Privacy Policy
Last updated: February 2026
1. Introduction
POM3 Consulting AB ("we", "us", "our") is committed to protecting your personal data. This Privacy Policy explains how we collect, use, store, and share your personal information when you use POM3 AI services, in accordance with the EU General Data Protection Regulation (GDPR).
2. Data Controller
POM3 Consulting AB
Org.nr 559080-7862
Ekbacksvägen 28, Bromma, Sweden
contact@pom3consulting.org
3. What Data We Collect
We collect the following types of personal data:
- Account information: name, email address, and password (hashed) when you create an account
- Usage data: number of questions asked, session information, and feature usage
- Payment data: transaction references processed through Klarna (we do not store credit card numbers)
- Chat content: messages you send to our AI agents (used to provide the service)
- Technical data: IP address, browser type, device information, and cookies
4. How We Use Your Data
We process your personal data for the following purposes:
- To provide and maintain our AI agent services
- To process payments and manage subscriptions through Klarna
- To improve our services and develop new features
- To provide customer support and respond to inquiries
- To comply with legal obligations under Swedish and EU law
5. Legal Basis for Processing
We process your data based on: (a) performance of our contract with you (providing the service), (b) your consent (for marketing communications), (c) our legitimate interests (improving our services, preventing fraud), and (d) compliance with legal obligations.
6. Data Sharing and Third Parties
We share your data with the following third-party service providers, all of whom are bound by data processing agreements:
- Firebase (Google): Authentication and database services (data stored in EU region)
- Klarna: Payment processing (subject to Klarna's own privacy policy)
- AI Services: AI processing of your chat messages to generate responses
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide our services. Account data is deleted within 30 days of account deletion. Chat history is retained for 90 days for service quality purposes. Payment records are retained for 7 years as required by Swedish accounting law (Bokföringslagen).
8. Your Rights Under GDPR
As an EU/EEA resident, you have the following rights regarding your personal data:
- Right of access: request a copy of your personal data
- Right to rectification: correct inaccurate personal data
- Right to erasure: request deletion of your personal data
- Right to restriction: limit how we process your data
- Right to data portability: receive your data in a structured format
- Right to object: object to processing based on legitimate interests
To exercise any of these rights, please contact us at contact@pom3consulting.org. We will respond within 30 days.
9. Cookies
We use essential cookies for authentication and session management. We do not use advertising or tracking cookies. Firebase Auth uses cookies to maintain your login session.
10. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including encryption in transit (TLS/SSL), secure authentication (Firebase Auth), and access controls. However, no method of transmission over the internet is 100% secure.
11. Children's Privacy
Our services are not directed at children under 16 years of age. We do not knowingly collect personal data from children. If you believe we have collected data from a child, please contact us immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by posting the new policy on our website and updating the "Last updated" date.
13. Contact Us
For privacy-related questions or to exercise your rights, contact us:
POM3 Consulting AB
Ekbacksvägen 28, Bromma, Sweden
contact@pom3consulting.org
You also have the right to lodge a complaint with the Swedish data protection authority: Integritetsskyddsmyndigheten (IMY)