Contact

Tell us what you need

Describe briefly where you stand and what you have in mind. We'll get in touch and take it from there.

You'll hear from us within one business day. Elias usually calls back within the hour.
Contact details
Contact info

Thank you so much!

Your message is on its way. We'll be in touch within one business day, usually sooner.

AI training for companies since 2023 5,000+ employees trained 4.8 out of 5 average rating

Privacy policy

Last updated September 26, 2026

Contents
  1. About this page
  2. Who is responsible
  3. Data we process
  4. Cookies
  5. Who receives your data
  6. Transfers outside the EU and EEA
  7. How long we keep your data
  8. How we protect your data
  9. Your rights
  10. How to file a complaint
  11. Changes to this policy
  12. How to reach us

This is an English translation of our Swedish privacy policy. In case of any discrepancy, the Swedish version (/integritetspolicy/) prevails.

About this page

This policy applies when you visit scribill.se, fill out a form with us, or get in touch in any other way. We keep it short and clear on purpose. If anything is unclear, you are always welcome to ask.

Personal data is any information that can be linked, directly or indirectly, to you as an individual, for example your name, email address, or IP address.

Who is responsible for your data

Scribill AB is the controller for personal data processed through scribill.se. Under the General Data Protection Regulation (GDPR), this means we decide why and how your data is used, and that you come to us with any questions.

Scribill AB Org. no. 559387‑9843
Höjdrodergatan 25 212 39 Malmö, Sweden
kontakt@scribill.se 040‑605 90 50

If you have questions about how we handle your data, the easiest way to reach us is at kontakt@scribill.se.

What data we process and why

We only collect data when there is a clear reason, and we always explain why. Here are the situations when that happens.

When you contact us

When you fill out a contact form, send an email, or call us, we save what you provide. This typically includes your name, company, email address, phone number, and the content of your message. The form also records which page you submitted from and how you found us, so we understand your question before we reply.

We use this data to answer your question, give you a proposal and a quote, and stay in touch about a possible collaboration. The legal basis is our legitimate interest in responding to and following up on inquiries (Article 6(1)(f) GDPR). If the contact leads to a booking, we process the data to enter into and perform a contract with you (Article 6(1)(b)).

When you book a meeting

If you book a meeting on the site, we save your name, company, email address, and phone number. The meeting is added to our calendar in Microsoft 365 with you as an attendee and a Teams link, so the invitation comes from Outlook. You also receive a confirmation email, and we get an internal notification about the booking. The basis is our legitimate interest in booking and preparing the meeting (Article 6(1)(f)).

When you take the AI maturity test

If you take the AI maturity test, we save your answers together with your name, company, role, email address, phone number, and company website. The data is sent through Make to our internal systems so we can prepare your report, send it to you, and follow up on it. The basis is our legitimate interest in delivering the report and following up (Article 6(1)(f)).

When you are a customer

When you engage us for a training session, a lecture, or any other service, we process the data needed to plan, deliver, and invoice the work. When we run training at your premises, we may also process data about participants, such as names and email addresses, in order to deliver the training. We typically receive that data from you. If a participant takes the knowledge test, we also process the result and, if they pass, the details on their personal certificate, which is issued through TrueOriginal. The basis is fulfilling the contract with you (Article 6(1)(b)) and, for accounting purposes, complying with legal obligations (Article 6(1)(c)).

When you visit the site

When pages load, our hosting provider logs technical data such as IP address, browser type, and timestamp. This is necessary for the site to work, stay secure, and withstand attacks. The basis is our legitimate interest in a safe and functioning site (Article 6(1)(f)).

Statistics on site usage

We use Google Analytics to understand which pages are useful and what we can improve. Google's tag loads for every visitor, but cookies are only placed once you say yes. The tool then collects data about how you navigate the site, your approximate location, and the device you use. If you decline, the tag only sends signals without cookies and without identifiers that link your visits, such as that a page was viewed and which choice you made in the cookie banner. We aggregate and anonymize this data as much as possible. The basis for measurement with cookies is your consent (Article 6(1)(a)), and you can withdraw or change your choice at any time. The signals without cookies are sent based on our legitimate interest in understanding how the site is used (Article 6(1)(f)). More on that in the Cookies section.

Ad measurement

We sometimes advertise through Google Ads so more people find us. If you agree to marketing cookies, Google can measure that an ad click led to, for example, a submitted contact form. If you decline, no such cookies are placed. The basis for the cookie measurement is your consent (Article 6(1)(a)).

Regardless of your choice, we note in our own database which ad campaign a visit came from. If you arrive through an ad, we also store Google's click ID and a random visit ID there, which only stays in your browser tab while it is open. If you book a meeting during the same visit, the visit ID goes with the booking so we can see which ad it came from. The click can then be linked to you as a person. The campaign name is also stored in your browser for 30 days, without the click ID or visit ID, so a form you send later can be tagged with the ad. Our own ad follow-up is based on our legitimate interest in knowing which ads lead to contact (Article 6(1)(f)).

Search on the reviews page

The reviews page has a search box that understands free text. When you search, your query is sent to OpenAI, which helps us match it against the right reviews. So do not enter any personal data in the search box. The basis is our legitimate interest in offering a useful search function (Article 6(1)(f)).

