Privacy Policy

Last updated: February, 2026

At Stilla Development AB, org number: 559504-8512 ("Stilla", "we", "us", "our"), we take your privacy seriously. Trust is the foundation of Stilla's platform and includes trusting us to do the right thing with your information.

Our role as data controller vs data processor

The information in this Privacy Policy covers Personal Data Processing for which Stilla is the data controller (as defined in the GDPR). As a data controller we are responsible for the Processing of Personal Data for which we decide the purpose and means ("the why and the how"). Our Privacy Policy does not describe how we Process Personal Data in the role as a data processor – i.e., when we process Personal Data on behalf of another party such as a Customer. Data Subjects whose Personal Data is collected through or otherwise Processed in connection with the use of Stilla's Services are referred to the applicable data controller (typically the Stilla Customer) for further information on such Processing of their Personal Data.

This Privacy Policy explains how we collect and treat personal data in relation to the following categories of data subjects:

  • individuals representing our Customers, suppliers, service providers or partners
  • individuals who visit our website
  • individuals who apply for a job with us

Definitions

"Applicable Data Protection Laws" refers to the legislation from time to time applicable to the Processing of your Personal Data including the General Data Protection Regulation (EU) 2016/679 ("GDPR"), the Data Use and Access Act ("DUAA"), the UK General Data Protection Regulation ("UK GDPR"), the UK Data Protection Act 2018, supplementary national legislation, as well as practices, guidelines and recommendations issued by a national or EU supervisory authority.

"Data Subject" is the living, identifiable natural person whose Personal Data is being Processed.

"Personal Data" is all information which directly or indirectly can identify a Data Subject by reference to an identifier such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that Data Subject.

"Processing" means any operation or set of operations which is performed on Personal Data, e.g., collection, storage, modification, access, transfer, deletion, use.

"Customer" is the legal entity or business organization which is the customer of Stilla as a result of having entered into a customer agreement with us or otherwise signed up to use the Services.

"The Services" refer to the Stilla AI agent, the Stilla platform and other Stilla product(s) and service(s) made available by Stilla to Customer from time to time.

"Visitor" is the individual who visits our website and in different ways interacts with us.

Data Subject Rights

If the GDPR or UK GDPR apply to our Processing or your Personal Data you have certain rights with respect to such Processing, as outlined below. For more information about these rights, or to submit a request, please email us at privacy@stilla.ai with the subject line: "GDPR Request: [nature of request]". Your request must include enough information for us to verify your identity, relationship with Stilla, and the nature of your request. In some circumstances, we may not be able to fully comply with your request, such as if we are unable to verify your identity, if it jeopardizes the rights of others, but in those circumstances, we will still respond to notify you of such a decision. Lastly, please note that where we process your Personal Data as a data processor on behalf of another organization, we will refer you to submitting your request directly to that organization.

Access: You can request more information about the Personal Data we hold about you and request a copy of such Personal Data from us, a so-called register extract. There is no charge for obtaining said register extract. For any additional copies you request, Stilla may charge a reasonable fee to cover our administrative costs in line with Applicable Data Protection Laws.

Rectification: If you believe that any Personal Data we Process about you is incorrect or incomplete, you can request that we correct or supplement such data. If you are a representative of a Customer, you can update your contact information by logging into the Service and adjusting it there.

Erasure: You can request that we erase your Personal Data from our systems ("right to be forgotten"). In the event you would like to exercise such right, please send an email with the subject line "Erasure of Personal Data Request." We will confirm receipt of your request and take reasonable steps to ensure you are the Data Subject. Upon verification, we will erase such Personal Data which we are obliged to erase under Applicable Data Protection Laws without undue delay. If we are required to retain certain Personal Data under applicable laws or a contract that we have entered with you, we will ensure that it is Processed only for the specific purpose set forth in such applicable law or contract. If you represent a Customer, please note that you can delete certain account-related information within your account settings.

Withdrawal of Consent: If we are processing your Personal Data based on your consent (as indicated at the time of collection of such data), you have the right to withdraw your consent at any time.

