RoshaLink Logo
RoshaLink Logo
ROSHALINK

Bridging the gap between rigorous business analysis and cutting-edge product development.

support@roshalink.com0724453332

Navigation

  • Home
  • Portfolio
  • Services
  • About Us
  • Contact

Capabilities

  • Strategic Design
  • Product Development
  • Cloud & Architecture
  • AI & Business Intelligence
  • Design Systems

Stay Updated

Get quarterly strategic insights and technical briefs.

© 2026 RoshaLink. All rights reserved.
Terms of ServiceSecurity Specification
GDPR & DATA PROTECTION ACT

Privacy Policy (Full Legal Version)

We are committed to safeguarding your personal data with the highest security standards, full transparency, and full compliance with the EU General Data Protection Regulation (GDPR).

Last Updated: August 10, 2026

1. Introduction

This Privacy Policy ("Policy") explains how RoshaLink ("Company", "we", "us", or "our") collects, uses, stores, shares, and protects personal data in connection with our IT development, software applications, infrastructure services, and integrated digital platforms. We are committed to respecting your privacy and protecting your personal data in full compliance with Regulation (EU) 2016/679 ("GDPR"), the Swedish Data Protection Act (Lag 2018:218), and all applicable laws. By using our services, accessing our applications, or entering into a contract with us, you acknowledge that you have read and understood this Privacy Policy.

2. Personal Data We Collect

We collect only personal data strictly necessary to fulfill contractual and legal obligations, maintain system security, and operate and enhance IT services: • Contact & Identity Data: Name, email address, phone number, job title, company name, billing address, IP address. • Account & Authentication Data: Usernames, encrypted passwords, security logs, authentication tokens, user preferences. • Technical Logs & Device Data: IP addresses, browser type, OS, resolution, timestamps, crash reports, performance metrics. • Communication Data: Messages, support tickets, inquiries sent via email, contact forms, or AI widgets (Rosha AI Assistant). • Integration & Telemetry Data: Telemetry and interaction logs generated during software and platform execution.

3. How We Use Your Information

We process personal data for explicit, legitimate purposes: 1. Service Delivery & Operation: Deliver, configure, maintain, and administer software solutions, websites, and user accounts. 2. Customer Support & Communication: Process support tickets, send technical notices, updates, and administrative news. 3. Security & System Integrity: Monitor infrastructure stability, prevent unauthorized access, mitigate cyber threats, perform debugging. 4. Optimization of Integrated Workflows: Ensure flawless functionality across workflows integrating 250+ cloud infrastructure services, AI platforms, and design tools. 5. Analytics & Product Enhancement: Analyze usage trends, optimize UI performance, and build new capabilities. 6. Legal Compliance: Comply with statutory duties under financial accounting laws, tax regulations, and lawful authority requests.

4. Legal Bases for Processing

We process personal data based on Article 6 GDPR legal grounds: • Performance of a Contract (Art. 6.1(b) GDPR): Necessary to execute or perform a contract with you or your entity. • Legal Obligation (Art. 6.1(c) GDPR): Necessary to comply with statutory legal duties (e.g., Swedish Bookkeeping Act 1999:1078). • Legitimate Interests (Art. 6.1(f) GDPR): Based on legitimate interests in providing secure, high-performance IT solutions and preventing fraud. • Consent (Art. 6.1(a) GDPR): Where required by law (e.g., non-essential cookies), we obtain prior explicit consent. You may withdraw consent at any time.

5. Data Sharing & Third-Party Integrations

We NEVER sell your personal data. As an advanced IT development firm, we seamlessly integrate 250+ cloud services, AI platforms, database systems, CDN providers, and design software tools. We share data only with: • Processors & Cloud Providers: Cloud infrastructure (AWS, Google Cloud), AI APIs (OpenAI, Anthropic), analytics and monitoring tools bound by strict DPAs (Art. 28 GDPR). • Public Authorities: When mandated by applicable law, court order, or lawful authority request. • Professional Advisors: Legal counsel, auditors, and financial accountants bound by confidentiality obligations.

6. International Data Transfers

Our servers and vendors may be located both inside and outside the European Economic Area (EEA). Whenever data is transferred outside the EEA to countries lacking an EU adequacy decision, we enforce Chapter V GDPR safeguards: • Executing European Commission approved Standard Contractual Clauses (SCCs) under Art. 46 GDPR. • Verifying certification under the EU-U.S. Data Privacy Framework. • Implementing technical safeguards like end-to-end encryption and pseudonymization.

7. Data Retention

We retain personal data only for as long as necessary or legally required: • Customer & Contractual Data: Retained for the contract duration plus up to 7 years post-termination (Swedish Bookkeeping Act 1999:1078). • Technical Logs & Security Audits: Retained for 30 days to 12 months, then automatically purged or anonymized. • Support & Correspondence: Retained for up to 3 years following ticket resolution. Expired data is permanently deleted or rendered strictly anonymous.

8. Your Rights Under GDPR

Under GDPR, data subjects possess the following rights: • Right of Access (Art. 15): Request confirmation of processing and obtain a copy of your personal data. • Right to Rectification (Art. 16): Request correction of inaccurate or incomplete personal data. • Right to Erasure / "Right to be Forgotten" (Art. 17): Request deletion of personal data under statutory conditions. • Right to Restriction (Art. 18): Request limitation of processing activities. • Right to Data Portability (Art. 20): Receive personal data in a structured, machine-readable format. • Right to Object (Art. 21): Object to processing based on legitimate interests or direct marketing. • Right to Lodge a Complaint: File a complaint with the lead supervisory authority (Integritetsskyddsmyndigheten - IMY, www.imy.se).

9. Cookies and Tracking Technologies

We utilize cookies to guarantee website stability, evaluate performance metrics, and enhance user navigation: • Essential Cookies: Mandatory for security, authentication, and core functionality. Cannot be disabled. • Analytics & Performance Cookies: Collect anonymized usage statistics to optimize speed and rendering. • Functional Cookies: Store preferences like language and theme configurations. You may adjust or revoke cookie consent at any time via browser settings.

10. Security Measures

We enforce robust technical and organizational security controls: • Encryption: Data in transit is protected via TLS 1.3; data at rest is encrypted using AES-256 standards. • Access Control: Zero-Trust architecture and Principle of Least Privilege (PoLP) strictly enforced across all accounts. • Security Hardening: Automated vulnerability scanning, intrusion detection systems, alignment with ISO 27001 standards.

11. Contact Information

For privacy inquiries or exercising GDPR rights, contact our Privacy Officer: • Entity: RoshaLink IT Infrastructure • Privacy Email: contact@roshalink.com • Website: https://roshalink.com • Address: RoshaLink IT Operations, Stockholm, Sweden (Global Engineering Operations)

12. Changes to This Privacy Policy

We reserve the right to revise this Privacy Policy to reflect technical advancements, legal updates, or operational changes. Material revisions will be notified via prominent website banners or email prior to taking effect.
Data Protection Officer (DPO)

Questions about GDPR or data privacy?

Our privacy engineering team normally responds within 24 hours. Reach out directly at privacy@roshalink.com.

Contact DPO