Privacy Policy
Introduction
Welcome to Econello. This Privacy Policy explains how Econello AB collects, uses, stores, and protects your personal data when you visit www.econello.com. Our website provides multilingual financial comparison tools, educational guides, and company reviews to help individuals make informed financial decisions.
We are committed to protecting your privacy and handling your personal data in full compliance with the General Data Protection Regulation (GDPR) and applicable Swedish data protection law. By using our website, you acknowledge that you have read and understood this policy. If you do not agree with any part of this policy, please discontinue your use of our website.
This policy applies to all visitors, users, and individuals who interact with our website or contact us directly.
Data Controller
The data controller responsible for your personal data is:
- Company: Econello AB
- Address: Fjallvagen 14, 981 91 Junosuando, Sweden
- Email: [email protected]
If you have any questions about how we process your personal data, or if you wish to exercise any of your rights under the GDPR, please contact us using the details above. We will respond to all requests within 30 days.
What Data We Collect
We collect two categories of personal data: data collected automatically when you visit our website, and data you provide to us voluntarily.
How We Use Your Data
We use the personal data we collect for the following purposes:
- Website analytics: To understand how visitors use our website, which content is most popular, and how we can improve the user experience.
- Content improvement: To identify gaps in our financial guides and reviews and ensure our content remains accurate and relevant.
- Responding to inquiries: To reply to messages submitted through our contact form or sent directly to our email address.
- Website security and performance: To detect and prevent fraudulent activity, technical errors, and unauthorized access.
We do not sell, rent, or trade your personal data to third parties for marketing purposes.
Legal Basis for Processing
Under the GDPR, we must have a lawful basis for processing your personal data. We rely on the following legal grounds:
- Legitimate interests (Article 6(1)(f) GDPR): We process automatically collected data such as IP addresses and browsing behavior to maintain website security, improve our content, and analyze traffic patterns. We have assessed that our legitimate interests do not override your fundamental rights and freedoms.
- Consent (Article 6(1)(a) GDPR): Where we use non-essential cookies, such as analytics cookies, we will request your consent before placing them on your device. You may withdraw your consent at any time through your browser settings or our cookie management tool.
- Contract performance (Article 6(1)(b) GDPR): When you contact us with a specific request or inquiry, we process your data to respond to that communication.
Cookies
Our website uses cookies to enhance functionality and collect analytics data. Cookies are small text files stored on your device by your browser. We use the following types of cookies:
- Essential cookies: Required for the website to function correctly. These cannot be disabled without affecting core functionality.
- Analytics cookies: Used to collect aggregated, anonymized data about how visitors interact with our website. This helps us improve our content and structure.
- Functionality cookies: Used to remember your preferences, such as language selection, to provide a more personalized experience.
You can manage or disable cookies at any time through your browser settings. Please note that disabling certain cookies may affect the performance and functionality of our website. Most modern browsers allow you to block or delete cookies through their privacy or security settings.
Third-Party Services
We use a limited number of trusted third-party services to operate and improve our website:
- Google Analytics: We use Google Analytics to analyze website traffic and user behavior. Google may process data on servers located outside the European Economic Area. Google Analytics is configured to anonymize IP addresses. For more information, visit Google’s Privacy Policy.
- Hosting provider: Our website is hosted on a secure server. Our hosting provider may process certain technical data as part of normal server operations. We ensure that our hosting provider complies with GDPR requirements.
We do not share your personal data with third parties beyond what is necessary for these services to function.
Data Retention
We retain personal data only for as long as necessary to fulfill the purposes described in this policy:
- Contact form submissions: Retained for up to 12 months after your inquiry is resolved, unless a longer retention period is required by law.
- Analytics data: Aggregated and anonymized analytics data may be retained for up to 26 months, in line with Google Analytics default settings.
- Server logs: Technical log files are typically retained for up to 90 days for security and troubleshooting purposes.
Once data is no longer needed, it is securely deleted or anonymized.
Your Rights Under GDPR
As a resident of the European Union or European Economic Area, you have the following rights regarding your personal data:
- Right of access: You may request a copy of the personal data we hold about you.
- Right to rectification: You may ask us to correct any inaccurate or incomplete data.
- Right to erasure: You may request that we delete your personal data, subject to certain legal conditions.
- Right to data portability: You may request that we provide your data in a structured, machine-readable format.
- Right to object: You may object to the processing of your data where we rely on legitimate interests as our legal basis.
- Right to withdraw consent: Where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
To exercise any of these rights, please contact us at [email protected]. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at www.imy.se.
Data Security
We take the security of your personal data seriously. We implement appropriate technical and organizational measures to protect your data against unauthorized access, loss, alteration, or disclosure. These measures include:
- SSL/TLS encryption: All data transmitted between your browser and our website is encrypted using industry-standard HTTPS protocols.
- Secure hosting: Our website is hosted on servers that meet modern security standards, including firewalls and regular security updates.
- Access controls: Access to personal data is restricted to authorized personnel only, on a need-to-know basis.
While we take every reasonable precaution, no method of data transmission over the internet is entirely secure. We cannot guarantee absolute security but are committed to addressing any breach promptly and transparently.
Children’s Privacy
Our website is not directed at children under the age of 16. We do not knowingly collect personal data from individuals under 16. If you believe that a child has provided us with personal data without appropriate parental consent, please contact us immediately at [email protected] and we will take steps to delete such data as quickly as possible.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements, or the services we offer. When we make significant changes, we will update the Last Updated date at the bottom of this page. We encourage you to review this policy periodically to stay informed about how we protect your data.
Continued use of our website after any changes to this policy constitutes your acceptance of the updated terms.
Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or the way we handle your personal data, please do not hesitate to reach out to us:
- Email: [email protected]
- Address: Econello AB, Fjallvagen 14, 981 91 Junosuando, Sweden
We are committed to resolving any concerns promptly and transparently. All requests will be acknowledged within 5 business days and fully addressed within 30 days.
Last updated: February 2026