Privacy Policy
Bardo Technology AB
Last updated: 24 August 2026
1. Who we are
Bardo Technology AB, company registration number 559471-5954, Norra Stationsgatan 93a, 113 64 Stockholm, Sweden, is the data controller for the personal data described in this policy.
For any question about this policy or to exercise your rights, contact info@bardo.se.
2. What this policy covers
This policy covers personal data we handle as a controller: visitors to our website, people who contact us, and business contacts we reach out to.
It does not cover personal data inside customer systems that we process on a customer's behalf when delivering our carbon accounting service. When we handle financial records, ERP data, invoices or supplier documents for a customer, we act as a processor. That processing is governed by the data processing agreement with that customer. Details of how we secure it, where it is hosted and which subprocessors are involved are published at trust.bardo.se.
3. Personal data we collect
3.1 Website visitors
If you consent to analytics and marketing cookies, we collect technical and usage data: IP address, browser and device type, pages viewed, time on page, referring source, approximate location derived from IP, and advertising interaction data. If you decline, we process only what is strictly necessary to serve the site securely. See section 7.
3.2 When you contact us or request something
Forms on our site, our chat function and our meeting booking tool collect the information you provide. This is typically name, work email address, company name, job title and the content of your message or request.
3.3 When we contact you first
We identify potential customers and reach out directly. If you received a message from us without having contacted us first, this section explains where your data came from.
What we hold: your name, job title, employer, work email address, professional profile URL, and our record of contact with you.
Where we got it: professional networking platforms including LinkedIn and LinkedIn Sales Navigator, your employer's public website, public company registers, and ZoomInfo, a commercial business contact database. We do not collect personal email addresses or private contact details, and we do not process information about you as a consumer.
Why: to tell people responsible for sustainability reporting, finance or procurement at relevant companies about a service that addresses a problem in their professional remit.
Our legal basis: legitimate interest under Article 6(1)(f) GDPR. We have assessed our interest in business-to-business marketing against your interests and rights, and limited our outreach to work contact details, professional roles and companies where the service is plausibly relevant.
Your right to object: you can object at any time and we will stop. Reply to any message from us saying so, or write to info@bardo.se. We will not try to justify continuing.
| Purpose | Legal basis |
|---|---|
| Operating and securing the website | Legitimate interest |
| Analytics and understanding site usage | Consent |
| Advertising and measuring campaigns | Consent |
| Responding to enquiries, demos and meeting requests | Legitimate interest, or steps prior to a contract |
| Direct business-to-business marketing | Legitimate interest |
| Marketing emails you signed up for | Consent |
| Managing the customer relationship | Contract |
| Accounting and tax records | Legal obligation |
| Establishing or defending legal claims | Legitimate interest |
Privacy policy text
We do not sell personal data.
We use service providers who process personal data on our behalf under written data processing agreements. The categories are:
- CRM, website, email, chat and meeting booking (HubSpot, data stored in the EU)
- Analytics and workplace tools (Google)
- Advertising platforms (LinkedIn)
- Content delivery, DNS and security (Cloudflare)
- Outreach sequencing tools
- Business contact data providers (ZoomInfo, United States)
- AI providers, used to generate drafts of business communication
- Internal communication tools
Our current list of subprocessors is maintained at https://www.bardo-technology.com/subprocessors. We may also share data with professional advisers and with authorities where legally required.
6. Transfers outside the EU/EEA
We store personal data within the EU/EEA wherever possible. Some providers, including our advertising tools and our business contact data provider, are established in or transfer data to the United States. Those transfers are made under the EU-US Data Privacy Framework or the European Commission's standard contractual clauses, with supplementary measures where needed.
7. Cookies
Cookies are small text files placed on your device when you visit a website. Similar technologies such as pixels and local storage do comparable things, and we refer to all of them as cookies here.
We set strictly necessary cookies without asking, because the site cannot be served securely without them. Everything else is set only if you consent through our cookie banner.
