Vashly AB

Privacy Notice

How we process your personal data when you use our websites and services, including TeamVibe and related features.

Last updated: January 1, 2026

1. Who we are

Vashly AB
Birger Jarlsgatan 57 C 113 56 Stockholm
If you contact us about privacy, please write "privacy request" in the subject line.

2. Scope

This notice applies to:

  • Visitors to our websites and landing pages
  • Users of our SaaS (admins/editors creating and managing content)
  • Visitors/candidates viewing an embedded team profile
  • Newsletter subscribers
  • Business contacts (prospects, customers, partners, suppliers)
  • Individuals whose professional data may appear in talent discovery features (see section 6)

Third-party services (e.g., payment providers, newsletter platforms, customer ATS pages) process data under their own notices in addition to this one.

3. Roles: Controller vs Processor

As Controller

We process personal data for our own purposes: websites, security, billing, support, product analytics, sales/marketing, and talent discovery.

As Processor

We process data on customer instructions within their workspace (e.g., team profile content). The customer is the controller.

Where needed, we provide a data processing agreement (DPA) to customers.

4. Personal data we collect

We collect personal data (i) you provide, (ii) collected automatically, and (iii) from lawful third parties/public sources.

AData you provide

  • Account data: name, work email, role, company, authentication data
  • Customer content: text, images, logos, videos, and inputs in Team profile
  • Communications: support requests, feedback, meeting notes
  • Billing: company details, VAT, invoicing and payment status

BData collected automatically

  • Usage/device data: pages viewed, actions taken, timestamps, IP address, browser/OS/language, referral URL
  • Cookies/local storage/SDKs: see section 10

CData from third-party or public sources

  • Business contact data: name, work email, role, company from public/licensed B2B providers
  • Talent discovery data: see section 6
Sensitive data: We do not intend to collect special category data (e.g., health, political opinions). Don't include it in content or uploads.

5. Purposes and legal bases

We process personal data only when we have a legal basis under GDPR.

AProvide and secure the Services

Account creation, authentication, hosting, support, abuse prevention, security monitoring.

Legal basis: Contract (Art. 6(1)(b)); Legitimate interests (Art. 6(1)(f))

BProduct improvement and analytics

Diagnostics, performance, feature adoption, de-identified/aggregated statistics.

Legal basis: Legitimate interests; Consent for non-essential cookies/SDKs (Art. 6(1)(a))

CB2B sales and marketing

Outbound to relevant business contacts, product updates, events/webinars, CRM, newsletter delivery.

Legal basis: Legitimate interests; Consent for newsletters where required

DPayments and bookkeeping

Invoicing, accounting, tax compliance.

Legal basis: Contract; Legal obligation (Swedish bookkeeping requirements)

ELegal compliance and claims

Comply with law, enforce terms, prevent fraud, establish/exercise/defend legal claims.

Legal basis: Legal obligation; Legitimate interests

6. Talent discovery (professional data)

This section applies if your professional profile data is processed in connection with features intended to help customers identify people who may be relevant to their teams.

How we collect this data

We may collect professional data from publicly available sources on the open web (e.g., employer websites, professional profiles) and from licensed data providers. Our talent discovery features rely on large-scale aggregation of publicly available professional information and licensed B2B data sources.In total, these sources represent hundreds of millions of professional profiles globally. We do not claim ownership of this data and do not maintain a single unified database of all profiles. Data is indexed, refreshed, and cached for limited periods to support search accuracy, deduplication, and relevance.Due to contractual and security obligations, we do not publicly disclose all individual data providers, but we require lawful sourcing, GDPR compliance, and documented rights to process professional data.

What data we process

Name, employer/company, role/title, location, profile links, education and similar professional info. Where available via lawful sources/providers, we may also process business contact details such as work email/phone.

Why we process it

To enable customers to discover and review potential professional matches and to maintain service quality (accuracy, deduplication, fraud/abuse prevention, and fixing errors).

Legal basis

Legitimate interests (Art. 6(1)(f)): enabling professional discovery for customers and operating/improving the service. You have the right to object (Art. 21). We stop processing for this purpose unless we have compelling legitimate grounds.

Sharing

If a customer runs a search or views results, relevant professional data may be displayed to that customer for the customer's evaluation. The customer becomes a controller for any further use in their recruitment/outreach process.

Your opt-out

You can request suppression/deletion of your professional data from our talent discovery processing by emailing hello@vashly.com. We will maintain a minimal suppression record to ensure we respect your request going forward.

7. AI features and automated decision-making

Our AI features help customers structure and write content and may assist with organizing discovery signals. We do not make decisions with legal or similarly significant effects based solely on automated processing. Hiring decisions remain with employers.

We do not use customer private workspace content to train publicly available foundation models. We may use aggregated and/or anonymised usage metrics to improve the Services.

8. Sharing and processors

We share personal data only with:

  • Processors (hosting, analytics, email delivery, payments, CRM, customer support) under contract and instructions
  • Customers where necessary to provide the service
  • Authorities/advisors when required by law or to protect rights/safety
  • Transaction parties in restructuring/merger/acquisition contexts (subject to appropriate safeguards)

We do not sell personal data.

9. International transfers

Some vendors may process data outside the EU/EEA. Where transfers occur, we use appropriate safeguards such as SCCs and/or adequacy mechanisms (including the EU-US Data Privacy Framework for participating US organisations, where applicable).

10. Cookies and similar technologies

We use cookies/local storage/SDKs to:

  • Keep sessions secure (strictly necessary)
  • Measure performance and improve the service (analytics)
  • Run marketing/retargeting only where you consent

Where required, we provide a cookie banner to manage consent. You can change preferences via the banner and/or browser settings.

11. Data retention

We retain personal data only as long as necessary for the purposes above, then delete or anonymise.

Data typeRetention period
Account + workspace contentSubscription term + up to 24 months
Support ticketsUp to 24 months after closure
Product analyticsUp to 26 months (aggregated may be longer)
B2B prospect/customer dataUp to 24 months from last interaction
Talent discovery dataUp to 3 months (cached/indexed)
Accounting records7 years (legal requirement)

Backups may persist for limited periods; we restrict access and delete according to backup lifecycle.

12. Your rights (EEA/UK)

Subject to law, you can request: access, rectification, erasure, restriction, portability, objection (incl. profiling), and withdrawal of consent.

We respond within one month, extendable by two months for complex requests, and we may verify identity.

To exercise rights: email carwan@vashly.com

Supervisory authority:

Integritetsskyddsmyndigheten (IMY)

Email: imy@imy.se

Phone: 08-657 61 00

Postal: Box 8114, 104 20 Stockholm

13. Children

Services are not directed to children under 16 and we do not knowingly collect children's personal data.

14. Security

We use appropriate technical and organisational measures (access controls, least privilege, encryption in transit, logging, backups). If a breach is likely to result in risk to individuals, we notify affected individuals and authorities as required.

15. Changes

We may update this notice. We will publish the updated version with a new "Last updated" date and, where appropriate, notify users via email/in-app.