Privacy Policy
Last updated 29 July 2026
This policy explains how Rungard AB handles personal data when you visit our website, create an account, place an order, use the Rungard cloud service, connect a Rungard device, or contact us. It also explains what normally remains only on your device.
1. Who is responsible?
Rungard AB is the data controller for the processing described in this policy.
Organisation number: 559392-4615VAT number: SE559392461501
Kaserngården 3A
451 34 Uddevalla, Sweden
info@rungard.eu
Data stored solely inside applications on your Rungard device is normally controlled by you, not by Rungard AB. If we process personal data on behalf of a business customer through a separately agreed support or hosted feature, the parties may also need a data processing agreement.
2. Personal data we process
- Account and contact data: name, email address, phone number, password hash, account roles, preferred language, and authentication records.
- Customer and billing data: postal and delivery address, customer type, company name, organisation and VAT numbers, invoice email and reference, currency, orders, subscriptions, invoices, discounts, and payment status. We do not collect card details.
- Device identity and ownership data: device serial and registry identifiers, public-key material and fingerprints, claim and ownership records, device name, hostname, subdomain, customer port, and activation history.
- Device management data: online status, internal IP addresses, CPU, memory, disk and temperature metrics, service status and errors, update and security status, failed-login counts, installed application and container metadata, resource use, ports, backup configuration and history metadata, and management-command results.
- VPN and application data: WireGuard interface and peer configuration, including peer names, addresses and cryptographic keys, and protected administrator credentials created for managed applications.
- Support and communications: messages you send us, attachments, troubleshooting details, and records of how we handled your request.
- Website and security data: IP address, request time, requested page, browser and device information, security events, and the cookies and browser storage described in our Cookie Policy.
- Updates and interest requests: your email address if you ask to receive launch or product updates.
Most data comes from you or your Rungard device. We may also receive delivery and payment-status data from providers involved in fulfilling your order. Please do not send special-category personal data, passwords, private files, or unrelated personal information in a support request unless it is necessary.
3. Why we use the data
| Purpose | Legal basis |
|---|---|
| Create and secure accounts, provide cloud management, register devices, and perform requested commands. | Performance of our contract or steps requested before entering it (GDPR Article 6(1)(b)). |
| Process, deliver and support orders and subscriptions. | Performance of our contract (Article 6(1)(b)). |
| Create invoices, keep accounting records, handle tax, withdrawals, complaints and statutory product obligations. | Legal obligations (Article 6(1)(c)). |
| Protect accounts, devices and infrastructure, prevent abuse, investigate incidents, and establish or defend legal claims. | Our legitimate interests in operating a secure and reliable service and protecting legal rights (Article 6(1)(f)). |
| Answer support requests and improve a fault affecting your service. | Contract where the request concerns the service; otherwise our legitimate interest in customer support (Articles 6(1)(b) and 6(1)(f)). |
| Send optional launch or product updates. | Your consent (Article 6(1)(a)). You may withdraw it at any time. |
Providing account, delivery and billing data is necessary to create an account or fulfil an order. Without it, we may be unable to provide the relevant service. Device-management data is required for cloud dashboard features; it is not described as anonymous or optional telemetry.
4. What stays on your device
Application files and ordinary application content are designed to remain on your Rungard device. Your local owner password and backup-encryption password are not sent to Rungard Cloud. The cloud service does, however, receive the device-management data listed above. If you request container or service logs through the cloud dashboard, the requested output is transmitted temporarily so it can be displayed to you. Applications you install may contact their own publishers or other third parties under those parties' terms and privacy notices.
5. Who receives personal data
We disclose only what is necessary to:
- authorised Rungard personnel who need access for operations, support, billing, security, or legal compliance;
- email-delivery, shipping, accounting, professional-adviser, and other suppliers that help us provide the service;
- public authorities, courts, insurers, or advisers where disclosure is required by law or necessary to protect legal rights; and
- a buyer or successor if Rungard undergoes a merger, financing, restructuring, or sale, subject to appropriate confidentiality and data-protection safeguards.
We do not sell personal data and do not share it for third-party behavioural advertising. Our core cloud application, databases and operational storage are hosted on Rungard-controlled servers in Sweden. Transactional email may be delivered through a contracted email provider. Suppliers that process personal data for us are bound by data-processing and confidentiality obligations where required.
6. International transfers
We aim to process core customer and device data in Sweden or elsewhere in the EU/EEA. If a supplier makes personal data available outside the EU/EEA, we will use a lawful transfer mechanism, such as an adequacy decision or the European Commission's standard contractual clauses, and apply additional safeguards where required. You may contact us for information about the safeguard relevant to you.
7. How long we keep data
- Account, customer, subscription and device records: while the relationship is active, then only as long as needed for closure, security, complaints, legal claims, or another legal obligation.
- Invoices, orders and accounting material: for the period required by Swedish bookkeeping and tax law, normally seven years after the end of the calendar year in which the financial year ended.
- Latest device snapshots: up to 14 days; short metric history is retained for up to two hours and device-presence records for up to 30 days. New snapshots normally replace earlier latest-state data.
- Temporary command responses: normally two to five minutes, unless the result becomes part of a longer-lived device, support, security, or audit record.
- Device claim and ownership records: while needed to prove device ownership, prevent reassignment or fraud, support recovery, and resolve claims.
- Optional update requests: until you withdraw consent or the list is discontinued.
Security and access logs are retained only as long as reasonably necessary for incident detection, investigation, service integrity, and legal claims. The period depends on the event, risk, and whether an incident or legal obligation requires longer preservation. We delete or anonymise data when its applicable retention purpose ends.
8. Your rights
Depending on the circumstances, GDPR gives you the right to:
- receive information and a copy of your personal data;
- correct inaccurate or incomplete data;
- request erasure or restriction;
- object to processing based on legitimate interests and always object to direct marketing;
- receive data you provided in a portable format where the portability rules apply; and
- withdraw consent without affecting processing that was lawful before withdrawal.
These rights are not absolute. For example, we may need to retain invoice data by law. Send a request to info@rungard.eu. We may need to verify your identity. We normally respond within one month; GDPR permits an extension of up to two further months for a complex request, in which case we will tell you why.
You may lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority in the EU/EEA country where you live or work.
9. Security and automated decisions
We use technical and organisational safeguards appropriate to the data and risk, including access controls, protected authentication credentials, transport security, restricted administrative access, and security monitoring. No internet-connected service can be guaranteed completely secure. Please use a unique password and protect your local device and recovery information.
We do not make decisions based solely on automated processing that produce legal or similarly significant effects for customers.
10. Children and changes
Rungard accounts and purchases are intended for people aged 18 or older and authorised business users. We do not knowingly offer the service directly to children.
We may update this policy when the service, suppliers, or law changes. We will publish the revised date and give appropriate notice before a material change takes effect. A privacy notice describes processing; continued use is not treated as consent where GDPR requires consent.
11. Contact
Questions or privacy requests can be sent to info@rungard.eu or by post to Rungard AB at the address above.
IP geolocation
Before you sign in, we may send your IP address to IPinfo to suggest an available sales country and show the relevant currency and VAT-inclusive consumer price. We store the selected country in your browser, and you can change it in Settings. Checkout uses the address and customer information you provide instead of the suggestion. We rely on our legitimate interest in presenting relevant regional pricing. IPinfo may process the IP address outside the EU/EEA under its IPinfo privacy notice. IP address data is provided by IPinfo.