LEGAL
Privacy Policy
Version 2.0 · Effective 2026-10-01
Last updated: 2026-09-27. Effective: 2026-10-01 (replaces version 1.0 dated 2026-05-04).
This Privacy Policy (the "Policy") describes how FutureCalc AB, registration number 559536-7847, VAT number SE559536784701, with registered office in Malmö, Sweden, and postal address c/o Kivra: 559536-7847, 106 31 Stockholm, Sweden ("FutureCalc", "we", "us") processes personal data when you visit our website, register an account, use the FutureCalc.ai service (the "Service") or otherwise interact with us.
We process personal data in accordance with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), supplementary Swedish data protection legislation, the Swedish Electronic Communications Act (LEK) and the Swedish Bookkeeping Act (Bokföringslagen, 1999:1078).
Capitalized terms not defined here have the meaning given in the Terms of Use (Customer Content, Output, Corrections, Derived Data).
In case of any discrepancy between the Swedish and English language versions of this Policy, the Swedish version prevails.
1. Contact and supervisory authority
Controller:
FutureCalc AB
Reg. no.: 559536-7847
Registered office: Malmö, Skåne County, Sweden
Postal address: c/o Kivra: 559536-7847, 106 31 Stockholm, Sweden
Phone: +46 10-106 06 61
Email (general): info@futurecalc.ai
Email (privacy/DPO): privacy@futurecalc.ai
Supervisory authority: Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, phone +46 8-657 61 00, imy.se.
2. Our roles – controller vs processor
Controller. FutureCalc is the controller for account data (name, email, role, company affiliation), authentication and security data, usage analytics and communication with us.
Processor. For personal data embedded in material that the Customer uploads to the Service (for example names of designers, handläggare or contact persons in title blocks and annotations), the Customer (the company that has subscribed) is the controller when we provide the Service, and FutureCalc acts as processor. Such processing is governed by our Data Processing Agreement (DPA), which applies to all business customers and is incorporated by reference into the Terms of Use.
Controller for development purposes. Under section 6 of the Terms of Use, we use uploaded drawings, Output and Corrections to develop, test, calibrate and improve the Service. For that processing we determine the purposes and means ourselves and are therefore the controller. Before material is used for development purposes, we remove or pseudonymize any personal data it may contain (typically names and contact details in title blocks). Remaining personal data is limited to what cannot reasonably be removed without distorting the technical content of the drawing. See further section 4.
3. Personal data we process
| Category | Data | Source | Purpose | Legal basis |
|---|---|---|---|---|
| Account / identity | Name, email, avatar, language, company ID, role | You or your administrator | Create and administer the account, authentication, access control | Art. 6(1)(b) – contract |
| Authentication / security | Password (stored hashed), session tokens, IP address at login, last activity | System | Secure sign-in, session handling, fraud and abuse prevention | Art. 6(1)(c) – legal obligation, and (f) – legitimate interest |
| Usage analytics | Pages viewed, events, Credit consumption and balance | System | Metering, billing, operations, product improvement | Art. 6(1)(b) – contract, and (f) – legitimate interest |
| Project content | Drawings, annotations, comments, Output, exports | Uploaded by Customer | Provide the Service | Art. 6(1)(b) – contract; for embedded personal data: processor activity under DPA |
| Development data | Drawings, Output, Corrections and Derived Data in pseudonymized form | Derived from project content | Develop, test, calibrate and improve the Service (regression tests, reference data) | Art. 6(1)(f) – legitimate interest |
| Communications / support | Support tickets, email, in-app messages | You | Provide support and meet obligations | Art. 6(1)(b) – contract, and (f) – legitimate interest |
| Marketing | Name, email, company, role, subscription status, open and click statistics | You, your administrator or website sign-up | Newsletters, product news, invitations and offers | Art. 6(1)(f) – legitimate interest (existing customer relationship, B2B), or (a) – consent (newsletter without customer relationship) |
| Billing data | Company name, invoice address, VAT number, payment metadata | You or payment provider | Invoicing and accounting | Art. 6(1)(c) – legal obligation (Bookkeeping Act) |
| Cookies / local storage | Session token, CSRF token, language preference, selected company context, optional analytics | Browser | Functionality and optional analytics | Art. 6(1)(f) – legitimate interest, or (a) – consent (analytics/marketing) |
We do not knowingly collect special categories of personal data (e.g. health, religion, political opinions). Such data must not be uploaded to the Service.
4. Purposes of processing
We process personal data to (i) provide and develop the Service in accordance with the contract, (ii) administer your account and communications with us, (iii) provide support and troubleshooting, (iv) issue invoices and keep accounting records, (v) protect the Service against fraud, abuse, intrusion and downtime, (vi) comply with legal obligations and (vii) establish, exercise and defend legal claims.
