Privacy Policy

Last updated: 2026-08-14

This privacy policy describes how Raw Digital AB (”Raw Digital”, ”we”, ”us”) processes personal data. The policy applies to our websites rawdigital.se and rawdigital.ai, as well as the processing of personal data carried out as part of our services.

1. Data controller

Raw Digital AB
Company registration number: 556892-8831
Address: Edsviksvägen 31 B, SE-182 33 Danderyd, Sweden
E-mail: kontakt@rawdigital.se

2. What personal data we process and why

Visitors to our websites

When you visit our websites, we may process:

  • Technical information (IP address, browser type, device, which pages you visit) through cookies and similar technologies — see section 4. Legal basis: consent (for non-essential cookies) and our legitimate interest in keeping the website secure and functional.

Enquiries and contacts

When you contact us via forms, e-mail or phone, we process the information you provide (name, e-mail address, phone number, company and the content of your enquiry) in order to respond and follow up.
Legal basis: legitimate interest in responding to enquiries, or steps taken prior to entering into a contract.
Retention period: for as long as the dialogue is ongoing and thereafter no longer than 12 months, unless a contract is entered into.

Clients and suppliers

For clients and suppliers, we process contact persons’ details (name, e-mail address, phone number, role) for contract management, delivery of services, invoicing and accounting.
Legal basis: performance of a contract and legal obligation (the Swedish Bookkeeping Act).
Retention period: for the duration of the contract and thereafter as required by the Swedish Bookkeeping Act (7 years for accounting records).

Marketing

We may contact company representatives with relevant information about our services. You can object to such processing at any time by contacting us.
Legal basis: legitimate interest.

3. Processing as part of our services (data processor)

Raw Digital works with digital marketing — including search engine advertising, search engine optimisation, social media advertising, and analytics and tracking — on behalf of our clients. As part of these engagements, we access data in our clients’ accounts on advertising platforms and analytics tools (for example Google Ads, Google Analytics, Microsoft Advertising, Meta and LinkedIn).

This data is primarily aggregated statistics (such as impressions, clicks, costs and conversions) and is used solely to deliver, monitor and report on our services to each client. To the extent personal data occurs in such data, we process it as a data processor on the client’s behalf, in accordance with data processing agreements with each client and the terms of use of each platform. We never sell data, never use it for the benefit of other clients, and never enrich it with information from other sources.

4. Cookies and analytics

Our websites use cookies and similar technologies via Google Tag Manager, including for web analytics (Google Analytics 4). Non-essential cookies are only set after you have given your consent, which you can give and withdraw via the website’s cookie settings.

We use analytics data to understand how our websites are used and to improve them.

5. Recipients of personal data

We share personal data with suppliers that help us run our business, such as hosting and infrastructure providers, cloud services (including Google Cloud), e-mail and office software, and accounting services. These parties process the data on our behalf under data processing agreements, or are independently responsible (for example public authorities where required by law).

6. Transfers to third countries

Some of our suppliers (for example Google and Microsoft) may process data in countries outside the EU/EEA. Where this happens, we ensure the transfer has a valid legal basis, such as an adequacy decision by the European Commission (including the EU-U.S. Data Privacy Framework) or standard contractual clauses with supplementary safeguards.

7. How long we keep your data

We keep personal data for as long as necessary for the purposes described above, or for as long as the law requires. After that, the data is deleted or anonymised.

8. Your rights

Under the General Data Protection Regulation (GDPR), you have the right to:

  • request access to the personal data we process about you (a copy of your data),
  • have inaccurate data rectified,
  • have data erased under certain circumstances,
  • request restriction of processing,
  • object to processing based on legitimate interest, including direct marketing,
  • receive the data you have provided in a machine-readable format (data portability),
  • withdraw any consent you have given, at any time.

Contact us using the details in section 1 to exercise your rights.

If your data is processed in a context where we act as a data processor (section 3), you should primarily contact our client, who is the data controller — but you are always welcome to contact us and we will point you in the right direction.

9. Complaints

If you believe we are processing your personal data incorrectly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), www.imy.se.

10. Changes to this policy

We may update this policy when needed, for example when our services or the law change. The latest version is always published on this page, with the date of the most recent update at the top.