1. Scope and controller
This notice covers kvarteriq.se, KvarterIQ accounts and workspaces, password authentication and email verification, saved research, alerts, subscriptions and evidence-grounded research features. Kvarteriq AB, identified above, is the controller for this processing.
Public source statistics and geographic facts are not personal data about a KvarterIQ user merely because the user views them. A search, saved area or research question can, however, become personal data when linked to an account or device.
2. Data KvarterIQ may process
Depending on the features you use, KvarterIQ processes the following categories:
- account and identity data: name, email address, email-verification status, identity identifier, language and accepted terms version. The password credential is managed by Google Identity Platform and is not stored in KvarterIQ's workspace database;
- profile and preference data: onboarding answers, household or professional context, followed areas and optional email preferences;
- workspace content: saved areas, comparisons, alerts, exports and account settings;
- research content: questions, selected geographies, conversation records, evidence, feedback and prepared actions;
- security and technical data: session identifiers, user-agent information, timestamps, request limits, security events and limited service logs;
- billing records when enabled: plan, customer and subscription references, payment status, consent record and transaction metadata, but not full card details;
- communications: messages and information you send when requesting support or exercising a right.
3. Sources of personal data
Most data comes directly from you when you register, answer optional profile questions, save research, ask a question, configure an alert, choose a plan or contact KvarterIQ. Identity, delivery and payment providers return limited verification, delivery, customer or subscription status needed to operate those features.
KvarterIQ does not obtain private property-owner dossiers from the public statistics shown in reports and does not treat an official area observation as a fact about an individual user.
4. Purposes and legal bases
KvarterIQ uses personal data only for stated purposes and with a documented legal basis:
- contract or steps requested before a contract: create and secure an account, provide the workspace, save research, deliver requested alerts, exports, support and billing;
- legal obligation: accounting, tax, consumer-law records, lawful requests and data-protection duties;
- legitimate interests: protect accounts and systems, prevent abuse, diagnose failures, maintain source and service integrity, and establish or defend legal claims, after balancing your rights;
- consent: optional change-notification emails or any future non-essential cookies or marketing where consent is required. Consent can be withdrawn at any time without affecting earlier lawful processing.
5. Personalisation and research assistance
Optional profile answers tailor the order and relevance of workspace information. They do not become observed facts about an area and do not enter KvarterIQ's shared housing-market forecast model. You can skip optional questions and later change or delete answers.
If live research assistance is activated, the necessary question, selected geography and approved evidence may be sent to an evaluated model provider to produce a draft answer. KvarterIQ applies evidence checks before display and does not use this feature to make a solely automated decision with legal or similarly significant effects about you.
6. Cookies and browser storage
KvarterIQ currently uses only storage necessary for requested functionality, including a secure, HTTP-only sign-in session cookie. The service does not currently use browser storage for advertising or cross-site tracking.
Product analytics, advertising cookies and cross-site tracking are not currently enabled. KvarterIQ will request prior consent before placing a non-essential cookie where required.
7. Recipients and processors
Access is limited to authorised people and processors who need the data for the stated purpose. Current or planned processor categories include Google Cloud and Identity Platform for hosting and authentication, Resend for transactional email, and Stripe for payment and subscription processing when checkout is activated.
KvarterIQ does not sell personal data. Personal workspace content is not disclosed to property sellers, brokers or data brokers. A processor may use data only under documented instructions, confidentiality and security obligations, except where it has an independent legal duty.
8. International transfers
KvarterIQ selects EU regions where the service configuration supports them. Some providers or their support operations may nevertheless make personal data available outside the EU/EEA. Before activation, each transfer must be documented and rely on an applicable adequacy decision, approved standard contractual clauses or another lawful safeguard, with additional measures where required.
You may contact KvarterIQ for information about the relevant transfer mechanism after the final processor review is approved.
9. Retention
KvarterIQ keeps personal data only as long as needed for the stated purpose:
- active account, profile, saved research and preferences: until you delete them or the account, subject to limited legal exceptions;
- research conversations in the initial assistant beta: 30 days unless a clearly offered saved-record feature states another period;
- signed-in sessions: five days, with expired or revoked session records removed after a further 30 days;
- request-limit records: two days; security audit events: 12 months; notification delivery events: 24 months;
- billing, tax, consent and dispute records: for the period required by applicable law or necessary for legal claims;
- backups and provider logs: for the shortest configured rotation period consistent with security, restoration and legal requirements.
10. Security
KvarterIQ uses Identity Platform password authentication, separate email verification, encrypted transport, secure session cookies, least-privilege service identities, private database networking, row-level account isolation, access logging and tested export and deletion boundaries. No system can guarantee absolute security, but KvarterIQ applies measures appropriate to the data and risk.
If a personal-data breach is likely to create a high risk, affected people and the competent authority will be informed as required by law.
11. Your rights
Subject to GDPR conditions and exceptions, you may request access, correction, deletion, restriction or portability of your personal data and object to processing based on legitimate interests. You may withdraw consent at any time and may request human review if a future feature makes a qualifying automated decision.
The workspace is designed to provide export and permanent deletion controls. KvarterIQ may need to verify your identity before acting on a request and will normally respond within one month. You may complain to the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.
12. Children
KvarterIQ accounts are intended for adults aged 18 or over. KvarterIQ does not knowingly offer accounts to children or ask users to provide children's personal data in free-text research questions.
13. Changes to this notice
The notice carries a date and version. KvarterIQ will publish an updated notice and provide appropriate advance information when a material change affects account data or user choices. A new legal basis or consent will be obtained when required; a notice change does not retroactively authorise a new purpose.