Legal

Privacy Policy

Last updated: March 2026  ·  Governing law: Sweden / GDPR (EU) 2016/679

1. Who We Are

This website is operated by Lampo, an AI automation agency based in Stockholm, Sweden. We are the data controller for personal data collected through this website.

Operated by: Jason Wall, trading as Lampo
Alviksvägen 23, 167 53 Bromma, Stockholm, Sweden

For privacy-related questions, contact us at: jasonw@lampo.se

2. What Data We Collect and Why

2.1 Data You Provide Directly

When you fill in a contact or enquiry form on this site, we collect:

  • Name
  • Email address
  • Company name (if provided)
  • Message content

Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) — to respond to your enquiry and assess whether we can help your business. Where you have requested a proposal or quote, the basis is pre-contractual steps (Art. 6(1)(b)).

2.2 Data Collected Automatically

When you visit our website, we and our third-party service providers automatically collect technical data including:

  • IP address (anonymised where possible)
  • Browser type and version
  • Device type and operating system
  • Pages visited, time on page, referral source
  • Approximate geographic location (city/country level)

Legal basis: Legitimate interest (Art. 6(1)(f)) for security and basic analytics. Consent (Art. 6(1)(a)) for marketing pixels and behavioural tracking — see Section 4 (Cookies).

2.3 Facebook Pixel

This website uses the Facebook Pixel, a tracking tool provided by Meta Platforms Ireland Ltd. The pixel collects data about your behaviour on our site (pages visited, actions taken) and sends it to Meta. This data may be used to:

  • Measure the effectiveness of our Facebook and Instagram advertising
  • Build custom audiences for ad targeting
  • Retarget visitors who have previously visited our site

Legal basis: Consent (Art. 6(1)(a)). The pixel is not loaded until you accept cookies.

Data processed by Meta may be transferred to the United States under Standard Contractual Clauses (SCCs). See Meta's privacy policy at facebook.com/privacy/policy.

Our Pixel ID is 906431410821205.

2.4 Google Fonts

This site loads fonts (Syne and Inter) from Google Fonts, a service operated by Google LLC. When the page loads, your browser makes a request to Google's servers, which logs your IP address. Google states it does not use this data for advertising or tracking purposes. See Google's Privacy Policy.

Legal basis: Legitimate interest (Art. 6(1)(f)) — delivery of a correctly rendered website experience. Data is transferred to the US under SCCs.

3. How Long We Keep Your Data

  • Contact form enquiries: 24 months from last contact, unless we enter a client relationship (in which case retention follows our client data policy).
  • Analytics data: Aggregated — retained indefinitely. Individual session data — maximum 14 months.
  • Facebook Pixel data: Governed by Meta's retention policies (typically up to 180 days for custom audience data).

4. Cookies

Cookies are small text files stored on your device. We use the following categories:

Category Purpose Provider Consent required?
Strictly necessary Site functionality, security Lampo (first-party) No
Analytics Understanding how visitors use the site Yes
Marketing / tracking Ad measurement, retargeting Meta (Facebook Pixel) Yes

You can withdraw consent at any time by clicking Cookie Settings in the footer, or by clearing cookies in your browser.

5. Third-Party Service Providers

We use trusted third-party services to operate our business. Where these services process personal data on our behalf, we have Data Processing Agreements in place.

Provider Purpose Location Transfer mechanism
Meta Platforms Ireland Ltd Facebook Pixel, ad measurement Ireland / USA SCCs
Google LLC Font delivery (Google Fonts) USA SCCs
Google LLC (Google Workspace / Gmail) Email communications and contact form responses USA SCCs

6. Your Rights Under GDPR

As a data subject in the EU/EEA, you have the following rights. You can exercise any of these by contacting us at jasonw@lampo.se. We will respond within 30 days.

Right of Access (Art. 15) Request a copy of the personal data we hold about you.
Right to Rectification (Art. 16) Ask us to correct inaccurate or incomplete data.
Right to Erasure (Art. 17) Request deletion of your data ("right to be forgotten").
Right to Restrict Processing (Art. 18) Ask us to pause how we use your data in certain circumstances.
Right to Data Portability (Art. 20) Receive your data in a structured, machine-readable format.
Right to Object (Art. 21) Object to processing based on legitimate interest, including direct marketing.
Right to Withdraw Consent (Art. 7) Where processing is based on consent, withdraw it at any time.
Right to Complain (Art. 77) Lodge a complaint with Sweden's supervisory authority: IMY.

To complain to the Swedish supervisory authority:
Integritetsskyddsmyndigheten (IMY)
imy.se  ·  +46 8 657 61 00  ·  imy@imy.se

7. Data Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, or disclosure. These include:

  • Encrypted data transmission (HTTPS/TLS)
  • Access controls limited to authorised personnel
  • Regular review of third-party processor security practices

In the event of a personal data breach that is likely to result in risk to your rights and freedoms, we will notify the relevant supervisory authority (IMY) within 72 hours and, where required, notify affected individuals without undue delay.

8. International Data Transfers

Some of our service providers are located outside the European Economic Area (EEA), primarily in the United States. We ensure that any such transfer is covered by an appropriate safeguard as required under Chapter V of the GDPR, including:

  • Standard Contractual Clauses (SCCs) — the EU Commission's approved template contracts that bind the recipient to EU-equivalent protections.
  • Adequacy decisions — where the European Commission has determined that the recipient country offers an adequate level of protection.

9. Children's Privacy

Our services are directed at businesses and professionals. We do not knowingly collect personal data from individuals under the age of 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

10. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices or applicable law. We will update the "last updated" date at the top of this page. For significant changes, we will take reasonable steps to notify you.

11. Contact Us

Data Controller

Jason Wall, trading as Lampo
Alviksvägen 23
167 53 Bromma
Stockholm, Sweden

Privacy enquiries: jasonw@lampo.se
General enquiries: jasonw@lampo.se

N