorised user's browser, and not persisted.
11.3 Categories of data subjects and data
Data subjects: the customer's business contacts, and the customer's own users. Data: name, job title, business email and phone as present in the customer's CRM, buying role, activity timestamps, deal associations, reporting relationships, team assignment, and HubSpot user identifiers. The customer determines what its CRM contains and must not use Rehnable to process special categories of personal data (Art. 9).
11.4 Instructions
We process personal data only on the customer's documented instructions, of which these terms and the customer's use of the application are the instruction, unless required otherwise by EU or member state law — in which case we inform the customer before processing, unless that law forbids it. We will inform the customer if we consider an instruction to infringe data protection law.
11.5 Confidentiality
Personnel authorised to process personal data are bound by confidentiality and are limited to those who need access to operate the service.
11.6 Security
We implement appropriate technical and organisational measures under Article 32, including encryption of stored credentials, TLS in transit, signed-request authentication, least-privilege API permissions, and — most significantly — an architecture that does not persist customer personal data.
11.7 Subprocessors
The customer gives general authorisation for the subprocessors listed in section 5. We will give at least 30 days' notice before adding or replacing a subprocessor, during which the customer may object on reasonable data protection grounds; if the objection cannot be resolved, the customer may terminate the affected service without penalty. We impose data protection obligations on each subprocessor equivalent to those in these terms and remain liable for their performance.
11.8 Assistance
Taking into account the nature of the processing, we assist the customer with data subject requests, with security, breach notification and impact assessments under Articles 32–36. In practice, because we hold no copy of the customer's data, requests are fulfilled by the customer inside HubSpot.
11.9 Personal data breach
We notify the customer without undue delay and no later than 72 hours after becoming aware of a personal data breach affecting their data, with the information available at the time and updates as the investigation proceeds. Notification goes to the account administrators and to any security contact the customer has given us.
11.10 Deletion and return
On termination we delete the customer's stored access token. Since no customer personal data is stored, there is nothing further to return or delete; portal configuration is deleted on request. The customer's own data remains in the customer's HubSpot account, under the customer's control.
11.11 Audit
We make available the information necessary to demonstrate compliance with Article 28, and we allow for and contribute to audits conducted by the customer or an auditor it mandates.
In the first instance an audit is satisfied by documentation: written answers to a security questionnaire, a description of the measures in place, and the information on our security page. Where the customer can reasonably show that this is not sufficient to demonstrate compliance, an inspection may be conducted — on at least 30 days' written notice, no more than once a year unless a personal data breach or a supervisory authority requires otherwise, during normal working hours, without disrupting the service, and subject to confidentiality. The customer bears its own costs for an inspection.
12. Changes to this policy
We may update this policy. Material changes are notified by email to account administrators or in the application at least 30 days in advance. The version and date at the top of this page identify what is in force.
13. Contact
hello@rehnable.com — privacy questions, data subject requests, DPA requests and security reports all reach the same place, and a person reads them.