Development and improvement of the Service. The Service gets better at interpreting drawings when it is tested against real drawings and against the corrections that kalkylatorer make to Output. We therefore use uploaded drawings, Output, Corrections and Derived Data to develop, test, calibrate and improve our interpretation methods and models. Our legitimate interest is to provide an accurate service. The interests of data subjects are protected by (i) removing or pseudonymizing personal data before material is used for development purposes, (ii) restricting access to FutureCalc's development staff and sub-processors bound by confidentiality, (iii) never disclosing the material to other customers in identifiable form and (iv) never using the material to train third-party foundation models. Our balancing test is available on request via privacy@futurecalc.ai. Customers with an Enterprise agreement may agree on limitations.
Marketing. We send product news, newsletters and offers by email to contact persons at existing and former customers and to people who have signed up for our newsletter. Emails to contact persons at customer companies are sent on the basis of legitimate interest in accordance with the Swedish Marketing Act (marknadsföringslagen, 2008:486); emails to others are sent only with consent. Every email contains an unsubscribe link, and you can opt out at any time via privacy@futurecalc.ai. We measure opens and clicks to tailor content; such measurement is part of the mailing and stops when you unsubscribe.
No third-party model training. Personal data and Customer Content are never used to train external language or generative AI models. Where we use external providers for individual interpretation steps, processing takes place under "zero retention" or "no training" terms to the extent the provider offers such terms.
Aggregated and anonymized data. We may use fully aggregated and anonymized data, which cannot be linked to an identifiable individual, for business intelligence, security and product improvement, including after your account is closed.
5. Recipients and sub-processors
To deliver the Service we engage carefully selected sub-processors within the following categories:
| Category | Function | Data | Region | Transfer mechanism |
|---|---|---|---|---|
| Cloud infrastructure | Database, authentication, file storage and hosting | Account data, project content, logs | EEA | EEA; SCC for support access from outside the EEA |
| Compute platform | Processing of uploaded files and development data | Project content during processing, development data | EEA | EEA; SCC where required |
| Network and security services | DNS, content delivery and protection against automated attacks | IP address, request metadata | Global edge, EU data primarily within the EEA | SCC or EU-US Data Privacy Framework |
| Transactional email | Invitations, password reset and system messages | Name, email, message metadata | EEA or US | SCC or EU-US Data Privacy Framework |
| Consent management | Cookie banner and storage of consents on the website | IP address (truncated), consent ID, browser information | EEA | EEA |
| Marketing platform | Newsletters, mailings and subscription management | Name, email, company, open and click statistics | EEA | EEA |
| Development and operations tools | Source code management, issue tracking and error monitoring | No personal data from the Service intentionally; may occur in error reports | EEA or US | SCC or EU-US Data Privacy Framework |
| Payment provider | Card payments and subscription billing | Company name, invoice address, payment metadata | EU and/or US | SCC + supplementary measures |
| External interpretation service | Individual interpretation steps under "no training" terms | Extracts from drawings | EU or US | SCC + supplementary measures |
The full, named list of current sub-processors is provided to business customers under the DPA. Customers with a DPA are notified of additions or changes at least thirty (30) days in advance and have the right to object to material changes. Other data subjects may request information via privacy@futurecalc.ai.
In addition, personal data may be disclosed to (i) banks, auditors and other advisors to the extent required by law, (ii) public authorities pursuant to mandatory disclosure obligations, (iii) acquirers in connection with the sale, merger or restructuring of our business and (iv) where necessary to defend our legal claims.
We never sell personal data and do not share data for third-party marketing purposes.
6. International transfers
Some sub-processors may process personal data outside the EEA. Such transfers rely on the European Commission's Standard Contractual Clauses (SCC, Decision 2021/914) or, where the recipient is certified, the EU-US Data Privacy Framework, combined with technical and organizational supplementary measures (encryption in transit and at rest, access controls, data isolation between Customer organizations, time-limited download links). Development data under section 4 is stored within the EEA.
You may request a copy of the applicable safeguards via privacy@futurecalc.ai.