Portability: You can ask for a copy of certain Personal Data about you in a structured, commonly used and machine-readable format, known as data portability. You can also request that we transmit such Personal Data to another controller where technically feasible, as determined by us.

Objection: You can contact us to let us know that you object to the further use or disclosure of your Personal Data for certain purposes, such as for direct marketing purposes.

Restriction of Processing: You can ask us to restrict further processing of your Personal Data.

Right to File Complaint: If you are of the opinion that Stilla has not satisfactorily answered your question or handled your request, you have the right to lodge a complaint with the supervisory authority such as the Swedish Authority for Privacy Protection "IMY" (https://www.imy.se/en/) or any other EU national data protection authority (https://www.edpb.europa.eu/about-edpb/about-edpb/members_en). If you are in the UK or your matter is related to the UK, you can make a complaint with the Information Commissioner's Office "ICO" (https://ico.org.uk/make-a-complaint/). Please note that if you are in the United States, you currently do not have access to a centralized national data protection authority for lodging complaints related to personal data.

Stilla's Processing of your Personal Data

We will only Process your Personal Data for legitimate purposes and will only keep your Personal Data for as long as necessary for such purposes. Below we provide you with more details on our Processing of Personal Data. Do not hesitate to contact us at privacy@stilla.ai if you have any questions about this Privacy Policy, our Processing of your Personal Data or if you wish to exercise any of your rights.

For you who represent a Customer, supplier, service provider or partner

Processing activities and purposes of Processing:

  • Creating and managing your account or other user profiles (where applicable).
  • Communicating with you and providing you with information you request.
  • Carrying out business purposes stated when collecting your Personal Data.
  • Marketing and selling the Services.
  • Communicating with and administrating contact details for potential customers and others who have or may have an interest in Stilla and/or the Services.
  • Enforcing any agreements with you.
  • Responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Stilla or the Services which we think may be of interest.

Personal Data: E-mail, first and last name, title/role, Employer, billing information (where applicable) and any other information included in your communication with us.

Identifying information in emails, letters, texts, or other communication you send us, Calendar data, including but not limited to meeting invitations, body text, and sender and recipients, Meeting data, including but not limited to attendees, audio, and transcriptions, Any other identifying information you authorize Stilla to access or elect to share with Stilla, Any derivatives of such data, including but not limited to transcripts of conversations.

Photos, videos or recordings of you, Photos, videos or recordings of your environment.

IP address, IP-address-based location information, Device ID, Type of device/operating system/browser used to access the Services, Other applications that utilize the microphone function

Source: Directly from yourself or from the business which you represent.

Legal basis: Our legitimate business interests to fulfill and administrate our collaboration with you or the business you represent, handle requests and inquiries with you and market Stilla and our Services.

Retention period: During active business relationship and maximum twelve (12) months thereafter or for as long as necessary for Stilla to fulfill its obligations in accordance with mandatory law e.g., the Swedish Bookkeeping Act (1999:1078). We will of course update and remove the relevant Personal Data if we are informed that you no longer represent the relevant organization.

We may where necessary also Process the aforementioned Personal Data for the purposes and based on our legitimate business interests or legal obligations of meeting legal requirements under applicable laws, regulation, court order or other legal process (such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities), protecting the rights, property or safety of you, Stilla or another party or for resolving legal disputes.

For Visitors (including job applicants)

Processing activities and purpose:

  • Administrate and respond to any questions and/or inquiries sent to us by e-mail, contact form or via social media.
  • Creating and managing your account or other user profiles (where applicable).
  • Personalizing website content and communications based on your preferences.
  • Doing fraud protection, security and debugging.
  • Marketing and selling the Services.
  • Corresponding with you and responding to correspondence that we receive from you, contacting you when necessary or requested, and sending you information about Stilla or the Services.
  • Sending emails and other communications according to your preferences or displaying content that we think will interest you.

Personal data: Name, e-mail, and any other information included in your messages to us. Web page interactions, Referring webpage/source through which you accessed our website.

