Privacy Policy
This privacy policy describes how Cloud 476 AB processes personal data in connection with the website cruisectrl365.se and the CruiseCTRL365 service (the ”Service”). We protect your privacy and comply with applicable data protection legislation, including the General Data Protection Regulation (GDPR).
1. Data Controller
Cloud 476 AB, org.nr 559210-1355, Stockholm, is the data controller for the processing. CruiseCTRL365 is a brand and a service owned and operated by Cloud 476 AB. The data controller determines the purposes and means of the processing.
If you have any questions about our personal data processing, you are welcome to contact us. We have no legal obligation to appoint a data protection officer and have chosen not to do so; data protection issues are handled by the company's legal function.
2. How we process personal data – and why AI is a strength
CruiseCTRL365 is built and operated by a human-led, AI-powered team. The use of AI throughout – in content, newsletters, community and support – is intentional and transparent. It’s part of the value of the service, not something we downplay. We apply exactly the same data protection requirements to AI-driven processing as to all other processing: purpose limitation, data minimisation, storage minimisation and a clear lawful basis under Article 6 GDPR for each purpose.
3. What data we process, for what purpose and on what legal basis
- Account and membership details (name, email address, role, organization) – to provide the Service, login and authorization. Legal basis: performance of contract (Art. 6.1 b).
- Payment and billing information – for billing and subscription management. Legal basis: contract (art. 6.1 b) and legal obligation (art. 6.1 c, Accounting Act).
- Usage and price data (course progress, activity in the platform) – to deliver and improve education. Legal basis: contract (art. 6.1 b) and legitimate interest (art. 6.1 f).
- Support and communication data – to answer and resolve issues. Legal basis: legitimate interest (Art. 6.1 f).
- Newsletter and market data (email address, opens and clicks) – to send newsletters and relevant information about the Service. Legal basis: consent (art. 6.1 a); double opt-in logged.
- Web analytics and session data (via Google Analytics/Tag Manager) – to improve the website. Legal basis: consent (art. 6.1 a) via our consent box, see section 8.
For processing based on legitimate interest (Art. 6.1 f), we have carried out a balancing of interests: the processing is limited, expected by the user and does not outweigh the interests and rights of the data subject.
4. Storage and thinning
- Account data: is retained as long as the account is active. An inactive member account is discarded after 12 months of inactivity, with a warning letter via email 30 days before deletion.
- Payment and subscription data: In case of non-payment, the account will be downgraded to the free level (Member). Member and payment data will be preserved. 12 months after downgrading, then thinning.
- Accounting data: preserved 7 years according to the Accounting Act.
- Newsletter data: opening and click data is preserved in 12 months, then they are de-identified (aggregated). The consent and timestamp for double opt-in are retained as long as the subscription is active. Consent can be revoked at any time via the unsubscribe link in each mailing.
- Support and communication data: will be processed when the case is closed and any deadlines have expired.
5. Data processors and sub-processors
We use suppliers (data processors) who process personal data on our behalf. Each is bound by a data processor agreement (DPA). Current sub-processors:
- Web support – web hosting and operation (WordPress). Location: EEA.
- Microsoft 365 – collaboration, storage and email. Location: EU/EEA (Microsoft EU Data Boundary).
- FluentCRM – email and CRM, run in our own WordPress database; sending is done via an email provider that is bound by an assistance agreement.
- Paid Memberships Pro with Stripe – membership and payment management. Location: EU/EEA and USA under EU Standard Contractual Clauses (SCC).
- Google (Analytics/Tag Manager via Google Site Kit) – web analytics, set only after consent (see section 8). Location: USA under the EU Standard Contractual Clauses (SCC).
- Anthropic (Claude) – AI processing for content, support and agent flows. Location: US under EU Standard Contractual Clauses (SCC).
- Microsoft Azure OpenAI / Foundry – AI inference on Azure. Location: EU/EEA.
- ElevenLabs – AI voice (text-to-speech) for course content, to the extent personal data is present. Location: USA under the EU Standard Contractual Clauses (SCC).
Changes to the list of sub-processors are notified in accordance with Art. 28.2 GDPR (general prior consent with right to object). The entire processing and tool chain, including the AI link, is entered into our processing register in accordance with Art. 30 GDPR.
6. AI-generated content and automated decision-making
- Transparency (EU AI Regulation, Art. 50): Content produced or substantially processed by AI – newsletters, community responses, and portions of course materials – happens openly as part of the Service. We label AI interaction where appropriate, so you know when you are communicating with an AI agent.
- Automated decision-making (Art. 22 GDPR): We do not make any legally binding, fully automated decisions about individuals with legal or similarly significant effect without human intervention.
7. Your rights
According to Articles 15–22 GDPR, you have the right to: access to the register, rectification, erasure (”right to be forgotten”), restriction of processing, data portability and objection to processing. You can also unsubscribe from the newsletter at any time. Contact us via contact page to exercise your rights.
You have the right to file a complaint with the supervisory authority The Privacy Protection Authority (IMY), Box 8114, 104 20 Stockholm, imy@imy.se.
8. Cookies and consent
We use necessary cookies for the website to function. Analysis and tracking cookies (e.g. Google Analytics/Tag Manager) are set only after your consent via our consent box. You can change or revoke your choice at any time via the cookie settings on the website. Necessary cookies are always required for basic functionality; other categories (statistics, settings, marketing) are only activated if you consent.
9. Security
We take appropriate technical and organizational measures (Art. 32 GDPR) to protect personal data against unauthorized access, loss and modification – authorization control, encryption during transmission, backup and logging.
10. Changes to this policy
This policy may be updated. Significant changes will be announced on the website. The current version is shown below.
Version 2.0. Last updated 2026-07-22. Replaces Privacy Policy version 1.0 (2025-05-05).