Privacy Policy
Tomlin Studio AB (org. no. 556749-8364), Sundeliusgatan 3, 602 35 Norrköping, Sweden is the controller for the personal data described here. Questions or requests: hello@tomlinstudio.com.
This website
We do not use analytics or advertising cookies. We set one cookie, "lang", which remembers whether you prefer Swedish or English.
Our hosting provider processes technical data such as your IP address to deliver the site and protect it from abuse. We use the country your visit comes from only to choose the language you see first.
When you contact us
If you email us, we process your name, email address, organisation and what you write, to reply and handle your request. The legal basis is our legitimate interest in answering you, or steps before an agreement. We keep this for up to 24 months after our last contact unless you become a customer.
Business contacts
We may process work contact details of people at organisations we think could benefit from our services: name, role, work email, organisation and publicly available professional information. The legal basis is our legitimate interest in business-to-business marketing. You can object at any time and we will stop.
Customers
For customers we process the contact and billing details needed to deliver the assignment and invoice it. Accounting records are kept for seven years as required by the Swedish Bookkeeping Act.
Material you upload
Images, video, reference material and brand assets you give us are used only to deliver the service you ordered, and are accessible only to the people working on your project. We never use them to train AI models.
Payments
Purchases on GENERAITR are paid through Stripe. We do not see or store your card details. Invoiced assignments are paid by bank transfer.
Publishing tools and social media
We use our own publishing tool to post Tomlin Studio's own content, for example educational videos about AI, to our own accounts on platforms such as TikTok, LinkedIn and Instagram. A person at Tomlin Studio approves every post. The tool does not collect personal data about other users of these platforms.
Customers of Social Media Publishing connect their own channels through a secure authorisation link. We receive an access token that only allows publishing the posts the customer has approved, never a password. The token is deleted when the customer removes the connection or the service ends.
AI and service providers
We use AI tools to research, draft and prepare, and a person reviews the result. We do not use your personal data to train AI models.
We use service providers for hosting, email, customer relationship management and publishing. They process data only on our instructions under data processing agreements. Data is primarily stored in the EU/EEA; where it is transferred outside, we rely on the EU Commission's standard contractual clauses.
Security
We protect data with access control, project-specific storage and limited internal access. No system is completely secure, but we work actively to minimise the risk.
Your rights
You have the right to access, correct or erase your personal data, to restrict or object to processing, and to data portability. Contact hello@tomlinstudio.com. You can also complain to the Swedish Authority for Privacy Protection (IMY), imy.se.
Changes
We update this policy when our processing changes. The date at the top shows the latest version.