You can change or withdraw your choice at any time using the cookie settings link. Withdrawing consent does not undo processing that already happened. You can also block or delete cookies in your browser settings, though blocking strictly necessary cookies may break parts of the site.
7.1 Strictly necessary
Set without consent.
Cookie
Cookie
__hs_cookie_cat_pref
Set by
HubSpot
Purpose
Stores which cookie categories you consented to
Duration
13 months
Cookie
Cookie
__cf_bm
Set by
Cloudflare
Purpose
Distinguishes humans from bots
Duration
30 minutes
HubSpot may also set __hs_opt_out, __hs_initial_opt_in, __hs_do_not_track or __hs_gpc depending on the choice you make and on whether your browser sends a Global Privacy Control signal. These store your preference and nothing else.
7.2 Analytics
Set only with consent.
Cookie
Cookie
_ga
Set by
Google Analytics
Purpose
Distinguishes visitors
Duration
2 years
Cookie
Cookie
_ga_J9PCXVC59Q
Set by
Google Analytics
Purpose
Maintains session state
Duration
2 years
Cookie
Cookie
__hstc
Set by
HubSpot
Purpose
Main analytics cookie, tracks visits over time
Duration
6 months
Cookie
Cookie
__hssc
Set by
HubSpot
Purpose
Tracks the current session
Duration
30 minutes
Cookie
Cookie
__hssrc
Set by
HubSpot
Purpose
Detects whether the browser was restarted
Duration
Session
Cookie
Cookie
hubspotutk
Set by
HubSpot
Purpose
Identifies a visitor and links them to form submissions
Duration
6 months
7.3 Functional
Set only with consent
Cookie
Cookie
messagesUtk
Set by
HubSpot
Purpose
Recognises you across chat conversations
Duration
6 months
7.4 Marketing
Set only with consent.
Cookie
Cookie
bcookie
Set by
Purpose
Browser identifier
Duration
1 year
Cookie
Cookie
lidc
Set by
Purpose
Routing
Duration
1 day
Cookie
Cookie
li_sugr
Set by
Purpose
Probabilistic visitor identification
Duration
90 days
Cookie
Cookie
UserMatchHistory
Set by
Purpose
Ad ID synchronisation
Duration
30 days
These are set by LinkedIn on the linkedin.com domain rather than by us, and are only set after you consent.
Cookies set by Google, LinkedIn, HubSpot and Cloudflare are governed by their own privacy terms as well as ours. See section 6 on transfers.
8. How long we keep it
We do not keep contact records indefinitely. Once a year we review our CRM and delete records that are no longer needed for the purpose they were collected for. In practice that means contacts with no meaningful activity, no ongoing relationship and no realistic prospect of one.
| Data | Retention |
|---|---|
| Enquiries, demo requests, prospect records and chat transcripts | Reviewed annually and deleted when no longer needed |
| Records of people who objected or unsubscribed | Kept indefinitely, solely so we do not contact you again |
| Customer relationship records | Duration of agreement plus 7 years, as required by the Swedish Accounting Act |
| Website analytics: event data | 2 months |
| Website analytics: user data | 14 months, reset on new activity |
Customer data inside the Bardo platform is deleted within 90 days of contract termination, as set out in the data processing agreement.
9. Your rights
You have the right to request access to your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable format. Where we rely on consent, you can withdraw it at any time without affecting processing that already took place.
One clarification on erasure: if you ask us to stop contacting you, we keep your email address on a suppression list. This is the only way we can reliably ensure we do not contact you again. We do not use it for anything else.
Contact info@bardo.se and we will respond within one month.
If you are not satisfied, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, imy.see supervisory authority where you live.
10. Security
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, multi-factor authentication and supplier due diligence.
Our security controls, certifications and current compliance status are published at trust.bardo.se
11. Data breaches
If a breach occurs that is likely to result in a risk to your rights, we notify IMY within 72 hours and inform affected individuals where required.
12. Changes
We may update this policy. The current version is always at this address with the date of last update at the top. If we make a significant change we will take reasonable steps to inform affected individuals.