Privacy Policy

Bardo Technology AB

Last updated: 24 August 2026

1. Who we are

Bardo Technology AB, company registration number 559471-5954, Norra Stationsgatan 93a, 113 64 Stockholm, Sweden, is the data controller for the personal data described in this policy.

For any question about this policy or to exercise your rights, contact info@bardo.se.

2. What this policy covers

This policy covers personal data we handle as a controller: visitors to our website, people who contact us, and business contacts we reach out to.

It does not cover personal data inside customer systems that we process on a customer's behalf when delivering our carbon accounting service. When we handle financial records, ERP data, invoices or supplier documents for a customer, we act as a processor. That processing is governed by the data processing agreement with that customer. Details of how we secure it, where it is hosted and which subprocessors are involved are published at trust.bardo.se.

3. Personal data we collect

3.1 Website visitors

If you consent to analytics and marketing cookies, we collect technical and usage data: IP address, browser and device type, pages viewed, time on page, referring source, approximate location derived from IP, and advertising interaction data. If you decline, we process only what is strictly necessary to serve the site securely. See section 7.

3.2 When you contact us or request something

Forms on our site, our chat function and our meeting booking tool collect the information you provide. This is typically name, work email address, company name, job title and the content of your message or request.

3.3 When we contact you first

We identify potential customers and reach out directly. If you received a message from us without having contacted us first, this section explains where your data came from.

What we hold: your name, job title, employer, work email address, professional profile URL, and our record of contact with you.

Where we got it: professional networking platforms including LinkedIn and LinkedIn Sales Navigator, your employer's public website, public company registers, and ZoomInfo, a commercial business contact database. We do not collect personal email addresses or private contact details, and we do not process information about you as a consumer.

Why: to tell people responsible for sustainability reporting, finance or procurement at relevant companies about a service that addresses a problem in their professional remit.

Our legal basis: legitimate interest under Article 6(1)(f) GDPR. We have assessed our interest in business-to-business marketing against your interests and rights, and limited our outreach to work contact details, professional roles and companies where the service is plausibly relevant.

Your right to object: you can object at any time and we will stop. Reply to any message from us saying so, or write to info@bardo.se. We will not try to justify continuing.

Purpose Legal basis
Operating and securing the website Legitimate interest
Analytics and understanding site usage Consent
Advertising and measuring campaigns Consent
Responding to enquiries, demos and meeting requests Legitimate interest, or steps prior to a contract
Direct business-to-business marketing Legitimate interest
Marketing emails you signed up for Consent
Managing the customer relationship Contract
Accounting and tax records Legal obligation
Establishing or defending legal claims Legitimate interest

Privacy policy text

We do not sell personal data.

We use service providers who process personal data on our behalf under written data processing agreements. The categories are:

  • CRM, website, email, chat and meeting booking (HubSpot, data stored in the EU)
  • Analytics and workplace tools (Google)
  • Advertising platforms (LinkedIn)
  • Content delivery, DNS and security (Cloudflare)
  • Outreach sequencing tools
  • Business contact data providers (ZoomInfo, United States)
  • AI providers, used to generate drafts of business communication
  • Internal communication tools

Our current list of subprocessors is maintained at https://www.bardo-technology.com/subprocessors. We may also share data with professional advisers and with authorities where legally required.

6. Transfers outside the EU/EEA

We store personal data within the EU/EEA wherever possible. Some providers, including our advertising tools and our business contact data provider, are established in or transfer data to the United States. Those transfers are made under the EU-US Data Privacy Framework or the European Commission's standard contractual clauses, with supplementary measures where needed.

7. Cookies

Cookies are small text files placed on your device when you visit a website. Similar technologies such as pixels and local storage do comparable things, and we refer to all of them as cookies here.

We set strictly necessary cookies without asking, because the site cannot be served securely without them. Everything else is set only if you consent through our cookie banner.

You can change or withdraw your choice at any time using the cookie settings link. Withdrawing consent does not undo processing that already happened. You can also block or delete cookies in your browser settings, though blocking strictly necessary cookies may break parts of the site.

7.1 Strictly necessary

Set without consent.

