EuroWork

Data protection and AI usage policy

Updated 26 July 2026

This document describes how EuroWork processes data, where processing takes place and which protections are built into the service. EuroWork is operated by Skräddarsydd AB, Norrgatan 16, 432 41 Varberg, Sweden.

Roles and responsibility

Your organisation is the data controller for the content employees enter into the service (questions, documents, source material). Skräddarsydd AB processes this content as a data processor, solely to deliver the service.

For account and billing data (name, email address, organisation details) Skräddarsydd AB is the data controller.

What data is processed

Account data: name, email address, job title, department, country, language preference and an optional profile picture. The profile picture is visible only to others in your organisation, never outside it.

Work content: conversations, uploaded documents, project sources, assistant material and saved documents. Content is row-level isolated per organisation in the database, one organisation can never read another's data.

Operations and cost log: every AI call is logged with model choice, timestamp, token volume and cost. Prompt and response content is not part of the decision log.

Where data is processed

All storage is within the EU: the database runs in Frankfurt (Germany) and the application in Stockholm (Sweden).

AI processing takes place with Mistral AI in Europe with zero data retention: no prompts or answers are stored by the AI provider, and nothing is used to train their models.

The sensitivity gatekeeper

Before anything is sent to an AI model, the prompt, attached documents and context sources are screened automatically in two layers: deterministic patterns (personal identity numbers, email addresses, phone numbers, IBAN and more) plus a contextual assessment on an EU model.

If sensitive data is detected, the conversation's protection class is raised automatically, the user is informed, and the event is logged. The protection is built fail closed: if the screening cannot decide, the content is treated as sensitive.

Information classes and web search

All content is handled in information classes: public, internal, confidential or prohibited. The class governs which data flows are allowed.

Web search can never be used for confidential content, a platform rule that cannot be switched off. Your organisation can tighten the rules further, never loosen them.

Retention and deletion

Your administrator controls the retention policy: conversations are deleted automatically after a chosen number of days of inactivity per information class. Deletion is recorded in the audit log.

The organisation can export all conversation content (JSON) at any time and request full deletion.

Cookies

The service uses only necessary cookies: a session cookie for signing in and a language cookie that is set only when you actively choose a language yourself. There are no analytics, tracking or third-party cookies, which is why no consent banner is shown.

Country and language for new visitors are derived from the browser's language setting and the network's country of origin on each page view, without storing anything.

Subprocessors

Vercel Inc. (application hosting, EU region Stockholm), Neon Inc. (database, EU region Frankfurt), Mistral AI SAS (AI models, France, zero data retention) and Resend (transactional email such as invitations and password resets).

Stripe is used for payments once billing is activated. Card details are then handled directly by Stripe and never reach EuroWork.

Security

Each organisation's data is isolated with row-level security in the database (Row-Level Security with FORCE). All traffic is encrypted. Administrator events, policy changes and exports are recorded in an audit log that the organisation's administrator and data protection officer can review.

Single sign-on (SSO/OIDC) and automatic provisioning (SCIM 2.0) are supported, deactivated accounts are shut out immediately.

Your rights and contact

Data subjects exercise their rights (access, rectification, erasure and more) primarily via their organisation, which is the data controller for work content.

Questions about this policy or Skräddarsydd AB's own processing: contact Skräddarsydd AB, Norrgatan 16, 432 41 Varberg, Sweden.