Piik Labs AB · Version 1.0.0
Privacy Policy
- Effective
- 8 August 2026
- Last updated
- 8 August 2026
Applies to the website at piiklabs.com. Piik Labs' products, including BDYCTRL, Quots and Buzzmark, are covered by their own separate privacy policies.
Download PDF (opens in a new tab)1. Who We Are
This Privacy Policy applies to Piik Labs AB, a company registered in Sweden with organisation number 559577-8506 (the “Company”, “we”, “us”, “our”).
We operate the website at piiklabs.com (the “Website”). It is our own company website: it says who we are and shows the products we build.
As the entity that determines the purposes and means of processing your personal data, Piik Labs AB acts as the data controller under the EU General Data Protection Regulation (Regulation (EU) 2016/679, “GDPR”) and the Swedish Data Protection Act (lag (2018:218) med kompletterande bestämmelser till EU:s dataskyddsförordning).
1.1Scope — which website this policy covers
This is the company's own website, not a product. Piik Labs AB operates products under separate brands, including BDYCTRL, Quots and Buzzmark. This Privacy Policy applies only to piiklabs.com. Each product has its own privacy policy covering its own processing, and nothing described here extends to them. Visiting piiklabs.com does not create an account with any Piik Labs product and does not add you to any mailing list.
1.2What the Website does
The Website has no accounts, no sign-in, no forms, no newsletter, and nothing to buy. The only way to give us personal data through it is to use the email link and write to us, which is entirely your choice.
That is why this Policy is short. It describes two things: the server logs generated when your browser requests a page, and the email you send us if you decide to.
1.3Contact
- Data controller
- Piik Labs AB
- Organisation number
- 559577-8506
- VAT number
- SE559577850601
- Registered address
- Box 691, 414 52 Göteborg, Sweden
- Enquiries, including privacy
- hello@piiklabs.com
- Supervisory authority
- Integritetsskyddsmyndigheten (IMY) · imy.se · imy@imy.se
Data Protection Officer. We have not designated a Data Protection Officer under Article 37 GDPR, as we are not required to do so. All privacy matters are handled directly by the Company and should be directed to hello@piiklabs.com.
2. Scope of This Policy
This Policy applies to all personal data we collect when you visit the Website or contact us using the address published on it. It does not apply to third-party websites or services linked from the Website, including our own product websites at bdyctrl.com, getquots.com and buzzmark.ai, or the social media platforms on which we maintain accounts. Each of those has its own privacy policy.
3. Personal Data We Collect
3.1Data you provide
| Data | When we collect it |
|---|---|
| Your email address, and anything you choose to include in your message | When you email us at hello@piiklabs.com, whether by clicking the link on the Website or otherwise. |
The Website itself collects nothing you type. It has no contact form, no newsletter signup, and no input field of any kind.
3.2Data collected automatically
| Data | Why |
|---|---|
| IP address, browser type and version, operating system, referring page, pages requested, and timestamps | Generated as ordinary server logs by our hosting provider when your browser requests a page. Used to operate, secure and troubleshoot the Website. |
We do not use any website analytics service, advertising network, tracking pixel, retargeting technology, session recording, or heatmap tool on the Website. No third-party script runs on it.
3.3Data we do not collect
For the avoidance of doubt, we do not collect or process through the Website: special category data as defined in Article 9 GDPR; your name, company, phone number or postal address; location data beyond what can be inferred from an IP address; account, profile or authentication data of any kind; payment or card data; or data about children. We hold no mailing list for the Piik Labs brand.
4. How and Why We Use Your Data
We process your personal data only where we have a lawful basis to do so under Article 6 GDPR.
| Purpose | Data used | Lawful basis |
|---|---|---|
| Operating, securing and troubleshooting the Website | Server log data | Legitimate interests, Art. 6(1)(f). Our interest is in keeping the Website available and free from abuse. |
| Responding to you when you contact us | Your email address and the content of your message | Legitimate interests, Art. 6(1)(f), or performance of a contract where your message relates to one. |
| Complying with our legal obligations, and establishing or defending legal claims | Whichever of the above is relevant | Legal obligation, Art. 6(1)(c). Legitimate interests, Art. 6(1)(f). |
We will not use your email address to market to you. If you write to us, we answer you. We do not add you to a list, we do not sell, rent or trade your address, and we do not share it with other companies for their own marketing.
Automated decision-making. We do not carry out automated decision-making producing legal or similarly significant effects concerning you, within the meaning of Article 22 GDPR.
Artificial intelligence. Piik Labs builds products with AI features in them. None of them run on this Website. No personal data collected through the Website is sent to any AI provider, and nothing you send us is used to train a model.
5. Third-Party Services and Data Sharing
We do not sell your personal data. We share data only with service providers who process it on our behalf under data processing agreements, and where required by law.
