Privacy Policy
How aktiebok.io processes personal data under the GDPR.
Last updated: 7 October 2026
aktiebok.io is a share register (aktiebok) and cap table for Swedish limited companies, provided free of charge by Stockholm Innovation & Growth AB (org. nr 556489-3781), Östermalmsgatan 26 A, 114 26 Stockholm ("Sting", "we"). This policy explains what personal data aktiebok.io processes, why, and your rights under the EU General Data Protection Regulation (GDPR).
1. Two kinds of data, two roles
Your account. When you sign in to aktiebok.io, we process data about you as a user. For this data, Sting is the controller.
The share registers. A Swedish limited company must keep a share register listing its shareholders (Aktiebolagslagen 5 kap). When a company keeps its register in aktiebok.io, the company is the controller of the personal data in it, and Sting processes that data on the company's behalf as processor (personuppgiftsbiträde), under the data processing agreement in section 7 of the Terms of Use. Questions about your data in a company's register should go to that company. If you contact us, we will forward your request.
2. What we process
Account data (Sting is controller)
- Your email address, and technical identifiers for your account.
- Sign-in records: time of sign-in and, in our providers' security logs, IP address and browser type.
- Companies you are a member of and your role (admin or reader).
- Access tokens you create for AI apps. We store only a one-way hash of each token, never the token itself, plus its name, access level, expiry and when it was last used.
- Your choices in "My holdings": registers you have hidden and creators you have blocked.
- A log of changes you make or confirm, including which of your tokens prepared a draft, and of security actions such as creating or revoking tokens and adding or removing members. Each entry you make in a company's register carries your email address and the time, shown to everyone who can read that register (section 4).
Register data (the company is controller)
- For each shareholder: name, personnummer or organisation number, postal address, the shares held with their numbers and class, and the history of how they were acquired or disposed of. This is the content the law requires of an aktiebok (Aktiebolagslagen 5 kap 5 §).
- Warrants and options: holder, number, terms.
- A contact email for the shareholder, if the company has entered one.
- "Visible to": an email address or domain that the company has entered so that the shareholder can view the register.
- For each entry: its date and its basis, a reference to the decision or agreement behind it.
3. Why we process it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Providing your account, sign-in and the service you use | Performance of our agreement with you (GDPR art. 6.1 b) |
| Security, preventing abuse, investigating incidents, keeping a record of changes | Our legitimate interest in a secure and reliable register (art. 6.1 f) |
| Keeping share registers for companies | We process on the company's instructions. The company's basis is its legal obligation to keep an aktiebok (art. 6.1 c, Aktiebolagslagen 5 kap). |
Personnummer are processed because the law requires the share register to state them. aktiebok.io shows another person's personnummer as a birth year only. The full number is shown only to the company's administrators, and only when they explicitly ask for it.
We do not sell personal data, use it for advertising, or use register data to train AI models. We do not send newsletters or marketing emails.
4. Who can see register data
- The company's administrators and readers, whom the company adds.
- Shareholders marked "visible to" an email address or domain. Anyone who signs in with that address, or an address at that domain, can read that company's register. Readers see personnummer as birth year only.
- A claim of access. When someone signed in with a company's backup email claims access to the company, aktiebok.io sends an email about the claim to each of the company's admins.
- Who made each entry. Everyone who can read a company's register sees, for each entry, when it was made and the email address of the person who made it.
- AI apps you connect. If you connect an AI app, for example Claude, it receives the data you ask it to read. That data is then also handled under your agreement with that AI provider. You can revoke its token at any time, and it loses access at once.
5. Service providers
aktiebok.io runs on infrastructure from three providers. Each processes data only on our instructions:
| What it does | Provider | Where |
|---|---|---|
| The database, sign-in, and the API your AI app connects to | Supabase Pte. Ltd. | Data stored in the EU (Stockholm, Sweden) |
| Delivery of the sign-in emails and the email about a claim of access | Resend, Inc. | Sent from the EU (Ireland) |
| Web hosting and content delivery: serves the pages and scripts of the web application. Register data is never stored with the web host or sent through it; it travels encrypted between your browser and the database. The host sees technical request data such as IP address and browser type. | Lovable Labs Sweden AB, delivered through Cloudflare's network | Sweden; delivered from the network location nearest you |
Where a provider or its support staff may access data from outside the EU/EEA, the transfer is protected by the EU Commission's standard contractual clauses.
6. How long we keep data
- Account data: while your account exists. You can delete your account at any time from your account page. We then delete your sign-in and your settings, end your memberships, and revoke your tokens and AI connections. Records of the account's memberships and tokens are kept, as the record of who administered a register and to investigate misuse. If you are the only administrator of a company, you first hand it over or remove it. Entries in the change log stay with the register they belong to, as the record of who changed it.
- Register data: for as long as the company keeps its register in aktiebok.io. When an administrator removes a company, it becomes invisible to everyone at once and is deleted permanently after 30 days; until then an administrator can restore it. The law requires the aktiebok to be kept for as long as the company exists and for at least ten years after it is dissolved (Aktiebolagslagen 5 kap 3 §). That duty is the company's: the web app requires a full export before a company can be removed, and an AI connection is told to make sure one is saved first.
- Drafts and import files: a draft waits until you confirm or discard it. Its content is removed the moment you do; a line saying that the draft existed, when, who made it and through which connection is deleted 30 days later. You can have up to 20 drafts waiting. The files sent to move a register in from another platform are deleted when the import is confirmed, or after 7 days if it is not.
- Backups: daily backups of the database are kept for 7 days. Data you delete leaves the backups within that time.
- Security logs at our providers: up to 7 days.
7. Your rights
You have the right to access your personal data, have it corrected, have it erased, restrict or object to its processing, and receive it in a portable format.
- Account data: contact us at aktiebokio@sting.co.
- Register data: contact the company that keeps the register. A company cannot erase data the law requires it to keep.
You can also complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), www.imy.se.
8. Cookies and local storage
- aktiebok.io stores your sign-in session and a few display choices, such as which columns a table shows, in your browser's local storage, so that you stay signed in and the pages look as you left them.
- The web hosting sets two technical cookies.
__cf_bmtells real visitors from automated traffic and expires within 30 minutes.__dplbelongs to the delivery of the site and lasts one day. Neither is used to follow you. - We do not use analytics, tracking or advertising cookies.
9. Security
- Register data is stored in the EU.
- Every read and write is checked against your access in the database itself.
- Tokens are stored only as hashes.
- Personnummer are masked by default.
- Every change to the shares of a register is prepared as a draft, shown, and confirmed by a person before it is written. An entry is never edited afterwards; a correction is a new entry. A holder's name, address and id number are corrected in place, and the change is logged.
10. Changes and contact
We will post changes to this policy here and date them. Questions: aktiebokio@sting.co, Stockholm Innovation & Growth AB, Östermalmsgatan 26 A, 114 26 Stockholm.
