Privacy policy
Privacy policy for Imeto Consulting AB
Last updated: 2026-04-27
Introduction
Imeto Consulting AB ("imeto", "we", "us") cares about your personal privacy. This policy describes how we collect, use, store and protect personal data in accordance with the EU General Data Protection Regulation (GDPR).
We process personal data in several contexts – as an employer, as the recipient of candidate information during recruitment, and as a company that conducts marketing and business development towards potential clients, as well as in relationships with suppliers and partners.
Data controller
Imeto Consulting AB
Org. registration number: 559477-9919
Address: Katarinavägen 19, 116 45 Stockholm, Sweden
Email: hello@imeto.com
imeto is the data controller for the processing described in this policy.
Categories of personal data we process
Clients and prospective clients
- Name, role and contact details (address, email, phone number)
- Company name and industry
- Information about previous and potential business relationships
- Invoicing and payment details
Employees and consultants
- Identity details (name, personal identity number)
- Contact details
- Salary and employment terms
- Time reports, project information and evaluations
- Information required by law (e.g. tax details)
Candidates in recruitment
- CV, cover letter, references and interview data
- Any test results and notes from the recruitment process
Suppliers and partners
- Name, role and contact details for points of contact
- Company name and registration number
- Contract and invoicing details
Purposes of processing
| Purpose | Categories of data subjects |
| Marketing to prospective clients | Company representatives |
| Client administration and contract management | Clients, suppliers |
| HR administration | Employees, consultants |
| Recruitment | Candidates |
| Supplier and partner management | Suppliers, partners |
| Accounting and invoicing | Clients, suppliers, employees |
| Follow-up and statistics | All categories |
For all of the purposes above, imeto has a legal basis for the processing under the GDPR – such as performance of a contract, legal obligation, legitimate interest or consent. The legal basis for a specific processing activity can be provided on request by contacting us at hello@imeto.com.
Where we collect data from
We collect personal data directly from you when you contact us, apply for a job or work with us.
Storage and retention
Personal data is not stored for longer than is necessary for the purpose. As a starting point, we apply the following retention periods:
- Client data is kept for as long as the business relationship continues and for up to 24 months thereafter, unless otherwise required by law or contract.
- Invoicing, payment and accounting records are kept for 7 years after the end of the calendar year in which the financial year ended, in accordance with the Swedish Bookkeeping Act (1999:1078).
- Candidate data is deleted or anonymised no later than 24 months after the end of the recruitment process, unless consent for longer storage has been given. Underlying employment documents are retained in accordance with employment and accounting legislation.
- Employee data is kept during employment and thereafter in accordance with applicable accounting and employment legislation, normally up to 10 years for information subject to the statute of limitations.
- Supplier and partner data is kept for as long as the cooperation continues and for as long as the Swedish Bookkeeping Act requires for the related records (7 years).
- Marketing data and leads is kept until the data subject objects to the processing, but for no longer than 24 months after the most recent contact.
Sharing of data
We handle most personal data internally at imeto. In some cases we need to share it – but only when there is a clear reason to do so, and never to sell it. Below is how this works depending on your relationship with us.
If you are a client or prospective client
Your data is handled internally at imeto. We may share it with third parties we use to run our business (for example, providers of technical or administrative services), but only to the extent needed to manage our professional relationship with you. Before we share anything, we make sure appropriate safeguards are in place to protect your data, and our providers are contractually prevented from using your data for their own purposes.
If you apply for a job at imeto
Your application is handled internally at imeto. If we use a recruitment agency or recruitment tool in the process, your information is shared with them. We may also share your data with authorities or public bodies if we are required to do so by law.
If you are a supplier to imeto
Your data may be shared with third parties we use to deliver services on our behalf when this is needed to manage our relationship with you – for example, for invoice handling. The same safeguards apply: we check that protection is in place before sharing, and providers cannot use your data for their own purposes.
If you are a sub-consultant to imeto
Your data is handled internally at imeto. We may share it with our clients so that you can carry out your assignment – for example, to give you access to IT systems and offices, and to allow any security checks to be performed. Your data may also be shared with third parties we use for things like invoice handling, with the same safeguards as above. We may also share your data with third parties if we are required to do so by law.
Marketing activities
When we run events, send press releases or send out newsletters, we may process your personal data – typically contact details, photographs or recorded material. For recorded material, we provide more specific information at the time of recording.
If you contact us about something else
If you contact us in your personal capacity, we keep that information to ourselves. If you contact us as a representative of a business, we may share that information within imeto's professional network.
Transfers to countries outside the EU/EEA
Some of our service providers (e.g. for email, collaboration tools, CRM and marketing) are established in the United States or use sub-processors in third countries. When personal data is transferred outside the EU/EEA, we ensure that the transfer is made on the basis of:
- An EU Commission adequacy decision (e.g. the EU–US Data Privacy Framework), or
- The EU Commission's Standard Contractual Clauses (SCCs), supplemented with any additional technical and organisational safeguards where needed.
You have the right to request information about which safeguards are applied to a specific transfer by contacting us at hello@imeto.com.
Security
imeto uses technical and organisational security measures to protect personal data, such as encryption, access controls and incident management procedures.
Your rights
You have the right to:
- Request access to your data
- Request rectification or erasure
- Object to processing based on legitimate interest
- Restrict processing
- Request data portability
- Withdraw consent given (where processing is based on consent)
- Lodge a complaint with the Swedish Authority for Privacy Protection (IMY)
Requests can be sent to hello@imeto.com.
Notifications regarding rectification, erasure or restriction (Article 19 GDPR)
When imeto rectifies, erases or restricts the processing of personal data at the request of a data subject, we notify the recipients who previously received access to the data about the action, to the extent that this is possible or does not involve a disproportionate effort.
If you as a data subject so request, we will inform you about which recipients have been notified.
Changes to this policy
imeto may update this policy as needed. The most recent version is always published on our website and is shared on request, without the requester needing to give a reason.