# Who is responsible

Parallel Collective, Svartensgatan 10, 116 20 Stockholm, Sweden, is the data controller for the processing described here. Contact: contact@parallelcollective.se.

# What we process and why

Member accounts. When you create a member account we process your name, email address, a hashed password and your language preference. Legal basis: performance of the membership contract.

Membership payments. Payments run through our payment processor Stripe. Your card details are processed by Stripe and never reach our servers. We store your membership tier, queue number, subscription status and paid period. Legal basis: performance of contract, and legal obligation for bookkeeping records.

Residency applications. Applications contain contact details, your statement, answers to cycle questions and portfolio files (images, PDFs, video). They are visible only to administrators and the assigned jury, under access controls. We keep applications for 24 months after the application cycle ends, then purge them. Legal basis: performance of the membership contract and steps taken at your request.

Newsletter. Our newsletter runs on Brevo with double opt-in: you confirm your subscription by clicking a link in a confirmation email, and we record the consent timestamp. You can unsubscribe at any time via the link in every issue. Legal basis: consent.

Art purchases. When you buy an artwork we process your name, email address, delivery address and the order details, with payment through Stripe. Order records are kept for as long as Swedish bookkeeping law requires. Legal basis: performance of contract and legal obligation.

Bot protection. Public forms are protected by Cloudflare Turnstile, which analyses technical signals to tell people from bots. Legal basis: legitimate interest in keeping our forms usable and free of abuse.

Site chat. When you use the chat, your messages are sent to our AI provider (Anthropic, with OpenAI as a fallback) to generate a reply; this can involve a transfer to the United States under the Chapter V safeguards described below. Conversations are stored with a hashed IP address, never the raw address, and are deleted after 90 days. Legal basis: legitimate interest in operating and protecting the feature.

# Cookies

Public pages set no cookies while you browse. If you switch language, a preference cookie remembers your choice. When you sign in to your member account, one strictly necessary session cookie keeps you signed in. Neither is used for tracking.

Because we use no tracking or marketing cookies, the site shows no cookie banner. There is nothing to consent to.

# Analytics without tracking

We measure visits with cookieless analytics from Plausible Analytics (EU-hosted): aggregate page statistics without cookies, cross-site identifiers or advertising profiles. No personal profile is ever built. Legal basis: legitimate interest in understanding how the site is used.

# Who receives data

We use a small set of processors under data processing agreements: Stripe (payments), Brevo (newsletter, EU-based), Postmark (transactional email), Cloudflare (bot protection and file storage), Plausible (visit statistics, EU), Anthropic and OpenAI (the AI that powers site chat and content translation), Sentry (error monitoring, EU region) and our hosting providers (Vercel for the site, Neon for the database). Some of these, notably the AI providers, process data in the United States; those transfers are covered by the safeguards in Chapter V of the GDPR, such as standard contractual clauses. Where a page embeds video from YouTube or Vimeo, the provider receives data only if you press play.

We never sell personal data.

# Funder and institution contact data

To research grants, residencies and collaborations for our members we keep a small registry of funders and institutions with their published contact routes. Wherever possible these are organisation-level addresses, such as an info@ or grants-office mailbox, which are not personal data. Where a funder itself publishes a named contact person for a grant programme, we may record that person’s name, role, work email and work phone, together with the exact public web page it came from and the date we last checked it.

We collect such details only from the funder’s or institution’s own public pages, official registers and official publications. We never buy contact lists, never use enrichment tools or private profiles, and we re-check every record against its source on a fixed schedule, at most twelve months apart. Legal basis: our legitimate interest in corresponding with funders and institutions about grants and residencies (GDPR Article 6(1)(f)).

If you are such a contact person you can ask us at any time what we hold about you, including the exact source page it came from, and you can object at any time. We treat every objection as final: your details are removed from use immediately, and a minimal suppression entry, a one-way code derived from the address rather than the address itself, ensures they are not collected again. Write to contact@parallelcollective.se.

# How long we keep data

Retention periods in summary:

  • Member account: until you ask us to delete it.
  • Residency applications, including portfolios: 24 months after the cycle ends.
  • Order and payment records: 7 years, under the Swedish Bookkeeping Act.
  • Newsletter address: until you unsubscribe.
  • Chat logs: 90 days.

# Your rights

You have the right to request access to the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, and to receive the data you provided in a portable format. Where processing rests on consent you can withdraw it at any time, without affecting processing carried out beforehand.

You exercise these rights by asking us, not through an automated self-service tool. To make a request, including access, a portable copy of your data, or erasure, email contact@parallelcollective.se; we confirm your request and respond within one month. Signed-in members can also download a copy of their membership data from the account page, which is a convenience and not a substitute for a formal request under this section.

Erasure requests are honored except where the law requires us to keep records, such as bookkeeping material.

# Complaints

If you believe we handle your personal data incorrectly, you have the right to lodge a complaint with the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY), www.imy.se.

# Changes

We update this policy when the service or the law changes. The date at the top shows the latest revision; significant changes are announced on the site.