Legal
Privacy Notice
Last updated August 15, 2026
This notice explains how Connectivo AB processes personal data when you visit, contact, register for, or use REPOSS.
Who is responsible
Connectivo AB operates REPOSS and is the controller for account, contact, commercial, security, and service-administration data that we process for our own purposes.
When REPOSS processes transaction or customer evidence on behalf of a subscribing company, Connectivo AB normally acts as that company’s processor under the applicable data-processing terms.
Data we process
Account and company data includes names, business contact details, organisation and VAT identifiers, memberships, roles, authentication settings, login and security events, and support correspondence.
Service data includes the minimum order, invoice, refund, product, country, currency, VAT, date, source-reference, and classification facts required to provide the OSS workflow. Connected credentials are encrypted and are not exposed in application responses or logs.
Commercial and technical data includes plan and subscription state, Stripe references, synchronization diagnostics, correlation identifiers, device and request information, and the necessary cookies described on the Cookies page. REPOSS does not store payment-card details.
Why we process it
We process data to provide and secure REPOSS, authenticate users, maintain company access, synchronize authorized sources, validate and compile OSS evidence, support customers, administer subscriptions, prevent misuse, meet legal obligations, and preserve required audit records.
Depending on the context, the legal basis is performance of a contract, steps requested before entering a contract, compliance with legal obligations, or our legitimate interest in providing and protecting the service. We ask for consent where the law requires it.
Connected sources and service providers
REPOSS communicates with a connected commerce or accounting provider only when an authorized company configures that connection. Provider credentials and access remain subject to that provider’s terms and privacy practices.
We use carefully selected infrastructure, communications, support, and billing providers where needed to operate REPOSS. Stripe processes checkout and payment information under its own privacy notice. Providers receive only the data required for their role and are bound by appropriate contractual and security obligations.
If a provider processes data outside the EU or EEA, we use an applicable lawful transfer mechanism and supplementary safeguards where required.
Retention
Structured OSS evidence may need to be retained for ten years from the end of the calendar year in which the underlying transaction occurred. Filed snapshots and their audit evidence remain immutable during the applicable retention period.
Uploaded SIE source files, operational diagnostics, account data, support records, and commercial records follow separate purpose-based retention periods. We remove or anonymize data when it is no longer required, unless law, an active legal hold, security needs, or a continuing customer instruction requires retention.
Security
REPOSS uses tenant isolation, role-based access, encrypted credentials and private files, optional two-factor authentication, audit records, request protections, data minimization, and controlled support access. No security measure eliminates every risk, and customers must protect their own accounts and authenticator recovery information.
Your rights and contact
Depending on applicable law, you may request access, correction, deletion, restriction, portability, or an objection to processing. Some rights can be limited where data must be retained for legal, contractual, security, or audit reasons.
Contact hello@reposs.se for privacy questions or requests. You may also complain to Integritetsskyddsmyndigheten (IMY) if you believe personal data has been handled incorrectly.
Changes to this notice
We update this notice when the service, providers, or legal requirements change. Material changes will be communicated through an appropriate service or account channel.
