Last updated: August 16, 2026
This notice explains how Unifire AB collects and uses personal data through unifire.com and in the course of dealing with customers, enquirers and job applicants. It also explains what rights you have and how to exercise them.
Who we are
The data controller is Unifire AB, org.nr 556265-0399, Exportgatan 33D, 422 46 Hisings Backa, Sweden.
For any question about this notice, or to exercise any of the rights described below, write to le***@*****re.com.
We have not appointed a Data Protection Officer, as we are not required to do so under Article 37 GDPR. Data protection enquiries are handled at the address above.
What we collect, why, and on what basis
We collect personal data for the purposes set out below. For each one we state the legal basis we rely on under Article 6 GDPR, and how long we keep the data.
| Purpose | Data | Legal basis | We keep it for |
|---|---|---|---|
| Answering enquiries sent through our contact form or by email | Your name, email address, the content of your message, and anything else you choose to include | Article 6(1)(b) where your enquiry concerns a possible purchase — steps taken at your request before entering a contract. Otherwise Article 6(1)(f), our legitimate interest in responding to people who contact us. | 24 months from our last exchange with you |
| Following up on sales enquiries and managing our relationship with customers and distributors | Name, business contact details, company, and a record of our correspondence | Article 6(1)(b) where we have or are negotiating a contract with you; otherwise Article 6(1)(f), our legitimate interest in managing business relationships | For the length of the relationship, then 24 months |
| Sending our newsletter | Email address, the date you subscribed, and whether you opened or clicked | Article 6(1)(a) — your consent, which you can withdraw at any time | Until you unsubscribe. We keep the record of your consent for 12 months after that as proof that it was given. |
| Handling orders, deliveries, support and warranty claims | Contact and company details, order, delivery and service records | Article 6(1)(b), performance of our contract with you; Article 6(1)(c) for the accounting records we are legally required to keep | For the length of the relationship, then 7 years for accounting records (bokföringslagen) |
| Understanding how our website is used | IP address, device and browser type, pages viewed, referring site | Article 6(1)(a) — your consent, given through our cookie banner | 14 months |
| Protecting our forms from automated spam, and keeping the site secure and available | IP address, server request logs, and technical signals about how a form was filled in | Article 6(1)(f), our legitimate interest in the security and availability of our systems and in not being overwhelmed by automated submissions | Spam-check signals last only as long as your visit. Server logs are kept for 12 months. |
| Considering job applications | Your application, CV, and our correspondence with you | Article 6(1)(b), steps taken at your request before a possible employment contract; and Article 6(1)(a) where you agree to us keeping your details on file for future roles | 6 months after the decision, unless you agree to a longer period |
Where you contact us through our website, providing your name and email address is necessary for us to reply. There is no consequence to withholding them other than that we cannot respond.
Cookies
We use cookies and similar technologies on unifire.com. Strictly necessary cookies are set automatically; statistics cookies are set only if you consent through our cookie banner. You can change or withdraw your choice at any time using the Cookie settings link in the footer of every page.
Our cookie policy lists each one, what it does and how long it lasts.
Who we share your data with
We do not sell personal data, and we do not share it with third parties for their own marketing.
We use the following providers, who process personal data on our behalf and under our instructions. Each is bound by a written data processing agreement under Article 28 GDPR.
| Provider | What they do for us | What they receive |
|---|---|---|
| Templ (templ.io) | Hosts unifire.com. Templ runs our site on Google Cloud infrastructure located in Finland, within the European Union. | Anything submitted through the website, and server logs |
| Zoho | Our customer relationship management system, where enquiries and sales conversations are recorded. Our account is hosted on Zoho’s European infrastructure. | Your name, contact details, company and the content of your enquiry |
| Google Workspace | Provides our business email | Any personal data contained in emails to and from us |
| CleanTalk | Protects our forms against automated spam | Your IP address and technical signals about how the form was filled in |
| Google Analytics | Website statistics, only where you have consented to statistics cookies | Online identifiers and information about how you used the site |
We may also disclose personal data where we are legally required to do so, or where it is necessary to establish, exercise or defend legal claims. If our business or part of it is sold or reorganised, personal data may transfer as part of that transaction; we will tell you before that happens and before your data becomes subject to a different privacy notice.
Transfers outside the EEA
Our website is hosted within the European Union, in Finland, and our customer relationship management system runs on European infrastructure. Personal data you submit through the site therefore stays within the EU in the first instance.
Some of the other providers listed above process personal data outside the European Economic Area, principally in the United States. Where that happens, we rely on one of the safeguards permitted under Chapter V GDPR: an adequacy decision of the European Commission covering the recipient country, including certification under the EU–US Data Privacy Framework where the provider is certified; or the European Commission’s Standard Contractual Clauses, together with any additional measures the circumstances of the transfer require.
You can request details of the safeguard that applies to a particular provider by writing to le***@*****re.com.
How we keep your data secure
We take appropriate technical and organisational measures to protect personal data against unauthorised access, loss and misuse. These include encrypted connections to our website, restricting access to personal data to the people who need it for their work, and selecting providers who can demonstrate appropriate security. We review these measures as our systems change.
Your rights
Under the GDPR you have the following rights in relation to your personal data:
- Access — you can ask us to confirm whether we hold personal data about you, and to give you a copy of it together with information about how we use it (Article 15).
- Rectification — you can ask us to correct data that is inaccurate, or to complete data that is incomplete (Article 16).
- Erasure — you can ask us to delete your personal data where there is no longer a good reason for us to keep it (Article 17).
- Restriction — you can ask us to pause our use of your data while a dispute about its accuracy, or about our grounds for using it, is resolved (Article 18).
- Portability — where we process data you gave us on the basis of consent or a contract, and we do so by automated means, you can ask for it in a structured, commonly used, machine-readable format, or ask us to send it directly to another controller (Article 20).
- Objection — you can object to processing we carry out on the basis of our legitimate interests, and we will stop unless we can demonstrate compelling grounds that override your interests. Where we process your data for direct marketing, you can object at any time and we will stop, without exception (Article 21).
- Withdrawal of consent — where we rely on your consent, you can withdraw it at any time. This does not affect the lawfulness of anything we did before you withdrew (Article 7(3)).
To exercise any of these rights, write to le***@*****re.com. We will respond within one month. If your request is complex, or you have made several, we may extend that by up to two further months and will tell you if we do. There is no charge. We may ask you for information to confirm your identity before we act, so that we do not disclose your data to someone else.
Complaints
If you are unhappy with how we have handled your personal data, please tell us first — we would rather put it right. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU member state where you live, where you work, or where you believe the problem occurred.
The Swedish supervisory authority is Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, im*@*my.se, www.imy.se.
Children
Our website and products are aimed at businesses and professional users, not children, and we do not knowingly collect personal data from children. In Sweden, where an online service is offered directly to a child and relies on consent, that consent is valid from the age of 13 (Article 8 GDPR, as implemented by lag (2018:218)). If you believe a child has provided us with personal data, contact us and we will delete it.
Automated decision-making
We do not make decisions about you based solely on automated processing, including profiling, that produce legal effects concerning you or similarly significantly affect you. Our spam protection scores form submissions automatically, but a submission it rejects is retained and can be reviewed by a person on request.
Changes to this notice
We review this notice at least once a year, and whenever we change how we use personal data or add a new provider. The date at the top shows when it was last updated. If we make a material change, we will make that clear on the website.l data. The date at the top shows when it was last updated. If we make a material change we will make that clear on the website.
