Privacy Policy
& cookies
Applies to thern.io and all subdomains · GDPR (EU) 2016/679
- 1.Who is responsible
- 2.Data we collect
- 3.Cookies and similar technologies
- 4.Advertising & Google AdSense
- 5.Other recipients
- 6.Purposes & legal basis
- 7.How long we keep data
- 8.Transfers outside the EU/EEA
- 9.Your rights
- 10.Changing or withdrawing consent
- 11.Children's privacy
- 12.Security
- 13.Links to other sites
- 14.Changes & contact
01Who is responsible for your data
The data controller for this website is Jonaz Thern, a sole trader registered in Sweden, company registration number 781229-2733, email info@thern.io.
This policy covers thern.io and its subdomains, and describes the personal data processed when you visit the site, contact us, order services or are shown advertising here. It does not cover websites we link to.
We are not required to appoint a Data Protection Officer under Article 37 GDPR. Questions about personal data are answered at the contact address above.
02What data we collect
Data you provide yourself. Name, email address, phone number, company name, company or VAT number, billing address, and whatever you write in forms, support tickets, the chat, quote requests and orders.
Data created when you use the site.
- Server logs — IP address, timestamp, page requested, referring page, browser and operating system. These are created automatically by the web server and used for operation, troubleshooting and security.
- Visitor statistics — we run our own lightweight counter instead of Google Analytics. Each visit is counted through a one-way hash (SHA-256) of the IP address and browser string, so the same visitor is not counted twice on the same day. The IP address is stored alongside the visit to derive approximate country and to filter out bot traffic. No profile is built and the data is never sold.
- Cookies and browser storage — see section 3.
Purchase data. Order lines, amounts, invoice numbers, payment status and the accounting records required by Swedish bookkeeping law. We never store full card numbers — card payments, where offered, are handled directly by the payment provider.
Account and sign-in. If you create a customer account we store your email address, your password in hashed form (never in plain text) and sign-in history. If you opt in to push notifications we also store the subscription key your browser generates.
We do not knowingly process special categories of data under Article 9 GDPR. Please do not send health, political or similar information through our forms or chat.
03Cookies and similar technologies
A cookie is a small text file stored in your browser. We also use localStorage, which works in a similar way. Under the Swedish Electronic Communications Act we may only use non-essential cookies with your consent, which you give in the cookie notice shown on your first visit.
We group them into three categories:
- Strictly necessary (no consent required) — language choice, session ID when signed in, shopping cart, the choice you make in the cookie notice (
thern_cookie_consent), and Cloudflare Turnstile, the human-verification check protecting our forms. - Statistics — our own visitor counter described in section 2.
- Advertising — cookies set by Google and its advertising partners, described in section 4. These are only set if you consent to advertising cookies.
You can block or delete cookies in your browser settings at any time. Blocking strictly necessary cookies will break sign-in, the cart and our forms. More about cookies at the Swedish Post and Telecom Authority.
04Advertising & Google AdSense
Parts of this website are funded by advertising served through Google AdSense, a service provided by Google Ireland Limited (Gordon House, Barrow Street, Dublin 4, Ireland). The following applies:
- Third-party vendors, including Google, use cookies to serve ads based on your prior visits to this website and other websites.
- Google's use of advertising cookies — including cookies for advertising and personalisation — enables Google and its partners to serve ads to you based on your visit to thern.io and/or other sites on the internet.
- In doing so, Google may process your IP address, device and browser information, the pages you have visited and how you interact with the ads.
- We, as the site owner, never gain access to the cookies or identifiers Google sets, and we cannot identify you personally through the advertising system. We only see aggregated impression and revenue statistics.
Consent in the EU/EEA and the UK. Personalised advertising is only shown if you have consented to advertising cookies. If you do not consent, or choose Essential only, non-personalised ads may be shown — these are based on the content of the page and coarse location rather than on a profile about you. Your choice is collected through a consent mechanism in line with Google's EU user consent policy.
How to opt out of personalised advertising:
- With Google: myadcenter.google.com (formerly google.com/settings/ads), where you can turn off ad personalisation entirely.
- Across many vendors at once: aboutads.info/choices and, for Europe, youronlinechoices.eu.
- On this website: reopen the cookie settings and decline advertising cookies (see section 10).
How Google processes data when you use sites that use its services is described in How Google uses information from sites or apps that use our services and in the Google Privacy Policy. An overview of Google's advertising cookies is available in Types of cookies used by Google.
We do not show advertising inside signed-in customer areas, and we do not use advertising data for automated decisions producing legal effects concerning you.
05Other recipients of your data
We never sell personal data. It is shared only with providers needed to run the business, acting as processors under Article 28 GDPR:
- Inleed AB (Sweden) — web hosting and email. Data is stored on servers within the EU.
