Skip to main content
    Licencēts: FLIQ, Google Pay, Apple Pay un kartes

    Mašīntulkojums no angļu valodas uz Latviešu

    The binding version of this page is available in Swedish and English.

    Privacy notice

    CoAccept AB (Registration number 559548-7405), Stockholm, is the data controller for personal data processed in the Remembill service.

    Data controller

    CoAccept AB, Reg. no. 559548-7405, registered in Stockholm, Sweden. Contact: gustav@remembill.com.

    What is processed

    Contact details you provide in the pilot form (name, email, company, phone number, message).

    Bill reference data needed to present and pay a bill (invoice reference, amount, currency, due date, recipient, payment status).

    Technical logs (IP address, timestamp, user agent, event log) generated automatically when the service is used.

    Purposes and legal bases

    Delivering the service and executing bill payments: necessary to perform the agreement with you, Article 6(1)(b) GDPR.

    Handling pilot requests and customer correspondence: legitimate interest to reply to incoming requests, Article 6(1)(f) GDPR.

    Security, abuse prevention and running the service: legitimate interest to protect the service and its users, Article 6(1)(f) GDPR.

    Complying with legal obligations such as bookkeeping and payment-related requirements, Article 6(1)(c) GDPR.

    One-time code to open a bill

    To open a bill without an account you enter your email address or phone number, and we send you a six digit one-time code.

    The data is processed to show the right bills to the right person without requiring an account. The legal basis is contract, Article 6(1)(b) GDPR, because the processing is necessary to deliver the service you request.

    The one-time code is valid for ten minutes. Neither the code nor your email address or phone number is stored in clear text, only as cryptographic hash values. The record is deleted when the code has been redeemed or has expired, whichever comes first.

    The code and your contact detail are stored within the EU/EEA. If the code is sent by email, delivery is handled by Resend in the United States under a data processing agreement and standard contractual clauses.

    Card payment scope: PCI DSS SAQ A. All card data is processed by payment providers. Never in Remembill's systems.

    The self test on the Demo page

    In the self test you provide your name and email address. The data is used to create and send a demo bill to you. Sending the demo bill is what you request, so the legal basis is contract, Article 6(1)(b) GDPR.

    To prevent abuse, hash values of the email address and IP address are stored in the website database for at most 48 hours.

    Recipients and processors

    Payment partners responsible for executing bank and card payments.

    Supabase, which operates the database and server functions within the EU/EEA.

    Resend for email delivery of one-time codes and transactional messages. Resend processes the email address in the United States under a data processing agreement and standard contractual clauses under Chapter V of the GDPR. One-time codes sent by SMS use an SMS provider.

    Where needed: contracted debt collection partner for unpaid bills.

    Where data is processed

    The database and server functions are operated within the EU/EEA. Email is delivered via Resend in the United States. Transfers of personal data outside the EU and EEA are made under a data processing agreement and standard contractual clauses or equivalent safeguards under Chapter V of the GDPR.

    Retention

    Contact details from the pilot form are kept for as long as needed to answer the request, and at most 24 months after the last contact.

    Data tied to a completed payment is kept for as long as bookkeeping and tax law require, as a rule seven years.

    Technical logs are rotated continuously and kept for at most 12 months.

    Your rights

    You have the right to request access, rectification and erasure of your personal data, to object to or request restriction of processing, and to data portability where applicable. Contact gustav@remembill.com.

    Right to complain to IMY

    You can lodge a complaint with the Swedish Authority for Privacy Protection (IMY), the supervisory authority for personal data processing in Sweden. See imy.se for contact details.

    Contact

    Questions about this notice or the processing of your personal data are answered at gustav@remembill.com.

    Last updated: 2026-08-22