Last Updated: February 26, 2026
Our Commitment: ICP Clarity is committed to protecting your privacy in full compliance with EU GDPR and Swedish data protection law (Dataskyddslag 2018:218). This policy describes only what we actually do with your data—no exaggerations, no future promises.
ICP Clarity is a Go-To-Market (GTM) intelligence consultancy helping Nordic B2B companies build data-backed Ideal Customer Profile (ICP) systems.
Data Controller (Personuppgiftsansvarig):
Contact for Privacy Inquiries:
Contact form will be available soon. For now, privacy inquiries can be submitted via our assessment form with "Privacy Request" in the message field.
Governing Law: This privacy policy is governed by Swedish law (Dataskyddslag 2018:218) and EU General Data Protection Regulation (GDPR).
When you use our ICP Clarity Assessment tool, we collect:
| Data Category | Specific Fields | Purpose |
|---|---|---|
| Contact Information | First name, last name, email address, phone number (optional), LinkedIn profile URL (optional) | To deliver your assessment results and follow up if you request consultation |
| Company Information | Company name, industry, company size, your role/title | To calculate your ICP Clarity Score and provide relevant insights |
| Assessment Responses | 12 structured questions about your GTM strategy, ICP definition, data sources, segmentation, and activation | To score your ICP maturity and generate personalized recommendations |
When you visit our website, we collect minimal technical data:
Coming Soon: Google Analytics 4 will be implemented for usage analytics. When enabled, we will collect page views, traffic sources, and user behavior data (with IP anonymization and cookie consent). This section will be updated before deployment.
We may enrich your company data using:
Note: All third-party enrichment is limited to publicly available business information. We do not purchase consumer data or personal sensitive information.
Under GDPR Article 6 and Swedish Dataskyddslag 2018:218, we process your data based on the following legal grounds:
| Processing Activity | Legal Basis | GDPR Article | Explanation |
|---|---|---|---|
| Assessment Form Submission | Consent | Article 6(1)(a) | You explicitly agree by submitting the form |
| ICP Score Calculation | Legitimate Interest | Article 6(1)(f) | You requested the assessment; receiving results serves your interest |
| Data Enrichment (Clearbit, Hunter, Apollo, Nordic Registries) | Legitimate Interest | Article 6(1)(f) | To provide accurate, relevant insights; we use only publicly available business data |
| Storing Data in CRM (Airtable) | Contractual Necessity | Article 6(1)(b) | To manage our business relationship and provide requested services |
| Internal Notifications (Slack) | Legitimate Interest | Article 6(1)(f) | To respond promptly to your inquiry |
Future Use Cases (Not Yet Implemented):
We use your personal data to:
We do NOT:
We share your data with the following trusted third-party processors to operate our services:
| Service Provider | Purpose | Data Location | GDPR Safeguards |
|---|---|---|---|
| Make.com | Workflow automation - routes assessment data from website to Clay and Airtable | EU (Europe 2 endpoint) | EU-based processing, GDPR-compliant DPA |
| Clay.com | Data enrichment and ICP scoring automation | United States | Standard Contractual Clauses (SCCs), Data Processing Agreement |
| Airtable | CRM and customer data management | United States | Standard Contractual Clauses (SCCs), Data Processing Agreement |
| Netlify | Website hosting and content delivery | Global CDN (EU servers prioritized) | SOC 2 certified, GDPR-compliant hosting |
| Slack | Internal notifications when you submit assessment | United States / EU | Standard Contractual Clauses (SCCs) |
Future Service Providers (When Implemented):
All processors listed above have signed Data Processing Agreements (DPAs) with ICP Clarity as required by GDPR Article 28. These agreements ensure processors:
We never sell, rent, or share your personal data with:
ICP Clarity is based in Stockholm, Sweden (EU), and we primarily process data within the European Economic Area (EEA). However, some of our service providers are located outside the EU/EEA, requiring international data transfers.
The following processors may transfer your data to the United States:
Legal Safeguards (GDPR Article 46):
All US-based processors have implemented Standard Contractual Clauses (SCCs) approved by the European Commission. These clauses provide equivalent data protection to EU law, even when data is processed in the US.
The following services process your data within the EU:
When we verify your company data using Allabolag (Sweden), Proff (Norway), or Virk (Denmark), this data remains within the Nordic region and EU/EEA.
