ReadyCMS 3.0.63 is live. · Read the changelog

ReadyCMS Privacy policy

ReadyCMS – Privacy Policy


Last updated: 14 May 2026
Version: 2.0
Replaces: the version dated 20 March 2023


This Privacy Policy explains how ReadyCMS AB ("ReadyCMS", "we", "us", "our") processes personal data when you visit our website, use the ReadyCMS platform, or otherwise interact with us. It is published in accordance with Articles 13 and 14 of Regulation (EU) 2016/679 (the "GDPR") and the Swedish Data Protection Act (Dataskyddslagen, SFS 2018:218).

If you are an end-user of an online store, booking system, or other website operated by one of our customers using the ReadyCMS platform, please read the section [When ReadyCMS acts as a processor on behalf of our customers] below. In that case, the operator of the website you are visiting is the controller of your data, not ReadyCMS, and you should consult that operator's own privacy notice in the first instance.

1. Controller identity and contact



 Controller  ReadyCMS AB
 Organisation number 559423-1010
 VAT SE559423101001
 Registered office Rymdtorget 50 Lgh 1302, 415 65 Göteborg, Sweden
 Website https://www.readycms.io
 General contact info@readycms.io
 Privacy contact privacy@readycms.io
 Security contact support@readycms.io

Data Protection Officer

ReadyCMS has assessed the criteria set out in Article 37(1) GDPR and has not designated a formal Data Protection Officer at the time of publication. The reasoning is documented internally and available to the Swedish Authority for Privacy Protection (IMY) on request. For all matters relating to the processing of personal data, please contact privacy@readycms.io, our central data-protection point of contact.

2. Scope of this Policy

This Policy covers two distinct roles in which ReadyCMS processes personal data:

a) As a controller — for visitors to our website, prospects, customers (and their representatives), support contacts, applicants, and recipients of our communications. Sections 3 to 12 below describe this processing.

b) As a processor — for personal data that our customers upload to, or generate within, the ReadyCMS platform when running their own online stores or websites. That processing is governed by the [Data Processing Agreement (DPA)](/legal/dpa/) and by each customer's own privacy notice, not by this Policy. See section 13 for a short summary.

3. Categories of personal data and sources

When acting as a controller, we process the following categories of personal data:

  • Identity and contact data: name, business email, business phone number, company name, role, country, billing address.
  • Account and authentication data: username, hashed password, two-factor authentication status, last login timestamps, and IP addresses used for authentication.
  • Billing and financial data: invoices, payment method tokens (the underlying card data is held by Stripe, not by us), VAT number, transaction history, subscription tier, and currency.
  • Communication data: support tickets, chat transcripts, email correspondence, attachments you send us, and scheduling information.
  • Website and usage data: pages visited, referrer, user-agent, IP address, approximate location derived from IP, cookies, and similar technologies (see our [Cookie Policy](/legal/cookies/)).
  • Marketing data: consent state, opt-in source, interaction with marketing emails (opens and clicks where measurable), and advertising audience identifiers when consented.
  • Recruitment data (only if you apply for a role): CV, cover letter, references, interview notes.

We collect this data either directly from you (when you sign up, contact us, or interact with our site) or, in limited cases, from public sources (LinkedIn, your company website) when we have a legitimate interest in prospecting.

We do not intentionally process special categories of personal data under Article 9 GDPR (data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic data, biometric data, health data, or data concerning sex life or sexual orientation). Please do not submit such data to us; if you do, we will delete it on becoming aware of it.

4. Purposes of processing and legal bases

The table below sets out each purpose for which we process personal data, the legal basis under Article 6(1) GDPR that we rely on, and the categories of data involved.

 Purpose  Legal basis  Categories used
 
 
 
