Privacy policy

Zomiro AB cares about your privacy. This policy describes how we process personal data in accordance with the EU General Data Protection Regulation (GDPR).

Data controller
Zomiro AB, reg. no. 559566-1926. The easiest way to reach us is via the contact form on the website.

What we collect
- **Bookings and contact forms:** name, email, phone number, requested location and date, and whatever you write in the message.
- **Client accounts:** name, email, phone number and an encrypted password (passwords are never stored in plain text).
- **Photographs:** images from sessions constitute personal data and are handled with particular care.
- **Technical:** a necessary session cookie when signing in. We use no third-party tracking.

Why we process the data
- To answer enquiries and administer bookings (legal basis: contract and legitimate interest).
- To deliver photos, booking overviews and invoices in the client portal (contract).
- To meet the requirements of the Swedish Bookkeeping Act (legal obligation).

Retention
- Contact and booking enquiries: at most 24 months.
- Customer records and invoicing data: 7 years under the Bookkeeping Act.
- Photographs: as long as required for delivery and agreed storage; portfolio images only with consent.
- Client accounts: until you request deletion.

Who receives the data
Data is shared only with the providers required for operation: web hosting (within the EU), the transactional email provider and file storage (our own Nextcloud server). Data is never sold.

Your rights
You may request access, rectification, erasure, restriction of processing and data portability. Contact us via the contact form on the website and we will help you — normally within 30 days. You may also lodge a complaint with the Swedish Authority for Privacy Protection (IMY).

Consent for portfolio images
Images are published in the portfolio, blog or social media only after explicit written consent, which can be withdrawn at any time.

Last updated: 2026-07-07