Last updated: 8 October 2026
Who is responsible for your information?
Brainstormer.app is operated by Roger Lundgren, a sole trader in Sweden. I am the controller responsible for the personal information described in this policy.
Roger Lundgren
Orrabäcksvägen 56
382 90 Örsjö
Sweden
Email: roger@brainstormer.app
Website: https://brainstormer.app
Information I collect
When you contact me, I receive the information you provide, such as your name, email address, business details and message.
When you purchase a service, I may receive your contact information, billing address, business name, payment status and transaction details. Card payments are processed by Stripe. I do not receive your full card number or security code.
During our work together, I may collect information about your business, the topics we discuss, correspondence and working notes. With your separate agreement, this may also include session transcripts and AI-assisted analysis.
The website and hosting services may process technical information, including IP addresses, browser information, request times and security logs, to deliver and protect the website.
Please avoid sharing sensitive personal information or unnecessary personal information about employees, customers or other people.
Why I use your information
I use personal information to:
- Respond to enquiries and discuss possible work.
- Arrange and deliver brainstorming sessions and consulting services.
- Process payments, issue invoices and maintain accounting records.
- Prepare notes and follow-up material and support ongoing client work.
- Keep the website and business systems secure.
- Handle complaints, resolve disputes and meet legal obligations.
Legal grounds for processing
Where you are personally entering into a contract with me, I process information necessary to prepare for and perform that contract.
When you contact me or act on behalf of a business, I rely on my legitimate interests in responding to enquiries, managing business relationships and delivering services. I also rely on legitimate interests for proportionate security measures and handling legal claims.
I process accounting and tax information to comply with legal obligations.
Optional recording, transcription and AI analysis will be based on your separate, informed consent. You may decline these activities and still receive an unrecorded session.
Session transcripts and AI analysis
I plan to offer transcription and AI-assisted analysis to help prepare working notes, follow-up material and continuity between sessions.
Before using these features, I will explain which providers will receive the information, what they will do with it and the relevant storage and international-transfer arrangements. Recording, transcription and uploading identifiable session material to an AI service will only begin after the necessary arrangements are in place and you have agreed separately.
If a recording is needed to create a transcript, I will delete the recording after checking the transcript.
You may withdraw consent by emailing me. Withdrawal does not affect processing that was lawful before withdrawal. I will stop the relevant consent-based processing and delete the associated material unless there is another lawful reason to retain it.
AI output will be reviewed by me. I do not use solely automated decisions that produce legal or similarly significant effects on you.
Services that receive information
Hostinger provides website hosting and email services. Contact-form submissions are handled through Fluent Forms within my WordPress website and may be stored in the website database and sent to my email.
Stripe processes payments and related transaction information under its applicable privacy terms:
https://stripe.com/privacy
Where necessary, information may also be shared with accounting or professional advisers and authorities entitled to receive it.
Any meeting, transcription or AI provider used for client material will be identified before that processing begins.
I do not sell your personal information.
International transfers
Some service providers may process information outside the European Economic Area.
Where GDPR requires safeguards for an international transfer, the applicable arrangement must be established before the transfer. This may involve a European Commission adequacy decision or standard contractual clauses with any additional safeguards required.
You can contact me for information about the safeguards applicable to your information and how to obtain a copy.
How long information is kept
Enquiries that do not lead to client work are normally deleted within 12 months after the last meaningful contact.
Client correspondence, transcripts, AI analysis and working notes are kept only while needed for the work and for up to 12 months after the client relationship ends. They may be deleted sooner if no longer needed.
Any recording used to create a transcript is deleted after the transcript has been checked.
Invoices and accounting records are retained for the period required by Swedish accounting law, normally seven years after the end of the calendar year in which the financial year ended.
Information needed for a specific dispute or legal obligation may be retained longer for that purpose, with access restricted.
Deletion routines cover material held in my working systems and relevant service accounts. Backup copies may remain until replaced through the applicable backup cycle.
Website analytics and cookies
I have not installed visitor analytics, advertising pixels or session-replay tools on this website.
Technical cookies or similar storage may be used where necessary for website functionality, security or administration. If I introduce optional analytics or tracking, I will update this policy and provide the required information and consent controls before enabling it.
External websites, including Stripe checkout, have their own privacy and cookie information.
Your rights
Depending on the circumstances, you may request access to your personal information, correction, deletion, restriction of processing or data portability.
You may object to processing based on legitimate interests and withdraw consent where consent is the legal basis.
To exercise your rights, email roger@brainstormer.app. I may need to confirm your identity before disclosing information. I will normally respond within one month; GDPR permits extensions in certain circumstances.
Some information cannot be deleted immediately where a legal obligation or another applicable exception requires its retention.
You may complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY):
https://www.imy.se
You may also contact the relevant supervisory authority in the country where you live or work.
Providing information
You choose what to include in an enquiry. Contact details are needed if you want a response. Information necessary to arrange a service or meet billing requirements must be provided for me to deliver that service.
Optional recording, transcription and AI analysis are not a condition of purchasing a session.
Changes to this policy
I will update this policy when my services or information-handling practices change. The date above identifies the latest version.