- Google Ireland Limited — advertising via AdSense (see section 4).
- Cloudflare, Inc. — Turnstile, the bot check protecting our forms. Processes IP address and technical signals during the check itself.
- Anthropic PBC — the language model behind the help chat on this site. What you type in the chat is sent to Anthropic's API to generate the reply. Please do not enter sensitive data, passwords or third-party information in the chat.
- Payment and banking providers — bank, Swish, PayPal or equivalent, depending on the payment method you choose. These are independent controllers for their part of the payment.
- Accounting and audit services — to the extent required by Swedish bookkeeping law.
Data may also be disclosed where required by law or a public authority, or to establish, exercise or defend legal claims.
06Purposes and legal basis
- Delivering ordered services, handling orders, accounts and support — contract (Art. 6(1)(b)).
- Invoicing and accounting — legal obligation (Art. 6(1)(c)), Swedish Bookkeeping Act (1999:1078).
- Operation, troubleshooting and security, including server logs and bot protection — legitimate interest (Art. 6(1)(f)) in keeping the site available and protected.
- Visitor statistics — consent (Art. 6(1)(a)) given in the cookie notice.
- Advertising and advertising cookies — consent (Art. 6(1)(a)).
- Newsletter — consent (Art. 6(1)(a)), given through double opt-in by email, withdrawable at any time via the link in each mailing.
- Answering enquiries and quotes — legitimate interest or pre-contractual steps (Art. 6(1)(b) and (f)).
07How long we keep your data
- Accounting records, invoices and order history — seven years after the end of the calendar year in which the financial year ended, as required by Swedish bookkeeping law.
- Customer accounts — for as long as the account is active. Deleted or anonymised on request, except for what bookkeeping law requires us to keep.
- Support and email correspondence — normally 24 months after the case is closed.
- Server logs — normally no longer than 12 months.
- Visitor statistics — aggregated figures are kept on an ongoing basis; visit rows containing IP addresses are normally purged within 14 months.
- Newsletter — until you unsubscribe.
- Advertising cookies — for the lifetimes set by Google; they are removed when you clear cookies in your browser.
08Transfers outside the EU/EEA
The website is hosted in Sweden. Some of the providers in section 5 — in particular Google, Cloudflare and Anthropic — are US companies and may process data outside the EU/EEA.
Such transfers rely on the European Commission's adequacy decision for the United States (EU–US Data Privacy Framework) where the provider is certified, and otherwise on the European Commission's Standard Contractual Clauses (SCCs) together with supplementary safeguards. You may request a copy of the safeguards applied by contacting us.
09Your rights
Under the GDPR you have the right to:
- Access the personal data we hold about you.
- Rectification of inaccurate data and completion of incomplete data.
- Erasure when the data is no longer needed, when you withdraw consent, or when there is no legal basis for the processing.
- Restriction of processing while an objection or correction is being assessed.
- Object to processing based on legitimate interest, and at any time to direct marketing.
- Data portability — receive your data in a machine-readable format and transfer it elsewhere.
- Withdraw consent at any time, without affecting processing carried out before the withdrawal.
Contact info@thern.io and we will respond without undue delay and within one month at the latest. If you are not satisfied you may lodge a complaint with the Swedish Authority for Privacy Protection (IMY), Box 8114, 104 20 Stockholm, imy@imy.se.
10Changing or withdrawing your consent
Your cookie choice is stored locally in your browser. To change it:
- Clear site data for thern.io in your browser settings — the cookie notice will reappear on your next visit and you can make a new choice.
- Turn off ad personalisation with Google at myadcenter.google.com, which applies wherever you browse.
- Unsubscribe from the newsletter using the link at the bottom of every mailing.
11Children's privacy
This website is aimed at businesses and adult consumers and is not intended for children under 13. We do not knowingly collect personal data from children. If you are a parent or guardian and discover that your child has provided us with data, contact info@thern.io and we will delete it.
12Security
All traffic to the site is protected with TLS encryption (HTTPS). Passwords are stored hashed, sensitive customer notes are encrypted in the database, and the administration interface requires separate authentication. Access to personal data is limited to what is needed to deliver the service.
In the event of a personal data breach likely to result in a risk to your rights, we notify IMY within 72 hours and inform you where the law requires it.
13Links to other websites
This site contains links to other websites, and advertisements may lead to an advertiser's page. We are not responsible for the content or privacy practices of sites we do not operate. Please read their own policies before providing data there.
14Changes to this policy & contact
We update this policy when our services, providers or the law change. The version that applies is always the one published here, dated at the top of the page. Material changes are announced on the website and, for customers, by email.
Questions about this policy or about how we handle your data: info@thern.io.
Company registration number: 781229-2733
VAT number: SE7812292733
Contact: info@thern.io
Last updated: 2026-08-18 · Version 1.0