Legal & Privacy

Privacy Policy

This Privacy Policy explains how Accure AB collects, uses, stores, and protects personal data. Accure is committed to GDPR compliance and EU data residency for all processing activities.

Company: Accure AB · Org. 556667-0625 Effective: 1 June 2026 Replaces: Policy dated 2023-03-06 Contact: [email protected]
GDPR (EU 2016/679) compliant NIS2 (EU 2022/2555) compliant SOC 2 — Security & Confidentiality ISO 27001 certification in progress EU data residency — Azure Western Europe

1. Personal Data We Collect

Accure collects personal data through our interactions with you and through our products. What we collect depends on how you interact with us and which products you use. We collect data in three ways:

  • Data you provide directly: name, business email address, job title, company information, contact preferences, and communications with us.
  • Data collected automatically: when you use our products or visit our website, we may collect IP address, device type, browser type, pages visited, and interaction data (via cookies and similar technologies).
  • Data from third parties: information from Accure partners, event registrations, or publicly available professional profiles.

You may decline to provide personal data. Where the data is necessary to provide a service, we will inform you that the service cannot proceed without it.

2. How We Use Personal Data

Accure uses personal data for the following purposes:

  • Providing, operating, and improving our products and cloud services (ACS4M3, Accure Business Cloud, Accure Cloud Label)
  • Customer support, onboarding, and service delivery
  • Account management and user authentication
  • Sending product updates, security notices, and service communications
  • Marketing and promotional communications (where you have consented or have a legitimate interest)
  • Analysing product usage to improve performance and customer experience
  • Complying with legal obligations, including GDPR, NIS2, and Swedish law
  • Workforce analysis and HR administration for employees

3. Legal Basis for Processing

Accure processes personal data under one or more of the following legal bases established in GDPR Article 6:

  • Contract (Art. 6(1)(b)): Processing necessary to perform our agreement with you or to take pre-contractual steps.
  • Legitimate interest (Art. 6(1)(f)): Processing necessary for Accure's legitimate business interests, such as improving our services, fraud prevention, and security — where these are not overridden by your interests.
  • Legal obligation (Art. 6(1)(c)): Processing necessary to comply with applicable law (GDPR, NIS2, Swedish law, accounting regulations).
  • Consent (Art. 6(1)(a)): Where you have given explicit consent, such as for marketing communications or non-essential cookies. You may withdraw consent at any time.

4. How We Share Personal Data

Accure does not sell personal data. We share personal data only in the following circumstances:

  • Service providers and subprocessors: Microsoft Corporation (Azure hosting, Western/Northern Europe) and Creative Software Limited (technical and development support, Sri Lanka). All subprocessors are bound by data processing agreements with equivalent obligations to this policy.
  • Accure group companies: Where necessary to provide our services, with equivalent data protection obligations.
  • Legal requirements: Where required by applicable law, court order, or regulatory authority. We will notify you where legally permitted to do so.
  • Business transfers: In connection with a merger, acquisition, or sale of business assets, subject to confidentiality obligations.
Important: Where Accure acts as a data processor for our customers (e.g., processing M3 document data on behalf of an ACS4M3 customer), the customer is the data controller. Our Data Processing Agreement (DPA) governs that relationship. See accure.eu/dpa.

5. International Transfers of Data

Accure's primary data processing takes place within the EU/EEA — specifically on Microsoft Azure infrastructure in Western Europe (Netherlands) and Northern Europe (Ireland). We do not transfer personal data outside the EEA without appropriate safeguards.

Where transfers to third countries are required (e.g., technical support from Sri Lanka via Creative Software Limited), we use Standard Contractual Clauses (SCCs) as approved by the European Commission. Full details are set out in our DPA Annex I.

For UK-based customers, transfers from the UK are covered by the UK ICO-approved Addendum to the EU SCCs.

6. Data Retention

We retain personal data for as long as necessary to fulfil the purposes for which it was collected, subject to the following principles:

  • Customer and contract data: Retained for the duration of the business relationship, plus the period required by applicable accounting, tax, and legal obligations (typically 7 years under Swedish law).
  • User account data: Inactive accounts are disabled after 45 days of inactivity. Disabled accounts are deleted or archived after 90 days unless a legal hold applies.
  • Access logs: Retained for a minimum of 12 months, or longer if required by contract or regulation.
  • Transactional output data: Default retention target of 30 days for transactional data in ACS4M3. Customers are notified 30 days before deletion. Extended retention available by agreement.
  • Marketing data: Retained until you withdraw consent or request erasure.