Identifying information in emails, letters, texts, or other communication you send us, Calendar data, including but not limited to meeting invitations, body text, and sender and recipients, Meeting data, including but not limited to attendees, audio, and transcriptions, Any other identifying information you authorize Stilla to access or elect to share with Stilla, Any derivatives of such data, including but not limited to transcripts of conversations.

Photos, videos or recordings of you, Photos, videos or recordings of your environment.

IP address, IP-address-based location information, Device ID, Type of device/operating system/browser used to access the Services, Other applications that utilize the microphone function

Source: Directly from you/the Data Subject, the business you represent or through the use of cookies or tracking technologies in accordance with our Cookie Statement.

Legal basis: Our legitimate interest in communicating with potential customers and assist individuals who contact us with questions and/or inquiries.

Retention period: As long as necessary to fulfill the purpose of the Processing, typically until we no longer have an open matter or active conversation with you.

Processing activities and purpose: Receiving job applications to review them and carry out our recruitment process and communicating with you in connection with such process.

Personal data: Name, e-mail, phone number, and any information the individual chooses to include in the CV/personal letter.

Source: Directly from you/the Data Subject.

Legal basis: Our legitimate interest to carry out necessary activities relating to a recruitment process.

Retention period: As long as necessary for the purpose it was collected (typically until we have terminated the relevant recruitment process). We may save applications for future job openings in which case we will ask for your consent before we save the application.

Processing activities and purpose: Administration and distribution of information related to the Services, newsletters, and Stilla's current and future offerings.

Personal data: Name, e-mail, phone number, and any information you choose to share with us.

Identifying information in emails, letters, texts, or other communication you send us, Calendar data, including but not limited to meeting invitations, body text, and sender and recipients, Meeting data, including but not limited to attendees, audio, and transcriptions, Any other identifying information you authorize Stilla to access or elect to share with Stilla, Any derivatives of such data, including but not limited to transcripts of conversations.

Photos, videos or recordings of you, Photos, videos or recordings of your environment.

IP address, IP-address-based location information, Device ID, Type of device/operating system/browser used to access the Services, Other applications that utilize the microphone function

Source: Directly from you/the Data Subject.

Legal basis: Our legitimate interest to provide the Data Subject with the requested information regarding our services to those who are interested.

Retention period: As long as you have an active subscription to receive newsletters and other information from Stilla. We only send marketing emails after receiving your consent (such as when you register yourself to receive them) and you always have the right to withdraw said consent at any time.

We may where necessary also Process the aforementioned Personal Data for the purposes and based on our legitimate business interests or legal obligations of meeting legal requirements under applicable laws, regulation, court order or other legal process (such as preventing, detecting and investigating security incidents and potentially illegal or prohibited activities), protecting the rights, property or safety of you, Stilla or another party or for resolving legal disputes.

Google API Data

Notwithstanding the foregoing, to the extent we collect Personal Data about you through use of a Google API, our use and transfer of such Personal Data to any other third-party will be in compliance with the Google API Services User Data Statement, including the Limited Use Requirements.

Google Workspace Data – Additional Restrictions

Stilla does not (i) use Google Workspace user data to develop, improve or train non‑personalized or generalized AI/ML models or (ii) combine such data with data from other customers for model training.

Consent: In some cases, we process Personal Data based on the consent you expressly grant to us at the time we collect such data. When we process Personal Data based on your consent, it will be expressly indicated to you at the point and time of collection.

How We Disclose Your Personal Data

We carefully analyze what types of information we need to provide our services, and we try to limit the information we collect to only what we really need. Where possible, we delete or anonymize this information when we no longer need it. When building and improving our products, our engineers work closely with our privacy and security teams to build with privacy in mind (the principle of privacy by design).

We may share your Personal Data with – or Process it with the help of – suppliers hired by us. Such parties can either be processors to Stilla, i.e. companies that process your Personal Data on behalf of Stilla according to our instructions (e.g. providers of IT- and communication services), or independent data controllers who are responsible for their processing of your personal data (e.g. law firms or auditing firms that Stilla hires and which, in connection with the performance of their assignment, have access to your Personal Data and Processes it in accordance with their procedures and requirements applicable to their business). Stilla is responsible for any such sharing of your personal data to such third parties for processing to take place in accordance with Applicable Data Protection Laws.