If you have concerns about international data transfers, you have the right to:
We retain your personal data only for as long as necessary to fulfill the purposes described in this policy, in compliance with Swedish law:
| Data Category | Retention Period | Legal Basis |
|---|---|---|
| Active Client Contracts | Duration of service + 7 years | Swedish Tax Law (Bokföringslagen 2010:1142) - accounting records must be kept 7 years |
| Assessment Users (Non-Clients) | 2 years from last interaction | Legitimate interest to provide follow-up value; you can request earlier deletion |
| Transactional Emails/Records | 1 year from completion | Business record-keeping and customer service |
| Aggregated/Anonymized Data | Indefinitely | No longer personal data once fully anonymized (GDPR Recital 26) |
Future Retention Periods (When Implemented):
Early Deletion: You can request deletion of your data at any time (see Section 7 - Your Rights). We will honor your request except where we have a legal obligation to retain data (e.g., invoicing records for tax authorities).
As a data subject in Sweden/EU, you have the following rights under GDPR (Articles 15-22) and Swedish Dataskyddslag 2018:218:
You can request a copy of all personal data we hold about you. We will provide this in a clear, commonly used format (typically PDF or CSV).
Response Time: Within 30 calendar days (may extend to 60 days for complex requests, with notification).
You can correct inaccurate or incomplete data. Example: Update your email address, LinkedIn profile, or company information in our records.
You can request deletion of your personal data.
Limitations: We must retain financial records for 7 years if you're an invoiced client (Swedish tax law). We will delete all other data promptly.
You can ask us to limit how we use your data. Example: Keep your account active but stop sending any communications.
You can receive your data in a machine-readable format (CSV or JSON) to transfer to another service.
What's Included: Contact info, assessment responses, ICP scores, any correspondence.
You can object to data processing based on legitimate interest (e.g., marketing, profiling, analytics).
How: Contact us via the method below with "OBJECT" in the subject line.
If processing is based on consent (e.g., marketing emails, cookies), you can withdraw consent at any time.
Effect: Withdrawal doesn't affect the lawfulness of processing before withdrawal.
If you believe we've violated your privacy rights, you can file a complaint with the Swedish Data Protection Authority (see Section 9 for contact details).
Contact Method: Submit via our assessment form with "GDPR Request" in the message field, or wait for dedicated privacy contact form (coming soon).
Please Include:
Response Time: We will respond within 30 calendar days. If your request is complex, we may extend by an additional 60 days (we'll notify you of any extension).
We implement appropriate technical and organizational measures to protect your personal data from unauthorized access, loss, or misuse:
In the unlikely event of a personal data breach, we will:
Questions, concerns, or GDPR requests? Contact us:
Privacy Contact: Dedicated privacy contact form coming soon. For now, use our assessment form with "Privacy Request" in the message field.
Company Address: Jakobsbergsgatan 24, 111 44 Stockholm, Sweden
Response Time: We aim to respond within 48 hours (maximum 30 calendar days for GDPR requests as required by law)
If you have concerns about how we handle your personal data, or if you believe your rights have been violated, you have the right to file a complaint with the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
(Formerly Datainspektionen - Swedish Authority for Privacy Protection)
Website: www.imy.se
Email: imy@imy.se
Telephone: +46 8 657 61 00
Postal Address: Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm, Sweden
If you're based in another EU country, you can also file a complaint with your national data protection authority. Find your authority at: edpb.europa.eu
Our website uses essential cookies required for basic functionality:
Under Swedish ePrivacy Law (Elektronisk kommunikationslagen 2003:389), these cookies are exempt from consent requirements as they're strictly necessary for website functionality.
Coming Soon: When we implement Google Analytics 4 and email marketing, we will:
Compliance: Cookie consent will comply with Swedish ePrivacy Law and GDPR requirements for explicit, informed, freely given consent.
You can control cookies through your browser settings. Note that disabling essential cookies may prevent the website from functioning properly.
Browser Instructions:
We may update this privacy policy to reflect:
Notification of Changes:
Version History: This is version 2.0 (February 26, 2026) - Rebuilt for legal accuracy and Swedish GDPR compliance.
Our website may contain links to third-party services:
Important: We are not responsible for the privacy practices of these third-party services. Please review their privacy policies separately.
Our services are intended exclusively for business professionals (B2B). We do not knowingly collect personal data from individuals under 16 years of age.
If we discover that we have inadvertently collected data from a child under 16, we will delete it immediately and notify the parent/guardian if contact information is available.
Transparency: This privacy policy describes only what we actually do—no exaggerations or future promises.
Swedish Law Compliance: We comply with GDPR and Swedish Dataskyddslag 2018:218.
Your Control: You can access, correct, or delete your data at any time.
No Data Selling: We never sell your personal data to third parties.
Questions? Privacy contact form coming soon. For now, submit via assessment form with "Privacy Request" in message.
⚠️ Placeholder Notice: This privacy policy contains one remaining placeholder (highlighted in yellow) for dedicated privacy contact email. This will be added when email infrastructure is configured.