Who is responsible #
Techsteal AB (org.nr 559416-8261), trading as Parallel Collective, is the data controller for the processing described here. Its registered address is Svartensgatan 10, 116 20 Stockholm, Sweden, and you can reach us at contact@parallelcollective.se.
What we process and why #
Member accounts. When you create a member account we process your name, email address, a hashed password and your language preference. Legal basis: performance of the membership contract.
Membership payments. Payments run through our payment processor Stripe. Your card details are processed by Stripe and never reach our servers. We store your membership tier, queue number, subscription status and paid period. Legal basis: performance of contract, and legal obligation for bookkeeping records.
Residency applications. Applications contain contact details, your statement, answers to cycle questions and portfolio files (images, PDFs, video). They are visible only to administrators and the assigned jury, under access controls. We keep applications for 24 months after the application cycle ends, then purge them. Legal basis: performance of the membership contract and steps taken at your request.
Newsletter. Our newsletter runs on Brevo with double opt-in: you confirm your subscription by clicking a link in a confirmation email, and we record the consent timestamp. You can unsubscribe at any time via the link in every issue. Legal basis: consent.
Art purchases. When you buy an artwork we process your name, email address, delivery address and the order details, with payment through Stripe. Order records are kept for as long as Swedish bookkeeping law requires. Legal basis: performance of contract and legal obligation.
Bot protection. Public forms are protected by Cloudflare Turnstile, which analyses technical signals to tell people from bots. Legal basis: legitimate interest in keeping our forms usable and free of abuse.
Site chat. When you use the chat, your messages are sent to our AI provider (Anthropic, with OpenAI as a fallback) to generate a reply; this can involve a transfer to the United States under the Chapter V safeguards described below. Conversations are stored with a hashed IP address, never the raw address, and are deleted after 90 days. Legal basis: legitimate interest in operating and protecting the feature.
Event bookings. When you book a place at an event we process your name, email address and the size of your party, so that we can hold your place and contact you about the event. Legal basis: performance of a contract and steps taken at your request. Where an event offers it, an optional question about access requirements can reveal data about your health, which is a special category of personal data under Article 9 of the GDPR. We ask it only where an event enables it, we record an answer only with your separate, explicit consent (Article 9(2)(a)), and we erase that answer 14 days after the event. Booking records that are not erased sooner are anonymised 12 months after the booking, so any later statistics are drawn from records that no longer identify you.
Cookies #
Public pages set no cookies while you browse. If you switch language, a preference cookie remembers your choice. When you sign in to your member account, one strictly necessary session cookie keeps you signed in. Neither is used for tracking.
Because we use no tracking or marketing cookies, the site shows no cookie banner. There is nothing to consent to.
Analytics #
We run no visit analytics. The site loads no page-view or measurement script, and no third-party analytics service receives data about your visit. If we ever introduce visit measurement, it will use a cookieless, EU-hosted service that builds no personal profile, and we will describe it here before it goes live.
Who receives data #
We use a small set of processors under data processing agreements: Stripe (payments), Brevo (newsletter, EU-based), Postmark (transactional email), Cloudflare (bot protection and file storage), Anthropic and OpenAI (the AI that powers site chat and content translation), Sentry (error monitoring, EU region) and our hosting providers (Vercel for the site, Neon for the database). Some of these, notably the AI providers, process data in the United States; those transfers are covered by the safeguards in Chapter V of the GDPR, such as standard contractual clauses. Where a page embeds video from YouTube or Vimeo, the provider receives data only if you press play.
We never sell personal data.
Funder and institution contact data #
To research grants, residencies and collaborations for our members we keep a small registry of funders and institutions with their published contact routes. Wherever possible these are organisation-level addresses, such as an info@ or grants-office mailbox, which are not personal data. Where a funder itself publishes a named contact person for a grant programme, we may record that person’s name, role, work email and work phone, together with the exact public web page it came from and the date we last checked it.
We collect such details only from the funder’s or institution’s own public pages, official registers and official publications. We never buy contact lists, never use enrichment tools or private profiles, and we re-check every record against its source on a fixed schedule, at most twelve months apart. Legal basis: our legitimate interest in corresponding with funders and institutions about grants and residencies (GDPR Article 6(1)(f)).
If you are such a contact person you can ask us at any time what we hold about you, including the exact source page it came from, and you can object at any time. We treat every objection as final: your details are removed from use immediately, and a minimal suppression entry, a one-way code derived from the address rather than the address itself, ensures they are not collected again. Write to contact@parallelcollective.se.
How long we keep data #
Retention periods in summary:
- Member account: until you ask us to delete it.
- Residency applications, including portfolios: 24 months after the cycle ends.
- Order and payment records: 7 years, under the Swedish Bookkeeping Act.
- Newsletter address: until you unsubscribe.
- Chat logs: 90 days.
- Event bookings: any access-requirements answer is erased 14 days after the event; the booking record is anonymised 12 months after the booking.
Your rights #
You have the right to request access to the personal data we hold about you, to have it corrected or erased, to restrict or object to processing, and to receive the data you provided in a portable format. Where processing rests on consent you can withdraw it at any time, without affecting processing carried out beforehand.
You exercise these rights by asking us, not through an automated self-service tool. To make a request, including access, a portable copy of your data, or erasure, email contact@parallelcollective.se; we confirm your request and respond within one month. Signed-in members can also download a copy of their membership data from the account page, which is a convenience and not a substitute for a formal request under this section.
Erasure requests are honored except where the law requires us to keep records, such as bookkeeping material.
Complaints #
If you believe we handle your personal data incorrectly, you have the right to lodge a complaint with the Swedish supervisory authority: Integritetsskyddsmyndigheten (IMY), www.imy.se.
Changes #
We update this policy when the service or the law changes. The date at the top shows the latest revision; significant changes are announced on the site.