7. Retention periods
| Data | Retention |
|---|---|
| Account during active subscription | For the lifetime of the account |
| Account after deletion request | Erased within 30 days, except backups (max 90 days) |
| Project content in the production environment | Until the Customer deletes it or the subscription ends + 30-day grace period |
| Development data (pseudonymized) | As long as needed for development and regression testing of the Service; unaffected by account or subscription termination |
| Invoices and accounting records | 7 years pursuant to chapter 7 section 2 of the Bookkeeping Act |
| Login and audit logs | 12 months |
| Automated Takeoff logs (metadata) | 30 days |
| Transactional email logs | 30 days |
| Support tickets | 24 months after the ticket is closed |
| Marketing mailings | Until you unsubscribe, and no longer than 24 months after your last interaction (open, click or customer relationship) |
| Personal data needed for legal claims | As long as the claim may be asserted, in any case no more than 10 years |
We delete or anonymize data when it is no longer needed for the purpose for which it was collected, unless another legal basis justifies further retention.
8. Your rights
Under the GDPR you have the right to:
(a) be informed about our processing (Art. 13–14);
(b) request access to your personal data (Art. 15); one register extract is provided free of charge per year, and for manifestly unfounded or excessive requests we may charge a reasonable fee or refuse;
(c) rectify inaccurate or incomplete data (Art. 16);
(d) erase your data (Art. 17), except where retention is required by law (e.g. accounting records) or where data has been pseudonymized for development purposes and can no longer be linked to you without disproportionate effort (Art. 11);
(e) restrict processing (Art. 18);
(f) data portability, i.e. receive your data in a structured, machine-readable format (JSON export, Art. 20);
(g) object to processing carried out on the basis of legitimate interest (Art. 21), including use for development purposes; we will then assess whether our compelling legitimate grounds override your interests;
(h) withdraw consent at any time without affecting the lawfulness of prior processing (Art. 7(3));
(i) lodge a complaint with IMY or the supervisory authority in the EEA member state where you reside or work.
Requests should be sent to privacy@futurecalc.ai. We normally respond within 30 days of receiving a complete request. For complex requests, or a high volume of simultaneous requests, the deadline may be extended by an additional two months; we will inform you in such case.
In order to handle your request, we may need to verify your identity, for example by confirming that the request comes from the email address registered for your account.
If you are a user under a corporate account, you should first contact your company's administrator; in many cases we will need to refer the request to them. If you appear in a drawing uploaded by one of our customers, that customer is the controller for that processing and the right addressee for your request.
9. Security measures
We take appropriate technical and organizational measures to protect personal data against unauthorized access, alteration, loss or disclosure, including:
- Logical tenant isolation between Customer organizations at the database layer.
- Least privilege with role-based access control at the application and database layers.
- Passwords stored only in hashed form using industry-standard methods.
- Encryption using modern protocols both in transit and at rest.
- Time-limited download links for files in storage.
- Audit log for administrator actions and per-user activity log.
- Forced session termination and account blocking on security events.
- Protection against automated attacks and credential stuffing at sign-in.
- Pseudonymization of development data and separate access control for such data.
- Recurring review of access rights and sub-processors.
- Backups with defined recovery time (RTO) and recovery point (RPO).
- Personnel bound by confidentiality and trained in data protection and information security.
No system is fully secure. We cannot guarantee absolute security and take measures based on industry practice and risk assessment.
10. Cookies and local storage
Strictly necessary cookies / local storage are used for the Service to function (session token, CSRF protection, language preference, selected company context). These do not require consent under the Swedish Electronic Communications Act and the ePrivacy Directive.
Analytics or marketing are used only with your consent via a cookie banner. Such scripts are not loaded until consent is given. You may withdraw consent at any time via the cookie settings.
More information is provided in our cookie policy at futurecalc.ai/cookies.
11. Children
The Service is not directed to anyone under 16. We do not knowingly collect personal data from minors. If we learn that we have collected data from a person under 16 without appropriate consent, we delete the data without delay.
12. Personal data breaches
In the event of a personal data breach likely to result in a risk to the rights and freedoms of natural persons, we notify IMY within 72 hours of becoming aware of it (GDPR Art. 33). Where the risk is high, we also inform affected data subjects without undue delay (Art. 34).
For breaches affecting Customer Content, we notify the relevant Customer in its capacity as controller in accordance with the DPA, so that the Customer can comply with its own notification obligations.
13. Changes to this Policy
We may update this Policy from time to time. The current version is published at futurecalc.ai/privacy with a date stamp.
For material changes, we will notify you by email or in the Service at least 30 days before the effective date. Minor changes (typographical fixes, clarifications, legally required updates, changes in your favor) take effect immediately.
Previous versions of the Policy are archived and provided on request.
14. Contact and complaints
Questions, requests to exercise your rights and complaints should be sent to privacy@futurecalc.ai or by mail to the address above.
You always have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or the supervisory authority in the EEA member state where you reside or work:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm
Phone: +46 8-657 61 00
Web: imy.se
Email: imy@imy.se