Skip to content
Hemvia

Privacy Policy

Effective date: 27 September 2026

1. Who is responsible

Julianna Cordes (enskild näringsverksamhet, firm "Mossblom", brand "Hemvia"), Kyrkvägen 22, 362 58 Linneryd, Sweden, e-mail: privacy@hemvia.eu (the "controller" under the EU General Data Protection Regulation, GDPR).

2. The short version

Hemvia is built to store as little personal data as possible. Your answers and task progress are saved in your own browser (localStorage). When you finish the questions at the start, we also store your answers, your e-mail address and, from then on, your task progress in our database (Supabase, see §6) — so we can send you the sign-in link for your plan and keep your plan recoverable. We also record which pages and questionnaire steps are opened, so we can improve Hemvia (see §3). About children we only ever ask for age ranges — no names, no birth dates. We do not ask for or store documents such as passports, permits, contracts, or bank or health records.

3. Data before you create an account

In your browser (localStorage) we store your answers (for example: where you are moving from, planned timing, family situation as age ranges, language level) and your task progress. When you save your plan, send us feedback, ask to be notified about another country, share an experience or mark an experience note, our database service Supabase also stores a technical, anonymous session identifier there, which links your browser to what you saved. You can remove this local data at any time by clearing your browser data for this site.

When you finish the questions at the start, we also store your answers, the e-mail address you entered and whether you ticked the optional box for planning tips in our database (Supabase, EU region, see §6), linked to that anonymous identifier. After that, the status of your tasks (open, in progress, done) is stored there as well. Purpose: to send you the sign-in link for your plan and to keep your plan recoverable when you create an account. Legal basis: performance of the free user agreement and steps taken at your request before entering into it (Art. 6(1)(b) GDPR). For the optional planning-tips box, the legal basis is your consent (Art. 6(1)(a) GDPR); you can withdraw it at any time by writing to privacy@hemvia.eu.

If you write notes in Hemvia — a note or a case or reference number on a task, or a note on the Notes page, optionally with a date and time — we store them in your browser and, like your task progress, in our database, linked to your plan, so they are not lost and come back when you sign in on another device. They are shown only to you. We do not read, evaluate or pass them on; our database service Supabase stores them on our behalf (§6). Please do not enter ID, bank or health details. Legal basis: performance of the free user agreement (Art. 6(1)(b) GDPR). Notes are deleted with your plan (§8) or when you delete them. A calendar file for an appointment is created on your device; we do not send it anywhere.

If you share an experience after finishing a task, we store your text, the task it belongs to, the language, and when and to which version of the consent text you agreed, linked to your plan. We never show single reports: when several reports on a task point the same way, a person at Hemvia may write one summary from them without names, and only that summary is shown. Before storing, we automatically check the text for contact details, ID or account numbers and links and refuse it if it contains them; please do not include health details or anything that identifies your children. Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time by writing to privacy@hemvia.eu; your text is then deleted. A summary that has already been published stays, because it contains nothing that identifies you. Otherwise, a report we do not use is deleted as soon as we decide not to use it, and at the latest after 12 months; a report used for a summary is kept while that summary is shown. In every case your text is deleted with your plan (§8). If you mark an experience note as not helpful or out of date, we store that mark with your plan so that each person counts only once; it is deleted after the note has been reviewed, or with your plan. Legal basis: our legitimate interest in keeping these notes accurate (Art. 6(1)(f) GDPR).

If we write to an organisation (for example an employer's HR team, a school or a congregation) about Hemvia, we use the contact address it has published and keep the address and our correspondence in our e-mail inbox. Legal basis: our legitimate interest in making Hemvia known to organisations that help people moving to Sweden (Art. 6(1)(f) GDPR). You can object at any time; we then delete the correspondence and keep only a note not to contact you again.

We also record which pages and questionnaire steps are opened and, if you arrived through a link with campaign parameters, its source. These records carry only a random number that exists while the browser tab is open; nothing is stored on your device for this, and the records are not linked to your answers, your e-mail address or your account. This shows us where people stop and helps us improve the questions. Legal basis: our legitimate interest in understanding and improving Hemvia (Art. 6(1)(f) GDPR); you can object at any time (§9).

If you send us feedback or ask to be notified when Hemvia covers another country, we store what you enter (feedback: page, rating and optional text; notification: e-mail address and country) in the same database, Supabase. Legal basis: for feedback, our legitimate interest in improving Hemvia (Art. 6(1)(f) GDPR); for the notification, your request and consent (Art. 6(1)(a) GDPR), which you can withdraw at any time.

Our web host processes technical connection data (such as your IP address) in server logs to deliver the site securely — legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).

4. Data if you create an account

If you create an account, we store: your e-mail address (so you can sign in and your progress isn't lost) and the answers you gave when you started, plus your task progress (to build and keep your personal relocation plan). Legal basis: performance of the free user agreement between you and us, and steps taken before entering into it (Art. 6(1)(b) GDPR). Hemvia has no payment function: we do not process purchases, payment data or billing information of any kind, and no payment provider is involved.