 Providing the ReadyCMS service to customers (account creation, login, configuration, support)  Contract — Art. 6(1)(b) Identity, account, communication
 Billing, invoicing, tax reporting Legal obligation — Art. 6(1)(c) (Bokföringslagen 1999:1078) and contract — Art. 6(1)(b) Identity, billing
 Responding to inquiries from prospects and the public Legitimate interest — Art. 6(1)(f): responding to a question is in the requester's own interest Identity, communication
 Outbound marketing emails to existing customers about closely related services Legitimate interest — Art. 6(1)(f) with opt-out (Art. 21 GDPR; LEK 2003:389 §19) Identity, marketing
 Outbound marketing emails to non-customers Consent — Art. 6(1)(a) Identity, marketing
 Operating our website, security logging, and anti-abuse Legitimate interest — Art. 6(1)(f): keeping the service available and secure Website/usage
 Cookies and similar technologies that are not strictly necessary Consent — Art. 6(1)(a), via the cookie banner Website/usage, marketing
 Statistics about how the marketing site is used Consent — Art. 6(1)(a) (Google Analytics) Website/usage
 Recruitment Legitimate interest — Art. 6(1)(f) (filling a vacancy) or consent — Art. 6(1)(a) (kept on file for future roles) Recruitment 
 Fraud prevention, abuse handling, network, and information security Legitimate interest — Art. 6(1)(f) and legal obligation under NIS2 / SFS 2025:18 where applicable Identity, account, website/usage
 Establishing, exercising, or defending legal claims Legitimate interest — Art. 6(1)(f) All categories as relevant
 Complying with lawful requests from public authorities Legal obligation — Art. 6(1)(c) All categories as relevant

Where the legal basis is legitimate interest, you have the right under Article 21 GDPR to object — see section 9.

Where the legal basis is consent, you can withdraw your consent at any time without affecting the lawfulness of processing carried out before the withdrawal. To withdraw consent, email privacy@readycms.io or use the link in any marketing email.

5. Whether providing personal data is required

When you become a customer or open a paid account, certain personal data is required to enter into and perform the contract (identity and billing). If you do not provide it, we cannot conclude the contract.

Billing data is also necessary for us to comply with Swedish bookkeeping law.

All other processing is either based on legitimate interest (where you may object) or your consent (which you may decline or withdraw without consequence for our contract with you).

6. Recipients and categories of recipients

We share personal data only as follows:

  • Within ReadyCMS AB — with personnel who need it to perform their role and who are bound by confidentiality.
  • With sub-processors and service providers that act on our documented instructions. The current list, including jurisdictions and transfer mechanisms, is published at [/legal/sub-processors/](/legal/sub-processors/). We notify customers at least 30 days before adding or replacing a sub-processor that processes their data.
  • With professional advisers (auditors, lawyers, accountants) bound by their own professional confidentiality obligations.
  • With public authorities and courts, where required by law or in response to a valid legal request.
  • In a corporate transaction — if ReadyCMS is involved in a merger, acquisition, restructuring, or asset sale — personal data may be transferred to the counterparty, subject to equivalent confidentiality and data-protection obligations.

We do not sell personal data. We do not share personal data for advertising or analytics purposes other than as disclosed in our Cookie Policy and after obtaining the relevant consents.

7. International transfers

Customer-facing platform data is stored on Hetzner servers located in Germany. However, some of our sub-processors are established outside the European Economic Area, in particular in the United States.

When we transfer personal data outside the EEA, we rely on one of the following safeguards from Chapter V GDPR, in this order of preference:

  1. Adequacy decisions — for example, the EU–US Data Privacy Framework (Decision (EU) 2023/1795), where the recipient is certified.
  2. Standard Contractual Clauses (SCCs) — Decision (EU) 2021/914, supplemented by a transfer impact assessment and any additional safeguards required by the EDPB's Recommendations 01/2020.
  3. Derogations under Article 49 GDPR — only in limited and documented circumstances.

The specific transfer mechanism applicable to each sub-processor is shown on our [Sub-processors page](/legal/sub-processors/). A copy of the SCCs we use is available on request from privacy@readycms.io.

8. Retention periods

We retain personal data only for as long as it is necessary for the purpose for which it was collected, after which it is deleted or anonymized. Specific retention periods are:

 Category  Period 
 
 
 Account and authentication data  For the duration of the account, then 30 days after termination for backup-rotation reasons
 Customer billing records, invoices, receipts  7 years after the end of the financial year (Bokföringslagen 1999:1078 §10)
   24 months after the ticket is closed
 Marketing email opt-ins  Until consent is withdrawn, then 30 days for evidence of withdrawal
 Marketing prospect data (no consent obtained yet)  Maximum 12 months from collection
 Server access logs and security logs  90 days 
 Backups (full snapshot rotation)  30 days
 Unsuccessful job applications  24 months after the recruitment process closes, then deleted (longer only with the applicant's explicit consent)
 Records of consent  5 years after the consent is withdrawn or expires
 Data needed to establish, exercise, or defend legal claims  Until the statute of limitations expires (up to 10 years for civil claims under Preskriptionslagen 1981:130)

Where personal data is processed under more than one purpose, the longest applicable retention period applies. Where a legal obligation requires longer retention than indicated above, the legal obligation prevails.