When data is no longer required, it is securely deleted in accordance with industry best practices, and a destruction record is maintained.

7. Your Rights Under GDPR

You have the following rights regarding your personal data, subject to applicable legal exceptions:

  • Access (Art. 15): Request a copy of the personal data we hold about you.
  • Rectification (Art. 16): Request correction of inaccurate or incomplete data.
  • Erasure (Art. 17): Request deletion of your personal data ("right to be forgotten").
  • Restriction (Art. 18): Request that we limit processing of your data in certain circumstances.
  • Portability (Art. 20): Receive your data in a structured, machine-readable format.
  • Objection (Art. 21): Object to processing based on legitimate interest or for direct marketing.
  • Withdraw consent: Withdraw consent at any time where processing is consent-based.

To exercise your rights, contact us at [email protected]. We will respond within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with your national data protection authority. In Sweden: Integritetsskyddsmyndigheten (IMY).

8. Security Measures

Accure implements appropriate technical and organisational measures to protect personal data, proportionate to the risk. Our security posture includes:

  • All data encrypted at rest (AES-256) and in transit (TLS 1.2+)
  • Multi-factor authentication (MFA) on all access paths
  • Role-based access control (RBAC) — least-privilege enforcement
  • 24/7/365 automated monitoring and incident response
  • Regular vulnerability scanning and security auditing
  • Annual security awareness training for all staff and contractors
  • Personal data breach notification within 24 hours of becoming aware (GDPR Art. 33)
  • SOC 2 Type II compliance — independently audited security controls
  • NIS2 Directive (EU 2022/2555) compliant operations
  • ISO/IEC 27001 certification in progress

Full technical and organisational security measures are described in the DPA Annex II at accure.eu/dpa.

9. Cookies and Tracking Technologies

Accure's website uses cookies and similar technologies. We use:

  • Strictly necessary cookies: Required for the website to function. No consent required.
  • Preference cookies: Remember your settings and choices. Require consent.
  • Analytics cookies: Help us understand how visitors use our website (e.g., Google Analytics). Require consent. Data is anonymised where possible.
  • Marketing cookies: Used to show relevant advertising. Require explicit consent.

You can manage cookie preferences at any time using our cookie consent tool. For full details, see our Cookie Policy.

10. Compliance, Certifications and Regulatory Framework

Accure's privacy and data protection practices are aligned with the following regulatory frameworks and standards:

  • GDPR (EU 2016/679): The General Data Protection Regulation is the primary legal framework governing Accure's processing of personal data in the EU/EEA.
  • NIS2 Directive (EU 2022/2555): Accure complies with the NIS2 requirements for network and information security, incident reporting, and supply chain security applicable to our operations and services.
  • SOC 2 Type II: Accure is SOC 2 compliant across the Trust Services Criteria for Security, Availability, and Confidentiality — independently audited.
  • ISO/IEC 27001: Formal ISO 27001 certification of Accure's Information Security Management System is currently in progress.
  • Microsoft Azure compliance: Accure inherits Azure's compliance posture including ISO 27001, ISO 27017, ISO 27018, SOC 1/2/3, and the EU Data Boundary commitment.
  • Swedish law: As a Swedish company (Accure AB, org. 556667-0625), Accure also complies with Swedish data protection law as implemented by IMY.

11. Job Applicants

If you apply for a position at Accure, we collect the personal data you provide in your application (CV, cover letter, contact details, qualifications). We use this data to evaluate your application, make employment decisions, and for workforce planning. Your data may be shared with employment screening or background check services where applicable and with your consent.

Application data is retained for up to 24 months after the conclusion of the recruitment process, to allow us to consider you for future roles if appropriate. If you do not wish your data to be retained beyond the active recruitment process, please notify us at [email protected].

12. Updates to This Policy

Accure reviews and updates this Privacy Policy at least annually, or when there are material changes to our processing activities or applicable law. If we make significant changes, we will notify you by email or by posting a prominent notice on our website. The effective date at the top of this policy indicates when it was last updated.