If you switch on e-mail reminders in your account, we send you an e-mail when steps in your plan are still open and you have neither opened nor changed your plan for 14 days — at most one e-mail every 30 days, and no more than two in a row if you don't use your plan in between. For this we use your e-mail address, your answers and task progress (to find the open steps), when you last opened or changed your plan, and a record of which reminder we sent and when. Legal basis: your consent (Art. 6(1)(a) GDPR). You can withdraw it at any time in your account, with the link in every reminder or by writing to privacy@hemvia.eu; withdrawing does not affect reminders already sent. The record of sent reminders is deleted with your account.

If you deepen your plan (optional), we store the topics you chose (up to two), your time per week, your municipality and when you saved them, linked to your plan. We use them only to order your weekly focus and to show your municipality's website on matching steps. Legal basis: performance of the free user agreement (Art. 6(1)(b) GDPR). You can change them at any time; they are deleted with your account (§8).

5. What we deliberately do not collect

No child names or exact birth dates (age ranges only). No document uploads. No passport, ID, permit, bank or health data. No advertising trackers.

6. Recipients and processors

We use service providers who process data on our behalf under Art. 28 GDPR data-processing agreements:

  • Hosting and deployment: Vercel Inc. (USA). Serves the website and processes technical connection data (such as IP address) in server logs. Active.
  • Website analytics: Vercel Web Analytics (Vercel Inc., USA). Cookie-free page-view statistics. Visits are counted using a short-lived identifier that is discarded after 24 hours; no identifiers are used that track you across other websites. Recorded per page view are, for example: the page path, referrer, approximate location (country/region/city level), device type, operating system and browser version — aggregated statistics that cannot identify individual visitors. We additionally remove query strings and URL fragments before the data is sent, so no address parameters ever reach the analytics service. Active.
  • Database and authentication: Supabase Inc. (USA), data stored in an EU region. Stores the data described in §3 and §4 — your answers, e-mail address, task progress, your notes, your plan preferences, experiences you share, your marks on experience notes and our own usage records — and provides the anonymous session and sign-in. Active.
  • E-mail delivery: Resend (Plus Five Five, Inc., USA). Sends sign-in and e-mail-confirmation messages and, if you have switched them on, reminders about open steps in your plan (§4). Processes your e-mail address and the message content. Active. We do not use Resend for advertising e-mail.
  • Domain registration and e-mail inbox: Strato AG (Germany) — registers our domains (hemvia.eu; hemvia.de redirect) and hosts the inbox for our addresses (such as privacy@hemvia.eu). If you write to us, it stores your e-mail address and your message. No website hosting. Active.
  • DNS, website security and e-mail routing: Cloudflare, Inc. (USA) — resolves our domain, routes traffic to our host and forwards e-mails sent to our addresses to our inbox; in doing so it processes technical connection data (such as IP address) and, for forwarded e-mails, sender, recipient and content. Active.

Several of these providers are established in the USA or process data there. Where that is the case, the transfer is based on the European Commission's Standard Contractual Clauses agreed in the respective provider's data-processing agreement, supplemented by that provider's own safeguards. We do not sell personal data and do not share it with advertisers.

7. Cookies and local storage

We currently use no advertising or third-party analytics cookies. The Vercel page statistics (§6) are cookie-free by design. We use your browser's localStorage to save your answers, your progress and — once you save your plan, send feedback, ask to be notified, share an experience or mark an experience note — the anonymous session identifier described in §3, plus small technical markers (for example, whether you have already seen the dashboard), and, for our internal admin area, to store review states. Our own usage records (§3) store nothing on your device. If this changes, we will update this policy first.

8. How long we keep data

Local data in your browser stays until you delete it. If you have no account, your data in our database (§3) is deleted automatically once your plan has been neither opened in your browser nor changed for 12 months; feedback and notification requests sent without an account are deleted 12 months after you sent them. Our usage records (§3) are deleted automatically after 12 months. You can also ask us to delete your data at any time (§9a). Account data is deleted when you ask us to delete your account (§9a), unless we are legally required to retain something.

9. Your rights

Under the GDPR you can request access to your data, correction, deletion, restriction of processing, and a copy of data you provided in a portable format (Art. 15–20 GDPR), and you can object to processing based on legitimate interest (Art. 21 GDPR). Write to privacy@hemvia.eu. You also have the right to lodge a complaint with a supervisory authority — in Sweden this is IMY (Integritetsskyddsmyndigheten, www.imy.se); you may also contact the authority in your home country.

9a. How to request deletion of your data

To ask us to delete your data (right to erasure, Art. 17 GDPR), write to privacy@hemvia.eu. We currently handle every deletion request manually — there is no automatic self-service deletion yet — and we let you know once it is done. This is the reachable way to exercise your GDPR erasure right today; a self-service "delete my account" option in the product is planned for later. This section is linked directly from the site footer ("Request data deletion") so it does not require reading the whole policy to find.

10. Changes

We will update this policy when our practices change and show the current version with its effective date here.