Cookie

Cookie

__hs_cookie_cat_pref

Set by

HubSpot

Purpose

Stores which cookie categories you consented to

Duration

13 months

Cookie

Cookie

__cf_bm

Set by

Cloudflare

Purpose

Distinguishes humans from bots

Duration

30 minutes

HubSpot may also set __hs_opt_out, __hs_initial_opt_in, __hs_do_not_track or __hs_gpc depending on the choice you make and on whether your browser sends a Global Privacy Control signal. These store your preference and nothing else.

7.2 Analytics

Set only with consent.

Cookie

Cookie

_ga

Set by

Google Analytics

Purpose

Distinguishes visitors

Duration

2 years

Cookie

Cookie

_ga_J9PCXVC59Q

Set by

Google Analytics

Purpose

Maintains session state

Duration

2 years

Cookie

Cookie

__hstc

Set by

HubSpot

Purpose

Main analytics cookie, tracks visits over time

Duration

6 months

Cookie

Cookie

__hssc

Set by

HubSpot

Purpose

Tracks the current session

Duration

30 minutes

Cookie

Cookie

__hssrc

Set by

HubSpot

Purpose

Detects whether the browser was restarted

Duration

Session

Cookie

Cookie

hubspotutk

Set by

HubSpot

Purpose

Identifies a visitor and links them to form submissions

Duration

6 months

7.3 Functional

Set only with consent

Cookie

Cookie

messagesUtk

Set by

HubSpot

Purpose

Recognises you across chat conversations

Duration

6 months

7.4 Marketing

Set only with consent.

Cookie

Cookie

bcookie

Set by

LinkedIn

Purpose

Browser identifier

Duration

1 year

Cookie

Cookie

lidc

Set by

LinkedIn

Purpose

Routing

Duration

1 day

Cookie

Cookie

li_sugr

Set by

LinkedIn

Purpose

Probabilistic visitor identification

Duration

90 days

Cookie

Cookie

UserMatchHistory

Set by

LinkedIn

Purpose

Ad ID synchronisation

Duration

30 days

These are set by LinkedIn on the linkedin.com domain rather than by us, and are only set after you consent.

Cookies set by Google, LinkedIn, HubSpot and Cloudflare are governed by their own privacy terms as well as ours. See section 6 on transfers.

8. How long we keep it

We do not keep contact records indefinitely. Once a year we review our CRM and delete records that are no longer needed for the purpose they were collected for. In practice that means contacts with no meaningful activity, no ongoing relationship and no realistic prospect of one.

Data Retention
Enquiries, demo requests, prospect records and chat transcripts Reviewed annually and deleted when no longer needed
Records of people who objected or unsubscribed Kept indefinitely, solely so we do not contact you again
Customer relationship records Duration of agreement plus 7 years, as required by the Swedish Accounting Act
Website analytics: event data 2 months
Website analytics: user data 14 months, reset on new activity

Customer data inside the Bardo platform is deleted within 90 days of contract termination, as set out in the data processing agreement.

9. Your rights

You have the right to request access to your personal data, to have inaccurate data corrected, to have data erased, to restrict or object to processing, and to receive your data in a portable format. Where we rely on consent, you can withdraw it at any time without affecting processing that already took place.

One clarification on erasure: if you ask us to stop contacting you, we keep your email address on a suppression list. This is the only way we can reliably ensure we do not contact you again. We do not use it for anything else.

Contact info@bardo.se and we will respond within one month.

If you are not satisfied, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY, imy.see supervisory authority where you live.

10. Security

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, role-based access control, multi-factor authentication and supplier due diligence.

Our security controls, certifications and current compliance status are published at trust.bardo.se

11. Data breaches

If a breach occurs that is likely to result in a risk to your rights, we notify IMY within 72 hours and inform affected individuals where required.

12. Changes

We may update this policy. The current version is always at this address with the date of last update at the top. If we make a significant change we will take reasonable steps to inform affected individuals.

Try for yourself

See what we'd find in your data.

We'll analyze a sample of your invoices and show you what real carbon data looks like for your organization.
See it in action
MessagesSquare Talk to our team
Ellipse 2 (1)