Legal

Privacy policy

Last updated 20 August 2026

Team Scaleup helps founders get ready to raise. Doing that means handling some information about you: your name, your email, sometimes what your company is working on.

This page explains what we collect, why, how long we keep it, and what you can tell us to do with it. If anything here is unclear, email us and we'll explain it.

Who is responsible for your data

Team Scaleup AB (org. no. 556390-7384), Malmskillnadsgatan 44 A, 111 57 Stockholm, Sweden, is the controller of the personal data described on this page. We decide what is collected and why, and we are responsible for how it is handled.

Privacy questions and requests: hello@teamscaleup.se

What we collect, and why

When you fill in a contact or enquiry form

What
Your name, email address, company, and whatever you write in the message field.
Why
To answer you, and to work out whether we can help.
Basis
We take your enquiry as a request to take steps before entering an agreement (Art. 6(1)(b) GDPR). Where you're writing on behalf of a company rather than yourself, we rely on our legitimate interest in responding to a business enquiry (Art. 6(1)(f)).
How long
24 months after our last contact, then deleted. If we start working together, the record moves into the client relationship and follows the retention below.

When you sign up for our newsletter

What
Your email address, and your name if you give it. Plus whether you opened an email or clicked a link in it, if you accept that.
Why
To send you the newsletter you signed up for.
Basis
Your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time using the unsubscribe link in every email, or by emailing us. Withdrawing doesn't affect anything we sent before.
How long
Until you unsubscribe. After that we keep your email address on a suppression list so you are not added again by mistake.

When you register for an event

What
Name, email, company, role, and anything else the registration form asks. We run event registration through Luma.
Why
To manage the guest list, confirm your seat, send you practical information, and follow up afterwards.
Basis
Performing our agreement with you to give you a seat (Art. 6(1)(b) GDPR).
How long
24 months after the event, so we can invite you to future events. Then deleted, unless you are on the newsletter list.

If you tell us about allergies, intolerances or access needs

What
What you tell us, for example an allergy, a dietary requirement, or an accessibility need.
Why
To arrange catering and access at our events.
Basis
Your explicit consent (Art. 9(2)(a) GDPR). Health information is protected more strictly under the GDPR, so we ask for it separately and only when there is an event.
How long
Deleted within 30 days after the event. It is not carried over to the next event; we ask again each time.

When you apply to or join a programme

What
Contact details, company information, and material you share with us about your business as part of an assessment. The assessment runs on our own platform.
Why
To run the assessment, deliver the programme, and make introductions you've asked for.
Basis
Performing our agreement with you or taking steps before entering one (Art. 6(1)(b) GDPR). Where the information concerns your colleagues rather than you, we rely on legitimate interest (Art. 6(1)(f)).
How long
36 months after the engagement ends, except where accounting law requires longer.
NDA
Before a programme or service delivery begins, we sign a separate non-disclosure agreement with you. This page covers personal data. The NDA covers your company's confidential material.

When you visit the website

What
Cookies and similar technologies. Only the strictly necessary ones run unless you accept the rest.
Why
To make the site work, to understand what people read, and (if you accept it) to measure our advertising.
Basis
For strictly necessary cookies, our legitimate interest in a working website (Art. 6(1)(f) GDPR). For everything else, your consent (Art. 6(1)(a)).
Detail
See our cookie policy.

When we're required to keep records

Invoices and accounting material are kept until the end of the seventh year after the calendar year in which the financial year ended, as the Swedish Bookkeeping Act requires (bokföringslagen 7 kap. 2 §). That's a legal obligation (Art. 6(1)(c) GDPR) and it overrides a deletion request for those specific documents.

Who else sees your data

We don't sell personal data. We don't share it for anyone else's marketing.

We do use service providers who process data on our behalf, under a written data processing agreement. As of 20 August 2026 those are:

Provider What it does Processed in
Webflow Website hosting and forms US / EU
Google Analytics EU / US
LinkedIn Advertising measurement EU / US
Luma Event registration US
Google Workspace / Microsoft 365 Email and documents EU / US
Mailchimp Newsletter delivery US
HubSpot Client and lead records EU / US
Our own assessment platform Programme assessment EU / US

We also share data where a law or authority requires it.

Data outside the EU/EEA

Some of the providers above are based in the United States. When personal data leaves the EU/EEA we rely on either the provider's certification under the EU–US Data Privacy Framework, or on the European Commission's standard contractual clauses combined with an assessment of the safeguards in place.

You can ask us for a copy of the safeguards that apply to a specific transfer.

How long we keep things

The retention periods are listed with each purpose above. The general rule: we keep personal data for as long as we need it for the purpose we collected it for, then we delete it. Where the law sets a longer period, the law wins.

Your rights

Under the GDPR you can ask us to:

Show you
What personal data we hold about you.
Correct
Anything that is wrong.
Delete
It, where we do not have a legal reason to keep it.
Restrict
What we do with it while a dispute is being sorted out.
Hand it over
To you or another provider in a machine-readable format, where the processing is based on consent or a contract.
Stop
Processing based on legitimate interest, including profiling.
Stop
Using it for direct marketing. This right is absolute and we act on it immediately.

Where processing is based on your consent, you can withdraw it at any time.

Email hello@teamscaleup.se and we'll respond within one month. There's no charge.

If you think we've handled your data badly and we haven't fixed it, you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten):

Integritetsskyddsmyndigheten, Box 8114, 104 20 Stockholm
imy@imy.se · +46 8 657 61 00 · imy.se

Security

We limit access to personal data to the people who need it, use two-factor authentication on the systems that hold it, and choose providers who can demonstrate their own security practices. If a personal data breach puts you at risk, we will notify you and the supervisory authority as the law requires.

Children

Our services are aimed at founders and businesses. We don't knowingly collect personal data from anyone under 18.

Changes to this policy

We update this page when what we do changes. The date at the top shows when it was last updated. If a change materially affects you, we will tell you directly.

Contact

Team Scaleup AB
Malmskillnadsgatan 44 A, 111 57 Stockholm, Sweden
hello@teamscaleup.se