9. Your rights

Under Articles 15–22 GDPR, you have the following rights:

  • Right of access (Art. 15) — to obtain confirmation of whether we process your personal data and a copy of it.
  • Right to rectification (Art. 16) — to have inaccurate data corrected and incomplete data completed.
  • Right to erasure / "right to be forgotten" (Art. 17) — to have your data deleted in the circumstances listed in that Article.
  • Right to restriction of processing (Art. 18) — to limit how we process your data while a dispute is resolved.
  • Right to data portability (Art. 20) — to receive the personal data you provided to us in a structured, commonly used, machine-readable format and to have it transmitted to another controller.
  • Right to object (Art. 21) — at any time, on grounds relating to your particular situation, to processing based on legitimate interest; and without justification to processing for direct-marketing purposes.
  • Right to withdraw consent (Art. 7(3)) where processing is based on consent.
  • Right not to be subject to a decision based solely on automated processing (Art. 22) — see section 11.

To exercise any of these rights, contact privacy@readycms.io. We will respond within one month of receipt of a verifiable request (extendable by two further months for complex or numerous requests under Art. 12(3)). We may request information to verify your identity before acting on a request.

If we cannot identify you from the information available, we may ask for additional information; if we still cannot identify you, we may refuse to act on the request (Art. 11/12).

10. Right to complain to a supervisory authority

You have the right to lodge a complaint with a data-protection supervisory authority. The Swedish authority is:

Integritetsskyddsmyndigheten (IMY)

Box 8114, 104 20 Stockholm, Sweden

imy@imy.se · +46 8 657 61 00

https://www.imy.se

You may also lodge a complaint with the supervisory authority in the EU/EEA Member State of your habitual residence, place of work, or the place of the alleged infringement.

11. Automated decision-making and profiling

ReadyCMS does not subject customers or website visitors to any decision based solely on automated processing, including profiling, that produces legal effects concerning them or similarly significantly affects them within the meaning of Article 22 GDPR.

We do operate automated technical processes — for example, automated fraud scoring for new sign-ups and automated rate limiting at our web edge — but these do not, by themselves, produce binding decisions; any consequential action (such as terminating an account) is reviewed by a person.

12. Cookies and similar technologies

Our use of cookies, local storage, pixels, and similar technologies is described in our separate [Cookie Policy](/legal/cookies/). The cookie banner displayed when you first visit our website allows you to accept or reject each non-essential category individually, and you can change your choices at any time via the "Cookie settings" link in the footer.

13. When ReadyCMS acts as a processor on behalf of our customers

The ReadyCMS platform hosts e-commerce stores and similar websites for our customers. When an end-user (you) interacts with one of those customer-operated sites, the operator of that site is the controller of your personal data. ReadyCMS is the processor and acts only on the operator's documented instructions under the [Data Processing Agreement](/legal/dpa/).

In that capacity, we will typically process, on the operator's behalf, data such as:

  • Order and transaction data (items, prices, currency, fulfillment status)
  • Customer name, billing, and delivery address
  • Email address and phone number
  • IP address and basic device information
  • Where the operator has enabled the relevant features: visitor analytics, session-level interaction data, and form-input capture for diagnostics

Please direct requests to exercise your data-subject rights to the operator of the website where you made the purchase or interaction. If you have first contacted the operator and not received a satisfactory response, you may also contact us at privacy@readycms.io, and we will assist the operator in handling your request.

14. Security

We maintain technical and organizational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access. A high-level description is published on our [Trust page](/trust/). Customer-specific measures are described in Annex II of our DPA.

15. Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. The "Last updated" date at the top of the Policy indicates when the most recent change was made. For material changes, we will give existing customers at least 30 days' notice by email before the change takes effect.

Previous versions of this Policy are available on request from privacy@readycms.io.

16. Contact

For any question or request relating to this Policy or to your personal data:

ReadyCMS AB

Att: Privacy

Rymdtorget 50 Lgh 1302, 415 65 Göteborg, Sweden

privacy@readycms.io