Whatifio
  • Services
  • Case Studies
  • Engagement
  • About
  • Contact
  • Blog
Privacy

Privacy notice.

How Whatifio AB collects, uses, protects, and shares personal data, and how you can exercise your rights under the GDPR.

Last updated: 11 August 2026 · Version 1.0

The short version: If you fill in a form, book a call, or email us, we use your details to reply. We do not sell or share your data. You can ask to see or delete what we have at any time by writing to info@whatifio.com.

1. Who we are

Whatifio AB ("Whatifio", "we", "us") is the data controller for the personal data described in this notice.

  • Registered address: Gillesgatan 7C, 554 54 Jönköping, Sweden
  • Org.nr: 559546-2895
  • Contact: info@whatifio.com

2. What we collect and why

WhatWhyLegal basis
Name, company, email, phone, topic, message from the contact and booking forms. To reply to your enquiry and prepare for a first call. Steps prior to entering into a contract (GDPR Art. 6(1)(b)) and our legitimate interest in responding to enquiries (Art. 6(1)(f)).
Marketing opt-in flag, if you tick the box on a form. To send you occasional Whatifio articles and updates. Your consent (Art. 6(1)(a)). You can withdraw at any time.
Meeting details you submit through Microsoft Bookings (name, email, chosen slot). To confirm and hold the meeting. Contract preparation (Art. 6(1)(b)).
IP address, briefly, in the request path. To rate-limit our forms against spam and abuse. Legitimate interest in protecting the service (Art. 6(1)(f)). Stored for less than one hour.

We do not use analytics cookies, tracking pixels, advertising SDKs, or profiling. The site sets a small amount of local browser storage to remember whether you have already seen a spotlight popup; this stays on your device.

3. How long we keep it

CategoryRetention
Enquiry without marketing opt-inUp to 12 months after the last contact, then deleted.
Marketing opt-in contactWhile you remain engaged. Deleted or re-consent requested after 24 months of no activity.
Unsubscribed contactEmail + suppression flag kept indefinitely so we do not re-add you. All other fields wiped on unsubscribe.
Customer / invoicing records7 years, as required by the Swedish Accounting Act (Bokföringslagen).

We keep encrypted backups of the enquiry list so we can recover it after accidental loss. Backups are held for a maximum of three months and then permanently deleted, so anyone who unsubscribes is removed from every copy within that window. If we ever restore from a backup, we re-apply the current unsubscribe list before using the data again.

4. Who else sees your data

Whatifio is a small operation. Your data is processed by a short list of trusted service providers acting on our behalf:

  • Microsoft Corporation — email (Microsoft 365), lead storage (SharePoint), calendar and bookings, hosting (Azure). Covered by Microsoft’s standard Data Processing Addendum, with EU data residency.
  • Anthropic PBC — the Claude API, used only for the internal admin tool that helps us draft site content. It never sees your enquiry text.
  • GitHub, Inc. — source code and content management sign-in.
  • GoDaddy — domain registration and DNS.

We do not sell your data. We do not share it for third-party marketing. We do not transfer it outside the EU/EEA except through the standard contractual clauses offered by the providers above.

5. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you.
  • Ask us to correct anything that is wrong.
  • Ask us to delete your data (the right to erasure).
  • Receive your data in a portable format.
  • Object to processing, or ask us to restrict it.
  • Withdraw consent for marketing at any time (use the unsubscribe link in any email, or email us).
  • Complain to the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY).

6. How to exercise your rights

Email info@whatifio.com. We aim to respond within one business day and, for formal requests, within the 30-day GDPR deadline. We may need to verify your identity to protect against impersonation.

7. Security

We use industry-standard practice appropriate for our scale: HTTPS everywhere, multi-factor authentication on all admin accounts, secrets stored in Azure and never in code, rate-limited public endpoints, and least-privilege access to Microsoft Graph and SharePoint. We do not store passwords, payment details, or special-category personal data.

8. Changes to this notice

If we make material changes, we will update this page and the "Last updated" date. For anyone still receiving marketing from us, we will also send a notice by email.

Something feels off, or you want to see what we have on you? Just email info@whatifio.com. No lawyer needed — we would rather sort it out directly.
Whatifio

Whatifio AB is a Microsoft Cloud and AI consultancy based in Jönköping, Sweden. Founder led, certification backed, outcome focused.

Site

  • Services
  • Case Studies
  • Engagement
  • About
  • Contact
  • Blog

Contact

  • info@whatifio.com
  • LinkedIn
  • Jönköping, Sweden
  • Privacy notice
© 2026 Whatifio AB. All rights reserved. From what if to insight.