Trust Center
This page is maintained by 42 Scandinavia to answer common security, privacy and compliance questions about our Services. It describes current practices in plain English and is not an independent certification.
Our Commitments
At 42 Scandinavia we believe software companies should earn trust. Accordingly, we make the following commitments.
Your Data Belongs to You
- You retain ownership of your Customer Data.
- We never claim ownership of your information.
No Advertising Business
- We do not sell Customer Data.
- We do not sell Personal Data.
- We do not build advertising profiles.
Essential Cookies Only
- Our websites use only cookies necessary for the operation and security of our Services.
- We do not currently use advertising or marketing cookies.
Transparency
- Our legal documents, privacy practices and subprocessors are published openly.
- We believe customers should not have to ask for basic information.
GDPR
Where we process Customer Data:
- You are normally the Data Controller.
- We are normally the Data Processor.
Export Your Data
Customers may export their data during their subscription and during the post-termination retention period.
Clear Legal Documents
- We write legal documents for people—not lawyers.
- Wherever possible we explain our commitments in plain English.
Continuous Improvement
- We continuously improve our Services, security practices and documentation.
- When material legal changes are made, we normally provide at least 30 days' notice.
Security Overview
This page is intentionally short.
Security
Security is built into our development process. Current practices include:
- encrypted communication using TLS;
- authenticated access;
- role-based access within our systems;
- managed cloud infrastructure;
- backups;
- monitoring;
- incident response procedures.
We continuously review and improve our security measures.
Data Locations
This page answers one of the most common procurement questions.
Data Processing
Current providers include:
| Service | Provider |
|---|---|
| Application hosting | Lovable |
| Database infrastructure | Supabase (where applicable) |
| Transactional email | Resend |
| Payment processing | Stripe |
Infrastructure providers may evolve over time. The current list is maintained in our published Subprocessor Policy.
GDPR FAQ
Who owns my data?
You do.
Do you sell customer data?
No.
Are you GDPR compliant?
We design our Services and processes to comply with applicable GDPR requirements. Compliance is a shared responsibility: as our customer, you remain responsible for your own obligations as a data controller where applicable.
Where is data stored?
Our Services are hosted in Europe.
Can I export my data?
Yes.
What happens if I terminate my subscription?
Customer Data remains available for 30 days.
After that it is deleted according to the Data Retention Policy.
How long are backups kept?
Up to 90 days.
Do you use AI to train models?
No Customer Data is used to train publicly available AI models.
Who do I contact regarding GDPR?
Contact
Questions about:
- privacy;
- GDPR;
- security;
- legal terms;
- subprocessors;
may be sent to:
