The controller for processing on tindom.se is Edström Business AB (org.nr 559101-7750). In this policy the company is called "Tindom", "we" or "us".
Send questions about personal data to contact@tindom.se.
This policy does not cover documenttrustgrade.org, a separate site with its own controller and its own information about how data is handled.
The table lists each purpose separately. Where more than one basis could apply, we give the most fitting one.
| Purpose | Data | Legal basis | Retention |
|---|---|---|---|
| Validate a document in the web validator | The uploaded file (may contain names and other details about signers), your IP address at the time of the request | Contract: providing the service you ask for (Art. 6(1)(b)) | The file is not stored. It is held in memory during validation and discarded once the answer is sent. |
| Email you a validation report | Email address, the report’s content (result, grade, filename, document fingerprint and the signature details the report shows) | Contract (Art. 6(1)(b)) | The report is sent immediately. Our email provider keeps delivery logs for a limited time under its own terms. |
| Record your request in our register of interested users | Email address, time, the document’s SHA-256 fingerprint, number and type of signatures, which trust service providers appeared, grade, whether the document appears to be BankID-originated | Legitimate interest: understanding how the service is used, improving it, and following up on your interest (Art. 6(1)(f)) | 24 months from the request, then deleted |
| Anonymous grade statistics to calibrate the grading scale | The grade and the technical signals behind it (e.g. signature format and trust regime). No email, filename, fingerprint or names | Not personal data, as it cannot be linked to a person or a document | Indefinitely |
| Contact form and pilot requests | Name, email address, organisation, organisation type, your message | Steps at your request before a contract, and legitimate interest in replying and keeping the conversation going (Art. 6(1)(b) and (f)) | While the conversation continues. If it does not lead to a customer relationship, deleted no later than 24 months after last contact. |
| Pilot: documents sent to validate@tindom.se | Sender’s email address and domain, subject line, attachment filenames, fingerprint, result and grade (operations log). We do not store the documents ourselves, but our email provider Postmark keeps the inbound message with attachments for 45 days. | Contract with the pilot customer (Art. 6(1)(b)); see the pilot section below | The operations log is kept for 12 months |
| Statistics on how the site is used | Cookie identifiers, page views, events (e.g. a form being submitted), approximate location, device and browser | Consent (Art. 6(1)(a)), which you can withdraw at any time | At most 14 months at Google |
| Manage and document your cookie choice | Your choice, time, an anonymised IP number, a random identifier | Legal obligation: being able to show that consent was given (Art. 6(1)(c), read with Art. 7(1)) | 12 months |
| Operations, troubleshooting and security | IP address, time, requested address, browser details and technical error messages (occasionally including a filename) | Legitimate interest: keeping the service secure and working (Art. 6(1)(f)) | A short time in the hosting provider’s logs, normally days to a few weeks |
When you upload a file to the web validator, our web application receives it and passes it on to our validation engine. The engine checks the signatures’ technical properties: certificates, timestamps, issuers, and whether the content has changed since signing. The file is not written to disk and is not stored once the answer has been sent.
We do not use documents for any other purpose, not to train models and not for statistics that could be linked to the document or the people in it.
A signed document can contain details about signers, for example name, organisation and personal identity number. Such details may appear in the validation result and in the report sent to you, but we do not store them. In the open web validator, personal identity numbers are masked and technical audit events (such as IP addresses and timestamps) are not shown.
Do not upload documents you have no right to process, and avoid documents containing sensitive data (for example health) or data about offences. Validation needs only the signature, and we do not want more than that.
Selected organisations can send documents to validate@tindom.se and receive a full report back. A separate pilot agreement then applies. For the content of the documents the customer sends, the customer is the controller and Tindom is the processor, and we process them only on the customer’s instructions and under the data processing agreement. A report to a pilot customer may contain full personal identity numbers and technical details from the signing (such as IP address and timestamps). These go to the customer and are not stored by us.
For the operations log we keep of pilot use (see the table), Tindom is the controller.
We do not sell personal data. We use the following providers (processors) to run the service, and have data processing agreements with them:
| Provider | What they do for us | Where data is processed | Processing terms |
|---|---|---|---|
| Vercel Inc. | Hosting of the website and APIs | Our application runs in Vercel’s Stockholm region. The company is US-based. | Vercel DPA |
| Railway Corp. | Runs the validation engine (the EU reference implementation, EC DSS) | The Netherlands (EU) | Railway DPA |
| Supabase Inc. | Database for the request register, operations log and grade statistics | Ireland (EU) | Supabase DPA |
| Resend, Inc. | Sending reports and replies by email | USA | Resend DPA |
| Postmark (ActiveCampaign, LLC) | Receiving email to validate@tindom.se (pilot only). Postmark keeps inbound messages for 45 days. | USA | Postmark DPA |
| Google Workspace (Google Ireland Ltd) | Our email, where contact-form messages and mail to us arrive | EU, with possible transfer to the USA | Google Cloud DPA |
| Google Analytics (Google Ireland Ltd) | Site statistics, only with your consent | EU, with transfer to the USA | Google Data Processing Terms |
| Usercentrics A/S (Cookiebot) | Cookie banner and recording of your choice | EU | Cookiebot DPA |
Beyond this, we disclose data only where the law requires it or where needed to establish, exercise or defend legal claims.
Several of our providers are US companies or use sub-processors in the US. Where data is transferred there, it relies on an adequacy decision (the EU–US Data Privacy Framework, where the provider is certified) or the European Commission’s standard contractual clauses, supplemented by the safeguards needed. Contact us if you would like a copy of the safeguards.
You have the right to:
Write to contact@tindom.se. We reply within one month. To find your data in the register we need the email address you used and, where relevant, the document’s filename or the time. We may need to verify that you are who you say you are.
You can also lodge a complaint with the supervisory authority, the Swedish Authority for Privacy Protection (IMY): imy.se. Questions about cookies as such are handled by the Swedish Post and Telecom Authority (PTS).
No. You can validate a document without giving any email address, and the result is then shown on screen. An email address is needed only if you want the report sent. Without the details the contact form requires, we cannot reply to you.
The grade A+ to F is calculated automatically from the signature’s properties. It concerns the document, not you as a person, and we make no decisions about individuals with legal or similarly significant effects on the basis of it.
Traffic to and from the service is encrypted. Access to the databases is limited to those who need it, and the registers cannot be read by visitors to the site. Validation results passed between your browser and us are signed so they cannot be altered in transit. No technical solution is entirely risk-free, but we work to keep the data protected.
The service is aimed at businesses, organisations and professionals, not children.
We update this policy when our processing changes. The latest version is always here, with the date of the last change at the top. For material changes that concern you directly, we will tell you on the site or, if we have your email address, by email.