Skip to content
Hemvia

Privacy Policy

Effective date: 11 August 2026

1. Who is responsible

Julianna Cordes (enskild näringsverksamhet, firm "Mossblom", brand "Hemvia"), Kyrkvägen 22, 362 58 Linneryd, Sweden, e-mail: privacy@hemvia.eu (the "controller" under the EU General Data Protection Regulation, GDPR).

2. The short version

Hemvia is built to store as little personal data as possible. Your answers and task progress are saved in your own browser (localStorage). If you sign in, your e-mail address and that same data are also stored on our servers so you can pick up your plan on another device (see §3 and §4). About children we only ever ask for age ranges — no names, no birth dates. We do not ask for or store documents such as passports, permits, contracts, or bank or health records.

3. Data in the current version (no account)

When you use Hemvia today, your answers (for example: where you are moving from, planned timing, family situation as age ranges, language level, your topics of concern) and your task progress are stored locally in your browser. This data stays on your device; you can remove it at any time by clearing your browser data for this site. Our web host processes technical connection data (such as your IP address) in server logs to deliver the site securely — legal basis: our legitimate interest in operating a secure website (Art. 6(1)(f) GDPR).

4. Data if you sign in

If you create an account, we store: your e-mail address (so you can sign in and your progress isn't lost) and the answers you gave when you started, plus your task progress (to build and keep your personal relocation plan). Legal basis: performance of a contract or steps prior to entering one (Art. 6(1)(b) GDPR). If you buy a premium report, we additionally store the report we generated for you and payment status; payment details themselves are handled by our payment provider, not by us.

5. What we deliberately do not collect

No child names or exact birth dates (age ranges only). No document uploads. No passport, ID, permit, bank or health data. No advertising trackers.

6. Recipients and processors

We use service providers who process data on our behalf under Art. 28 GDPR data-processing agreements:

  • Hosting and deployment: Vercel Inc. (USA). Serves the website and processes technical connection data (such as IP address) in server logs. Active.
  • Website analytics: Vercel Web Analytics (Vercel Inc., USA). Cookie-free page-view statistics. Visits are counted using a short-lived identifier that is discarded after 24 hours; no identifiers are used that track you across other websites. Recorded per page view are, for example: the page path, referrer, approximate location (country/region/city level), device type, operating system and browser version — aggregated statistics that cannot identify individual visitors. We additionally remove query strings and URL fragments before the data is sent, so no address parameters ever reach the analytics service. Active.
  • Database and authentication: Supabase Inc. (USA), data stored in an EU region. Stores account data and your plan once accounts are in use. Active for authentication.
  • Transactional e-mail: Resend (Plus Five Five, Inc., USA). Sends sign-in and email-confirmation messages. Processes your email address and the message content. Active. Resend is used only for these transactional messages; we do not use it for advertising email.
  • Domain registration: Strato AG (Germany) — domain registration only (hemvia.eu; hemvia.de redirect), no hosting, no e-mail. Active.
  • DNS and website security: Cloudflare, Inc. (USA) — resolves our domain and routes traffic to our host; in doing so it processes technical connection data (such as IP address). Active.

Several of these providers are established in the USA or process data there. Where that is the case, the transfer is based on the European Commission's Standard Contractual Clauses agreed in the respective provider's data-processing agreement, supplemented by that provider's own safeguards. We do not sell personal data and do not share it with advertisers.

7. Cookies and local storage

We currently use no advertising or third-party analytics cookies. Our website analytics (§6) is cookie-free by design. We use your browser's localStorage to save your answers and progress on your device (see §3) and, for our internal admin area, to store review states. If this changes, we will update this policy first.

8. How long we keep data

Local data in your browser stays until you delete it. Account data is kept while your account is active and deleted when you delete your account or ask us to — except where law requires us to keep records (e.g. bookkeeping records for purchases, kept for the statutory period).

9. Your rights

Under the GDPR you can request access to your data, correction, deletion, restriction of processing, and a copy of data you provided in a portable format (Art. 15–20 GDPR), and you can object to processing based on legitimate interest (Art. 21 GDPR). Write to privacy@hemvia.eu. You also have the right to lodge a complaint with a supervisory authority — in Sweden this is IMY (Integritetsskyddsmyndigheten, www.imy.se); you may also contact the authority in your home country.

9a. How to request deletion of your data

To ask us to delete your data (right to erasure, Art. 17 GDPR), write to privacy@hemvia.eu. We currently handle every deletion request manually — there is no automatic self-service deletion yet — and we let you know once it is done. This is the reachable way to exercise your GDPR erasure right today; a self-service "delete my account" option in the product is planned for later. This section is linked directly from the site footer ("Request data deletion") so it does not require reading the whole policy to find.

10. Changes

We will update this policy when our practices change and show the current version with its effective date here.