Business Transfers

Personal Data that we collect may be transferred to a third party if we undergo a merger, acquisition, bankruptcy or other transaction in which that third party assumes control of our business (in whole or in part). Should one of these events occur, we will make reasonable efforts to notify you before your information becomes subject to different privacy and security policies and practices.

De-identification of Personal Data

We may create aggregated, de-identified or anonymized data from the Personal Data we collect, including by removing information that makes the data personally identifiable to a particular user. We may use such aggregated, de-identified or anonymized data and share it with third parties for our lawful business purposes, including to analyze, build and improve the Services and promote our business, provided that we will not share such data in a manner that could identify you.

Cookies and Tracking Technologies

Stilla uses cookies and other tracking technologies such as pixel tags, web beacons, clear GIFs and JavaScript to analyze the use of our website, Services and related functions so that we can give you the best user experience. For more information in this regard, please see our Cookie Statement here.

You can set privacy preferences through Do Not Track ("DNT") mechanisms in certain web browsers. There is no consensus among industry participants as to what "Do Not Track" means in this context. Like many websites and online services, Stilla currently does not alter its practices when it receives a "Do Not Track" signal from your browser.

Data Security

We always want you to feel confident about providing us with your personal data. We have taken appropriate security measures to protect your personal data against unauthorized access, alteration, and erasure. Even though we work hard to protect your data, no security measures are perfect or impenetrable. Should a security breach occur that may lead to the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, Personal Data transmitted, stored or otherwise processed and is likely to result in a high risk to the rights and freedoms of you, e.g., risk of fraud or identity theft, we will contact you and inform you of such risk and recommend what action you can take to mitigate potential adverse effects of the personal data breach.

We strongly recommend that you help protect your data by being cautious and appropriately selecting and protecting your password and/or other sign-on mechanism; limiting access to your computer or device and browser; and signing off after you have finished accessing your account.

Data Retention

We retain your Personal Data only for as long as necessary for the purposes for which we originally collected the data in accordance with this Privacy Policy. When we no longer need to save your data, we will remove it from our systems, databases, and backups. The retention time depends on the context and cannot in all cases be specified; in that case, we will provide information about the factors deciding the retention time. Personal data processed to fulfill legal obligations in the Accounting Act will be stored for seven years. Data processed under the Anti-Money Laundering Act will be stored for five to ten years depending on the circumstances.

Where deletion of Personal Data is not possible due to fulfillment of legal obligations, Stilla will take measures to block the personal data from any further Processing (except to the extent necessary for its continued hosting or Processing required by applicable law) and shall continue to appropriately protect the Personal Data remaining in its possession, custody, or control and, where any authorized sub-processor continues to possess Personal Data, require the authorized sub-processor to take the same measures that would be required of Stilla.

Personal Data of Children

As noted in the Terms of Use, we do not knowingly collect or solicit Personal Data from children under 16 years of age; if you are a child under the age of 16, please do not attempt to register for or otherwise use the Services or send us any Personal Data. If you believe that a child under 16 years of age may have provided Personal Data to us, please contact us at privacy@stilla.ai.

International Transfers of Personal Data

Stilla will process your personal data within the EU/EEA. However, we occasionally need to transfer personal data to third countries, either directly or through our sub-processors. If we engage in such transfer, we will ensure that there is a legal basis for the transfer and that the level of protection is equivalent to that applicable within the EU/EEA such as by ensuring that the country has an adequate level of protection determined by the EU Commission, that the processor/ recipient in question is certified under the EU-U.S. Data Privacy Framework or that we have taken adequate protective measures such as based the transfer on the European Commission's standard contractual clauses (SCCs).

Changes to the Privacy Policy

We will make changes to this Privacy Policy when necessary. When we make changes that are not purely editorial, such as formatting, typographical error corrections, or other changes that do not materially affect you, we will inform you of these changes by posting it on our website or in some other way that makes you aware of the changes such as by sending you an email.