The prompt generator

In the prompt generator, what you write and your answers to the follow-up questions are sent to OpenAI, which creates the prompt for you. The text and the prompt are also stored in our own database, without names or contact details, so we can see how the tool is used and improve it. So do not enter any personal or sensitive data in it. The basis is our legitimate interest in offering and improving the tool (Article 6(1)(f)).

Cookies and similar technologies

A cookie is a small text file stored in your browser. We use them to make the site work and, if you agree, to understand how it is used. Under Swedish electronic communications law (Act 2022:482), we may only place non-essential cookies with your consent.

The first time you visit the site, a banner appears where you set your preferences. No analytics or marketing cookies are placed before you say yes, and declining is as easy as accepting. You can change your choice at any time using the link in the footer.

We group cookies into three categories.

Cookie What it does Category Storage period
scribill_samtycke Remembers your cookie choice Essential Up to 12 months
_ga Distinguishes visitors in Google Analytics Analytics, requires consent Up to 24 months
_ga_… Keeps track of the visit in Google Analytics Analytics, requires consent Up to 24 months
_gcl_… Connects Google Ads ad clicks to what you do here Marketing, requires consent Up to 3 months

The specific cookies we use may change over time, so we keep this list up to date. Choosing Accept in the banner means yes to both analytics and marketing. Under Customize you can choose category by category. If you arrive through an ad, we also store data in your browser's storage, as described under Ad measurement.

Who may receive your data

We never sell your data or share it for anyone else's marketing purposes. To run our business, we engage a few carefully chosen vendors who process data on our behalf. All are bound by data processing agreements that restrict them to using your data only on our instructions.

Vendor What they help us with Where data is processed
Cloudflare Hosting and running the site, and spam protection for the form (Turnstile) EU and USA
Microsoft (Microsoft 365) Email, contact inquiries, and meeting bookings in our calendar EU
Resend Sending confirmation and notification emails when you submit a form or book a meeting EU
Discord Receiving contact inquiries, bookings, and AI maturity test answers internally EU and USA
Make (Celonis) Forwarding contact inquiries and AI maturity test answers to our internal systems EU and USA
Google Analytics via Google Analytics and ad measurement via Google Ads EU and USA
OpenAI The search function on the reviews page and the prompt generator EU and USA
TrueOriginal Issuing and verifying the certificates after the knowledge test EU

If we add a CRM system to manage inquiries, it will be covered by the same type of agreement. We may also need to share data to comply with legal requirements, for example with the Swedish Tax Agency or another public authority.

Transfers outside the EU and EEA

Some of our vendors are US companies, so some data may be processed in the United States. This only happens when adequate protection is in place. Transfers are covered by the vendor being certified under the EU-US Data Privacy Framework, the regime that the European Commission has determined provides a level of protection equivalent to that within the EU, and additionally by the European Commission's standard contractual clauses. If you want to know more about the protection for a specific transfer, get in touch and we will explain.

How long we keep your data

We do not keep data longer than necessary.

  • Contact inquiries, meeting bookings, and AI maturity test answers are kept for the duration of the dialogue and for a period after, normally up to 24 months from your last contact, unless it leads to an engagement.
  • Data and documentation relating to a completed engagement are kept for as long as the engagement requires. Accounting records are kept for seven years, as required by Swedish accounting law.
  • Google Analytics data is kept for a maximum of 14 months.
  • Operational and security logs are cleared routinely after a short retention period.

How we protect your data

We protect personal data with technical and organizational measures. The site runs encrypted over HTTPS, access to data is limited to those at Scribill who genuinely need it, and we choose vendors that maintain a good level of security. Should something go wrong and there is a risk to you, we will report it as required and inform you when we must.

Your rights

It is your data, and you are in control of it. Under GDPR you have the right to

  • know what data we hold about you and receive a copy
  • have inaccurate data corrected
  • have data deleted when we no longer have a reason to keep it
  • request that we restrict processing while a matter is being investigated
  • object to processing we carry out based on legitimate interest
  • receive data you have provided in a portable format
  • withdraw a consent you have given, without affecting anything we have already done on the basis of that consent

To use any of these rights, email kontakt@scribill.se or use the form on the contact page. We respond as soon as we can, and within one month at the latest, at no cost to you.

How to file a complaint

If you think we are handling your data incorrectly, we would naturally like to hear from you first so we can put things right. You also always have the right to contact the Swedish Authority for Privacy Protection (IMY), which is the supervisory authority in Sweden.

Swedish Authority for Privacy Protection (IMY) Box 8114, 104 20 Stockholm
[email protected] imy.se

Changes to this policy

We update this policy when our operations or the rules change. The top of the page shows when it was last updated. If we make significant changes, we will announce them clearly on the site.

How to reach us

If you have a question about your data or this policy, get in touch and we will sort it out together.

Scribill AB Höjdrodergatan 25, 212 39 Malmö, Sweden
kontakt@scribill.se 040‑605 90 50

Contents

  1. About this page
  2. Who is responsible
  3. Data we process
  4. Cookies
  5. Who receives your data
  6. Transfers outside the EU and EEA
  7. How long we keep your data
  8. How we protect your data
  9. Your rights
  10. How to file a complaint
  11. Changes to this policy
  12. How to reach us