5.1Service providers (data processors)
- Vercel Inc. (USA) hosts the Website. Server logs are generated and retained by Vercel in the course of serving the site. Vercel is US-incorporated, so its own staff access for support and administration is a transfer covered by section 6. Data processing agreement in place. Review: vercel.com/legal/privacy-policy
- Microsoft Ireland Operations Limited (Ireland) provides Microsoft 365, which hosts the mailbox behind hello@piiklabs.com and therefore stores your message and our reply if you write to us. Microsoft processes this data as our processor under the Microsoft Products and Services Data Protection Addendum. Under Microsoft's EU Data Boundary, customer data for Microsoft 365 is stored and processed within the EU and EFTA; limited transfers continue outside it for remote administration and global security operations, covered by the Standard Contractual Clauses in that Addendum. Review: microsoft.com/privacy
That is the complete list. We use no analytics provider, no advertising provider, no customer relationship management system, no payment provider, no email marketing provider, and no AI provider in connection with the Website.
5.2Disclosure required by law
We may disclose your personal data to law enforcement, regulatory authorities, or courts where we are legally required to do so. We will notify you of any such disclosure where legally permitted.
5.3Business transfers
In the event of a merger, acquisition, or sale of all or part of our assets, your personal data may be transferred to the acquiring entity. We will notify you before your data is transferred and becomes subject to a different privacy policy.
5.4Changes to our service providers
We may add, replace, or remove service providers over time. Where a change is material, for example where a new provider introduces a transfer outside the EEA, or processes a category of data not described here, we will update this Policy in accordance with section 11.
6. International Data Transfers
Piik Labs AB is based in Sweden. Some of our service providers are established outside the European Economic Area (EEA), including in the United States.
When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses approved by the European Commission;
- Transfers to organisations certified under the EU–U.S. Data Privacy Framework, where the provider is certified;
- Supplementary technical and organisational measures where required.
Specifically, the US-side administrative access of our hosting provider, and the limited transfers Microsoft makes outside the EU Data Boundary for remote administration and security operations, are covered by Standard Contractual Clauses. You may request a copy of the applicable safeguards by contacting hello@piiklabs.com.
7. Data Retention
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy, or as required by law.
| Data | Retention |
|---|---|
| Server logs | Retained by our hosting provider for a short operational period, typically no more than 30 days, then deleted. |
| Email correspondence with us | Up to 24 months after the matter is closed, or longer where needed to establish, exercise or defend a legal claim. |
We hold nothing else. There is no account to close and no list to leave.
8. Your Rights Under the GDPR
As a data subject in the EU/EEA, you have the following rights. We will respond to all requests within one month.
- Access (Art. 15) obtain a copy of the data we hold about you.
- Rectification (Art. 16) correct inaccurate or incomplete data.
- Erasure (Art. 17) delete your data.
- Restriction (Art. 18) limit how we process your data in certain circumstances.
- Portability (Art. 20) receive your data in a structured, machine-readable format.
- Objection (Art. 21) object to processing based on our legitimate interests.
We do not rely on consent for any processing described in this Policy, so there is no consent for you to withdraw. If that changes, this Policy will be updated before the processing begins.
To exercise any of these rights, contact hello@piiklabs.com. You may also lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or with the supervisory authority where you live.
10. Data Security
We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. These measures include:
- Encryption of data in transit using TLS 1.2 or higher, enforced across the whole Website;
- Authenticated sending domains with SPF, DKIM and DMARC configured for our mail;
- Access to our hosting and mail accounts restricted to the smallest number of people who need it, protected by multi-factor authentication;
- Credentials for our service providers held in secret storage and never committed to source code;
- A Website with no database, no user accounts and no forms, which removes most of the surface an attacker would otherwise have;
- Selection of processors who offer appropriate security guarantees under Article 28 GDPR.
No method of transmission or storage is completely secure. If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection within 72 hours, and notify you directly where the breach is likely to result in a high risk to you.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the “Last updated” date and the version number at the top of this document;
- Publish the revised version on the Website before it takes effect;
- Where required by law, seek your consent.
The Website has no accounts and no mailing list, so we have no way to notify you of a change directly. The version in force is always the one published on this page, identified by the version number and date at the top.
12. Children's Privacy and Minimum Age
The Website is a company website directed at adults: people interested in what we build, potential partners, and potential hires. It is not directed at children, and we do not knowingly collect personal data from anyone under 16.
The Website collects nothing you type, so there is no signup at which age could be asked or verified. If you believe a person under 16 has sent us personal data, contact us at hello@piiklabs.com and we will investigate and delete that data promptly.
13. Users Outside the EEA
The Website is operated from Sweden and is designed around EU data protection standards. If you visit it from outside the EEA, your personal data will be processed in the EEA and in the other locations described in section 6. Depending on where you live, you may have additional or different rights under local law. Contact us at hello@piiklabs.com and we will tell you what rights apply to you and help you exercise them.
14. Governing Law and Jurisdiction
This Privacy Policy is governed by the laws of Sweden and the European Union, including the General Data Protection Regulation (EU) 2016/679 and the Swedish Data Protection Act (lag (2018:218)).
Any disputes arising from this Policy are subject to the jurisdiction of the Swedish courts, without prejudice to your rights as a consumer under applicable mandatory law in your country of residence.
15. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Data controller
- Piik Labs AB
- Organisation number
- 559577-8506
- VAT number
- SE559577850601
- Registered address
- Box 691, 414 52 Göteborg, Sweden
- Enquiries, including privacy
- hello@piiklabs.com
- Supervisory authority
- Integritetsskyddsmyndigheten (IMY) · imy.se · imy@imy.se
© 2026 Piik Labs AB. All rights reserved.