Vesence Privacy Notice

Version 1.1.0 · Effective 2 October 2026

Effective 2 October 2026.

1. About this notice

This notice explains how Vesence AB ("Vesence", "we", "us") processes personal data as a controller in connection with the Service. The Service means the workspace at desktop.vesence.com, the Vesence desktop app, and related features and support. It applies to Users of the Service, to administrators and billing contacts of our Customers, and to people who contact us about the Service.

Customer Content is covered by the DPA, not this notice. The documents, emails, chats and other content that Users put into or connect to the Service belong to our Customer, usually your employer. We process that content as the Customer's processor under the Vesence Data Processing Agreement. If you have a question about personal data in that content, contact the Customer. They decide how it is used.

The Vesence add-ins for Microsoft Word, Excel, PowerPoint and Outlook, the web application at app.vesence.com and our website are covered by the privacy notice at vesence.com/privacy.

2. Who we are

Vesence AB, reg. no. 559456-6902, Biblioteksgatan 11, 111 46 Stockholm, Sweden, is the controller. Contact us about privacy at legal@vesence.com.

3. What we process and why

We collect this data from you, from your organization when it invites you or manages your account, from the sign-in provider you use (Microsoft or Google), and from your use of the Service.

PurposePersonal dataLegal basisHow long we keep it
Your account and sign-inName, email address, sign-in provider and account identifier, your organization's Microsoft tenant or Google domain, Workspace membership and role, chosen region, sign-in sessionsContract, where you contract with us yourself. Otherwise our legitimate interest in providing the Service your organization usesWhile your account exists, and up to 90 days after it is closed
Connected ServicesWhich Microsoft or Google accounts you connect, the permissions you grant, and access tokens (stored encrypted)As for your accountUntil you disconnect, your provider revokes access, or your account is closed
Running and securing the ServiceIP address, device and browser information, request and error logs, desktop app version and update checksLegitimate interest in keeping the Service working, secure and free of abuseLogs: up to 30 days, unless needed longer to investigate a specific incident
Improving the ServiceHow features are used and how much storage is used, linked to your account. We use no third-party analytics or advertising toolsLegitimate interest in developing the ServiceWhile your account exists, and up to 90 days after it is closed. We may keep aggregated statistics that do not identify you
Orders, billing and paymentBilling contact name, email and company details, VAT number, Order and invoice history. Card details are handled by our payment provider; we never see full card numbersContract; legal obligation (bookkeeping)Accounting records: 7 years after the end of the financial year, as Swedish bookkeeping law requires. Other billing data: while the Order is active, then 1 year
Support and service communicationsYour messages to us, and notices we send about your account, security or changes to our termsLegitimate interest in supporting Customers and informing Users; contract1 year after the last communication; legal notices for as long as the Agreement plus the limitation period
Legal obligations and legal claimsAny of the above, as neededLegal obligation; legitimate interest in establishing, exercising or defending legal claimsAs long as the law requires or the claim lasts

We do not use your personal data for automated decisions that have legal or similarly significant effects on you. We never sell personal data. We do not use it, or Customer Content, to train AI models.

4. Cookies

The Service uses only the cookies it needs to keep you signed in and to complete sign-in. These are strictly necessary, so we do not ask for consent. We use no analytics, advertising or tracking cookies in the Service.

5. Who we share personal data with

  • Service providers acting for us. Examples are Cloudflare (hosting, storage and logs) and our payment provider. They process personal data only on our instructions.
  • Your organization. Your Workspace administrators can see your account details, role and activity in the Workspace, and manage or close your account.
  • People you choose to share with. For example, other Vesence users you add to a shared drive can see your name and email address.
  • Microsoft and Google. When you sign in or connect an account, we exchange data with them to authenticate you and to act on your instructions.
  • Authorities, courts and advisers, where the law requires it or to establish, exercise or defend legal claims.
  • A buyer or successor, if our business is reorganized or sold. Your data stays protected under this notice.

6. Transfers outside the EU/EEA

Some of our service providers process data outside the EU/EEA. Cloudflare, Inc., for example, is based in the United States. We transfer data only with a valid safeguard: the EU–US Data Privacy Framework where the recipient is certified, or the EU Standard Contractual Clauses. Ask us at legal@vesence.com for a copy of the relevant safeguards.

7. Security

We protect personal data with technical and organizational measures, including encryption in transit and at rest, encrypted storage of access tokens, and access restricted to personnel who need it.

8. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you and receive a copy;
  • rectify inaccurate data;
  • erase your data, where there is no longer a reason to keep it;
  • restrict our processing, for example while we check a complaint;
  • data portability, for data you gave us under a contract;
  • object to processing based on our legitimate interests.

To exercise a right, email legal@vesence.com. We respond within one month. If your request concerns Customer Content, we will refer you to the Customer, as the DPA requires.

You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se, or to the data protection authority where you live or work.

9. Changes to this notice

We may update this notice. We will post the new version with its effective date and keep earlier versions, which we provide on request. If a change materially affects you, we will tell you by email or in the Service before it takes effect.