Policy

Privacy notice.

What this public site receives, why JD Legal AB uses it, and what control you have.

Effective

10 August 2026

Short version: the corporate site uses no advertising, behavioural analytics, or non-essential cookies. If you use the contact form, we use what you submit to administer and answer the inquiry.

1. Data controller

JD Legal AB (organisation number 559557-7064; VAT SE559557706401), Hamngatan 24A, 172 66 Sundbyberg, Sweden, is the controller for processing described here. Use the contact form and select “Privacy or data-rights request,” or write to that postal address.

2. Scope

This notice covers macchiatolabs.ai, its public pages, and its contact and withdrawal forms. Macchiato Labs products provide additional product-specific privacy information for account, usage, payment, audio, and other data relevant to that product.

3. Personal data, purposes, and legal bases

Website delivery and security

The hosting layer may process IP address, date and time, requested URL, response status, referrer, browser or user-agent information, and security events. We use this to deliver the site, diagnose faults, prevent abuse, and maintain security. The legal basis is our legitimate interest in operating a secure, reliable public website (GDPR Article 6(1)(f)).

Contact and support inquiries

If you submit a form, we process your name, email address, selected topic, message, page path, submission time, and an internal reference. We do not intentionally persist your IP address with the inquiry. We use the record to route, answer, document, and protect the inquiry.

The legal basis is steps requested before a possible contract or administration of a contract where applicable (Article 6(1)(b)); our legitimate interests in communicating, supporting products, handling complaints, and establishing or defending legal claims (Article 6(1)(f)); or a legal obligation where the inquiry concerns rights we must administer (Article 6(1)(c)).

Withdrawal notices

If you use the online withdrawal form, we process identity and contact details, order reference, product, statement, timestamp, and receipt reference to register and respond to the notice. The legal bases are contract administration, legal obligations, and establishment or defence of legal claims.

4. Sources and whether data is required

We receive form information directly from you. Basic technical data is generated when your browser connects to the server. Required form fields are necessary to identify and answer the inquiry or withdrawal notice; optional details can be omitted. If required information is missing, we may be unable to act on the request.

Please do not submit passwords, full payment-card details, identity documents, health data, or other unnecessary sensitive information.

5. Processors, recipients, and transfers

The website and private form records are hosted on DigitalOcean infrastructure in its Amsterdam region. DigitalOcean acts as infrastructure provider and may use approved subprocessors. As a US-based provider, access or support involving countries outside the EEA may occur subject to applicable contractual and organisational transfer safeguards.

Within JD Legal AB, data is available only to people who need it for the stated purpose. We may disclose information to professional advisers, authorities, courts, counterparties, or security providers when reasonably necessary and lawful. We do not sell personal data.

6. Retention

  • Ordinary contact and support records: normally up to 24 months after the inquiry is closed.
  • Withdrawal, billing, complaint, contract, and legal-claim records: for the applicable statutory bookkeeping, limitation, consumer-protection, or claims period.
  • Routine web and security logs: normally no more than 30 days, unless an event must be retained longer to investigate abuse or protect legal rights.

We may delete obviously abusive, empty, or accidental submissions sooner. Backups may retain securely isolated copies until their scheduled rotation.

7. Cookies, local storage, and analytics

This corporate site sets no advertising, analytics, personalisation, or other non-essential cookies, and it does not use browser local storage for tracking.

8. Your rights

Subject to the GDPR and applicable exceptions, you may request access, correction, deletion, restriction, portability, or objection to processing based on legitimate interests. You may also ask us to explain a decision. This site does not perform solely automated decisions with legal or similarly significant effects.

To exercise a right, use the privacy contact topic or write to the controller address. We may need proportionate information to verify identity. You may complain to Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden, at imy.se, or to the competent authority where you live or work.

9. Security

The public site is encrypted with HTTPS. We apply technical and organisational measures appropriate to the data and risks involved. No online system is risk-free; please limit messages to information needed for the inquiry.

10. Changes

We update this notice when site processing changes materially. Changes apply from the effective date shown above.