How ITCM collects, uses and protects personal data — and the rights you have under the GDPR. We build privacy into our systems from the start, not as an afterthought.
Last updated: 9 July 2026
This privacy policy explains how Information Technology Consulting i Mark AB (“ITCM”, “we”, “us”) processes personal data and how we comply with the EU General Data Protection Regulation (GDPR) and Swedish data protection law. It applies when you visit itcm.se, contact us, apply for a job, or use an app or service that links here.
Many of the apps and systems we build are operated on behalf of our clients. For those services your data is controlled by the client and ITCM acts only as a data processor (see “When we process data for our clients” below). If you reached this page from such an app, please also read that service’s own privacy notice.
For the processing we carry out for our own purposes, ITCM is the data controller:
Information Technology Consulting i Mark AB
Corporate ID (org.nr): 559027-4287
Kyrkogatan 3, 511 54 Kinna, Sweden
Email: info@itcm.se
Depending on how you interact with us, we may process:
We do not intentionally collect special categories of data (such as health or political opinions), and we never sell personal data to anyone.
When we build, host or operate an application or system for a client, that client decides why and how personal data is processed — they are the controller and ITCM is a data processor acting on their documented instructions.
In those cases we process personal data only under a written data processing agreement (DPA) that requires appropriate security measures, confidentiality, control over sub-processors, and support for the controller in meeting its GDPR obligations. If you use such a service and want to exercise your rights, contact the organisation that provides it; we will support them in responding.
We share personal data only where necessary, with:
We choose sub-processors that provide adequate guarantees under the GDPR, and we host data within the EU/EEA wherever possible.
Where a provider processes data outside the EU/EEA, we make sure the transfer is protected by an adequacy decision or by appropriate safeguards such as the European Commission’s Standard Contractual Clauses, together with additional technical measures where needed.
We keep personal data only for as long as it is needed for the purpose it was collected, or as required by law. Enquiries and correspondence are kept while the relationship is active and for a reasonable period afterwards; accounting records are kept for seven years under Swedish law; job applications are kept for the duration of the recruitment process unless you agree to us keeping them longer.
Security is central to how we build systems. We apply encryption in transit, access controls and the principle of least privilege, network segmentation, logging and monitoring, regular updates and security reviews. We design new systems with data protection by design and by default, and we limit the personal data we collect to what is necessary.
Where ITCM is the controller, you have the right to:
To exercise any of these rights, email us at info@itcm.se. We will respond within one month.
We use necessary cookies to make the site work, and analytics and marketing cookies only with your consent. You can review and change your choices at any time through the cookie settings on this website.
If you have any questions about how we handle your personal data, contact us at info@itcm.se — we are happy to help.
You also have the right to lodge a complaint with the Swedish supervisory authority, the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), at imy.se.
We may update this policy from time to time. When we make significant changes we will update the date at the top of the page and, where appropriate, notify you.