Legal
Privacy Policy
Last updated: June 16, 2026 · Corners Sverige AB, trading as Artivex
Introduction
Corners Sverige AB, a company incorporated under Swedish law, trading as Artivex, is the data controller for personal data processed through the Artivex platform at artivex.io.
This Privacy Policy explains how we collect, use, store, and protect your data when you use our platform. We are committed to your privacy and to compliance with the General Data Protection Regulation (GDPR) and applicable Swedish data protection law.
We are committed to complying with GDPR and other applicable privacy regulations.
If you have any questions about this policy, please contact us at david@artivex.io..
What We Collect
We collect the following categories of data:
Account Data
- Name and email address (provided at registration)
- Password (stored as a hashed value — we never store your plain-text password)
- Account preferences and settings
Billing Data
- Subscription plan and billing history
- Payment method details are handled entirely by Stripe — we do not store card numbers or sensitive payment data
Build Data
- AppSpec definitions and system configurations you create
- Generated code and workflow definitions
- Entity schemas, field configurations, and integration settings
Usage Data
- Credit consumption records
- Automation execution logs (status, timestamps, error messages)
- API call logs
Technical Data
- IP Address
- Browser type and version
- Session identifiers (authentication tokens)
- Device Type
How We Use Your Data
We use data collected from you for the following purposes:
- Service Delivery: To operate the Platform, generate your Builds, and run your Systems
- Payment Processing: To manage subscriptions, process payments, and handle billing queries
- System health monitoring: To detect failures, send alerts, and maintain platform reliability
- Transactional communications: To send welcome emails, password resets, credit usage alerts, billing receipts, and service notifications — these are not marketing emails and cannot be opted out of while your account is active
- Platform improvement: We analyse anonymised, aggregated usage patterns (not individual data) to improve the Platform
- Legal compliance: To comply with applicable laws, respond to lawful requests from authorities, and enforce our Terms of Service
We do not sell your personal data. We do not use your data for advertising purposes.
Third-Party Processors
We share data with the following sub-processors to deliver the Platform. Each is bound by appropriate data processing terms. The current, complete list of subprocessors is published at artivex.io/subprocessors and updated whenever a subprocessor is added, removed, or replaced.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database and storage — stores your Build data, System data, and account data | EU-West-1 (Ireland) |
| Stripe | Payment processing — handles all financial transactions and subscription management | US / EU |
| Resend | Transactional email — sends welcome emails, password resets, receipts, and alerts | US |
| Vercel | Hosting — hosts deployed Systems and the Platform itself | Global (edge network) |
| Anthropic | AI processing — when your workflows include AI steps using Claude, data from those steps is processed by Anthropic | US |
| OpenAI | AI processing — when your workflows include AI steps using GPT models, data from those steps is processed by OpenAI | US |
| Mistral AI | AI processing — when your workflows include AI steps using Mistral models, or when EU-only AI mode is enabled, data from those steps is processed by Mistral | EU (France) |
Important note on AI step processing:
When you configure an AI step in your workflow, data from that step is sent to the selected AI provider (Anthropic, OpenAI, or Mistral) for processing. You control which data enters AI steps via your workflow configuration. For workflows processing personal data, we strongly recommend anonymising or masking personal data before it enters AI steps, unless you have confirmed that processing by the relevant AI provider is permitted under your compliance obligations.
Data Storage and Location
All primary data — your account data, Build data, System data, and usage data — is stored in the EU via Supabase EU-West-1 (Ireland). This is our primary data store.
Vercel may serve your deployed Systems from edge locations globally to minimise latency for your end users. Static assets and cached responses may be distributed across Vercel's global edge network.
AI providers (Anthropic, OpenAI) process data in the US per their own data processing terms. Data sent to AI providers in workflow AI steps is processed and returned but not persistently stored by those providers beyond their standard retention periods.
Where data is transferred outside the EU, appropriate safeguards are in place as described in our Data Processing Agreement.
Data Retention
- Active accounts: All account and Build data is retained for as long as your account is active.
- Account deletion: When you delete your account, all associated personal data, Build data, and System data is purged within 30 days. You will receive a confirmation email when deletion is complete.
- Execution logs: Automation execution logs are retained for 90 days and then automatically purged. This applies to all plans.
- Billing records: Financial transaction records may be retained for longer periods where required by Swedish tax law or other applicable regulations.
- Data export: You may request a full export of your data at any time before deletion. See Section 7 for how to exercise this right.
Your GDPR Rights
As a data subject under the GDPR, you have the following rights with respect to your personal data:
Right of Access (Art. 15)
Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16)
Request correction of inaccurate or incomplete personal data.
Right to Erasure (Art. 17)
Request deletion of your personal data ("right to be forgotten").
Right to Portability (Art. 20)
Receive your data in a structured, machine-readable format.
Restrict Processing (Art. 18)
Request that we limit how we use your personal data.
Right to Object (Art. 21)
Object to processing of your personal data in certain circumstances.
Withdraw Consent
Withdraw consent at any time where processing is based on consent.
Supervisory Authority
Lodge a complaint with the Swedish Authority for Privacy Protection (IMY) at imy.se.
To exercise any of these rights, email us at david@artivex.iowith a clear description of your request. We will respond within 30 days. We may need to verify your identity before processing the request.
Children
The Artivex Platform is intended for business use and is not directed at children under 18 years of age. We do not knowingly collect personal data from individuals under 18.
If you believe a person under 18 has provided personal data to us, please contact us at david@artivex.ioand we will delete that data promptly.
Data Processing Agreement
When customers use Chromoly to process personal data on behalf of their own clients, employees, or users, Chromoly acts as a data processor, while the customer remains the data controller.
In these circumstances, a Data Processing Agreement (DPA) governs the relationship. Our DPA is available at artivex-dpa.html and is provided on request to paying Customers.
If you are a business using Artivex to process personal data of your customers or employees, please contact david@artivex.ioto execute the DPA before processing begins.
Data Breach
In the event of a personal data breach affecting your data, Artivex will:
- Notify affected users within 72 hours of becoming aware of the breach
- Report the breach to the relevant supervisory authority (Swedish IMY) within 72 hours as required by GDPR Article 33
- Provide you with details of: the nature of the breach, the categories and approximate number of data records affected, the likely consequences, and the measures taken or proposed to address the breach
- Take immediate steps to investigate, contain, and remediate any unauthorized access or security vulnerability.
Our tenant isolation architecture (row-level security, separate access credentials per Customer) is designed to contain the impact of any breach to a single tenant.
Changes
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email at least 30 days before the changes take effect.
When we make material changes, we will notify you by email or through a prominent notice on the Platform before the updated policy becomes effective.
The "Last Updated" date at the top of this page will always reflect when the policy was last revised. We encourage you to review this policy periodically.
Contact
For all privacy-related enquiries, data subject requests, or questions about this Privacy Policy, please contact us using the details below.
- Data Controller: Corners Sverige AB (trading as Artivex)
- Email: david@artivex.io
- Website: artivex.io
For complaints that we are unable to resolve, you may contact the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten — IMY) at imy.se.