Privacy policy
Team ScaleUp helps founders get ready to raise. Doing that means handling some information about you: your name, your email, sometimes what your company is working on.
This page explains what we collect, why, how long we keep it, and what you can tell us to do with it. If anything here is unclear, email us and we'll explain it.
Who is responsible for your data
Team ScaleUp AB (org. no. 556390-7384), Malmskillnadsgatan 44 A, 111 57 Stockholm, Sweden, is the controller of the personal data described on this page. We decide what is collected and why, and we are responsible for how it is handled.
Privacy questions and requests: hello@teamscaleup.se
What we collect, and why
When you fill in a contact or enquiry form
What: your name, email address, company, and whatever you write in the message field.
Why: to answer you, and to work out whether we can help.
Legal basis: we take your enquiry as a request to take steps before entering an agreement (Art. 6(1)(b) GDPR). Where you're writing on behalf of a company rather than yourself, we rely on our legitimate interest in responding to a business enquiry (Art. 6(1)(f)).
How long: 24 months after our last contact, then deleted. If we start working together, the record moves into the client relationship and follows the retention below.
When you sign up for our newsletter
What: your email address, and your name if you give it. Plus whether you opened an email or clicked a link in it, if you accept that.
Why: to send you the newsletter you signed up for.
Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time using the unsubscribe link in every email, or by emailing us. Withdrawing doesn't affect anything we sent before.
How long: until you unsubscribe. After that we keep your email address on a suppression list so you are not added again by mistake.
When you register for an event
What: name, email, company, role, and anything else the registration form asks. We run event registration through Luma.
Why: to manage the guest list, confirm your seat, send you practical information, and follow up afterwards.
Legal basis: performing our agreement with you to give you a seat (Art. 6(1)(b) GDPR).
How long: 24 months after the event, so we can invite you to future events. Then deleted, unless you are on the newsletter list.
If you tell us about allergies, intolerances or access needs
What: what you tell us, for example an allergy, a dietary requirement, or an accessibility need.
Why: to arrange catering and access at our events.
Legal basis: your explicit consent (Art. 9(2)(a) GDPR). Health information is protected more strictly under the GDPR, so we ask for it separately and only when there is an event.
How long: deleted within 30 days after the event. It is not carried over to the next event; we ask again each time.
When you apply to or join a programme
What: contact details, company information, and material you share with us about your business as part of an assessment. The assessment runs on our own platform.
Why: to run the assessment, deliver the programme, and make introductions you've asked for.
Legal basis: performing our agreement with you or taking steps before entering one (Art. 6(1)(b) GDPR). Where the information concerns your colleagues rather than you, we rely on legitimate interest (Art. 6(1)(f)).
How long: 36 months after the engagement ends, except where accounting law requires longer.
Confidentiality: before a programme or service delivery begins, we sign a separate non-disclosure agreement with you. This page covers personal data. The NDA covers your company's confidential material.
When you visit the website
What: cookies and similar technologies. Only the strictly necessary ones run unless you accept the rest.
Why: to make the site work, to understand what people read, and (if you accept it) to measure our advertising.
Legal basis: for strictly necessary cookies, our legitimate interest in a working website (Art. 6(1)(f) GDPR). For everything else, your consent (Art. 6(1)(a)).
Full detail: see our Cookie policy.
When we're required to keep records
Invoices and accounting material are kept until the end of the seventh year after the calendar year in which the financial year ended, as the Swedish Bookkeeping Act requires (bokföringslagen 7 kap. 2 §). That's a legal obligation (Art. 6(1)(c) GDPR) and it overrides a deletion request for those specific documents.
Who else sees your data
We don't sell personal data. We don't share it for anyone else's marketing.
We do use service providers who process data on our behalf, under a written data processing agreement. As of 20 August 2026 those are:
| Provider | What it does | Where data is processed |
|---|---|---|
| Webflow | Website hosting and forms | US / EU |
| Analytics | EU / US | |
| Advertising measurement | EU / US | |
| Luma | Event registration | US |
| Google Workspace / Microsoft 365 | Email and documents | EU / US |
| Mailchimp | Newsletter delivery | US |
| HubSpot | Client and lead records | EU / US |
| Our own assessment platform | Programme assessment | EU / US |
We also share data where a law or authority requires it.
Data outside the EU/EEA
Some of the providers above are based in the United States. When personal data leaves the EU/EEA we rely on either the provider's certification under the EU–US Data Privacy Framework, or on the European Commission's standard contractual clauses combined with an assessment of the safeguards in place.
You can ask us for a copy of the safeguards that apply to a specific transfer.
How long we keep things
The retention periods are listed with each purpose above. The general rule: we keep personal data for as long as we need it for the purpose we collected it for, then we delete it. Where the law sets a longer period, the law wins.
Your rights
Under the GDPR you can ask us to:
- Show you what personal data we hold about you
- Correct anything that's wrong
- Delete it, where we don't have a legal reason to keep it
- Restrict what we do with it while a dispute is being sorted out
- Hand it over to you or another provider in a machine-readable format, where the processing is based on consent or a contract
- Stop processing based on legitimate interest, including profiling
- Stop using it for direct marketing. This right is absolute and we act on it immediately
Where processing is based on your consent, you can withdraw it at any time.
Email hello@teamscaleup.se and we'll respond within one month. There's no charge.
If you think we've handled your data badly and we haven't fixed it, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten):
Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholmimy@imy.se · +46 8 657 61 00 · imy.se
Security
We limit access to personal data to the people who need it, use two-factor authentication on the systems that hold it, and choose providers who can demonstrate their own security practices. If a personal data breach puts you at risk, we will notify you and the supervisory authority as the law requires.
Children
Our services are aimed at founders and businesses. We don't knowingly collect personal data from anyone under 18.
Changes to this policy
We update this page when what we do changes. The date at the top shows when it was last updated. If a change materially affects you, we will tell you directly.
Contact
Team ScaleUp ABMalmskillnadsgatan 44 A, 111 57 Stockholm, Sweden
hello@teamscaleup.se