Camphouse Saas
Privacy
Last updated: 10 September 2026
1. Introduction
About this Privacy Notice
Camphouse AB (“Camphouse”, “we”, “us”, “our”) provides a marketing management platform that gives marketers an overview and real-time control of their marketing activities (the “Service”). This Privacy Notice explains how we collect and use personal data, who we share it with, how long we keep it and what rights you have.
It applies when you visit or interact with camphouse.io or our other public web pages (the “Site”), use the Service as an authorised user of a Camphouse customer, contact us, act as a customer contact, prospect, supplier, partner or other business contact of Camphouse, register for or attend a Camphouse webinar or event, or otherwise interact with Camphouse.
Where Camphouse acts as controller
This Privacy Notice covers processing for which Camphouse determines the purposes and means, that is, where Camphouse acts as controller. This includes visits to the Site, sales and marketing activities, user account administration, authentication and security, customer support, contract and billing administration, and our own product and website analytics. Some of that processing, such as account and profile data, security event data, support correspondence, contract records and billing information, arises within a customer relationship but is nonetheless carried out by Camphouse as controller.
Where Camphouse acts as processor
When a customer uses the Service, personal data may be contained in the data that the customer and its users upload to, generate in or connect to the platform (“Customer Data”). In relation to personal data within Customer Data, the customer determines the purposes and means of the processing and acts as controller, and Camphouse processes that data on the customer’s behalf as processor. That processing is governed by the applicable customer agreement (the “Customer Agreement”) and the Camphouse Data Processing Agreement (the “DPA”), including the DPA schedules describing the processing, the security measures, the authorised subprocessors and the applicable transfer safeguards. This Privacy Notice does not describe or vary those instructions, and it does not create rights or obligations in addition to the DPA.
If you are an authorised user of a Camphouse customer and your question concerns how your organisation uses the Service, or the personal data your organisation holds in the platform, please contact your organisation in the first instance. We will support our customer in responding.
2. Who we are and how to contact us
Unless we tell you otherwise, the controller for the processing described in this Privacy Notice is:
Camphouse AB
Company registration number 556790-6689
Nybrogatan 11, 114 39 Stockholm, Sweden
Privacy contact: security@camphouse.io
Data Protection Officer: joakim@camphouse.io
Camphouse is part of a group of companies. Camphouse AB is the controller for the processing described in this Privacy Notice unless we tell you that another Camphouse group company is responsible for a specific processing activity. Where another group company acts as controller, we will identify that entity when the relevant personal data is collected or otherwise provide you with its identity and contact details, and this Privacy Notice applies to it in the same way.
You can contact us at any time using the details above with questions about this Privacy Notice or to exercise your rights. You also have the right to lodge a complaint with a supervisory authority, in Sweden Integritetsskyddsmyndigheten (IMY); see section 10.
3. Personal data we collect
We collect and use the following categories of personal data. Not every category applies to every individual; what we hold depends on how you interact with us.
Account and profile information. Your name, email address, profile picture, user role and permissions, login and authentication data, and the preferences and settings you choose in the Service.
Business and contact information. Your name, job title, employer or organisation, business email address and telephone number, and the capacity in which you interact with us (for example authorised user, customer contact, prospect or partner contact).
Communications and support information. The content of your emails, chat conversations, web form submissions and support tickets, including descriptions of issues you report and material you choose to send us, together with our records of the request and how it was handled.
Billing, transaction and contractual information. Billing contact and billing address, order and subscription details, purchase, refund, credit and cancellation information, bank details, invoices and payment records, and the contract documents in which you are named. Payment card details are submitted directly to our third-party payment processor; Camphouse does not access or store payment card details.
Technical, device and usage information. IP address, device and browser type, general location derived from your IP address, log and access data, the pages you access and features you use, links you click, crash and error data, and the time and duration of your access, including your interaction with our emails.
Website and cookie information. Identifiers and information collected through cookies, pixels, tags and similar technologies on the Site, including your consent state, referral source and your interaction with our content and advertising; see section 11 and the Cookie Policy.
Marketing and engagement information. Subscription and consent status, whether you open our emails and which links you click, event and webinar registrations and attendance, and content you download or request.
Information obtained from third parties. Business contact and company information obtained or supplemented through data enrichment and prospecting providers, business partners and publicly available professional or business sources, details you submit through lead generation forms on third-party platforms on which we advertise, and information about the organisation associated with a visit to the Site for account-based marketing purposes; see section 5.
We do not seek to collect special categories of personal data within the meaning of Article 9 GDPR in connection with the activities described in this Privacy Notice, and we ask that you do not provide such data to us.
Providing personal data
Where we ask you to provide personal data, we indicate which information is required. If you do not provide information that we need in order to provide the Service, administer an account, respond to your request or enter into or perform a contract, we may not be able to provide the relevant service or respond to you.
How and why we use personal data
The table below sets out the purposes for which we process personal data as controller, the personal data involved and the legal basis under the GDPR. A single activity may rely on more than one legal basis, and the same personal data may be used for more than one purpose. How long we keep personal data is explained in section 8.
Where we rely on legitimate interests under Article 6(1)(f) GDPR, we state the interest concerned and assess whether it is outweighed by your interests, rights and freedoms; you may object at any time (see section 10). Where we rely on consent under Article 6(1)(a) GDPR, you may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal. Where you are not our contracting party, as is the case for most authorised users and business contacts, we do not rely on Article 6(1)(b) GDPR in relation to you, and rely on legitimate interests or, where required, consent instead.
We obtain personal data:
directly from you, when you register for or use the Service, contact us, submit a form on the Site (including contact, demo request, gated content and newsletter forms), book a meeting or demonstration, subscribe to our communications, register for an event or correspond with us;
from you, when you submit your details through a lead generation form on a third-party platform on which we advertise, in particular LinkedIn;
from your employer or organisation, for example when it purchases the Service and nominates authorised users, or provides contact details of its personnel for contract, support or billing purposes;
automatically, through your use of the Site, our interactive product demonstrations or the Service, using server logs, product telemetry, cookies and similar technologies, including server-side tag management;
from data enrichment and business prospecting providers, and through enrichment carried out within our customer relationship management platform, which supply or supplement business contact and company information;
from our service providers and business partners, in connection with the services they provide to us; and
from publicly available professional and business sources, such as professional networking platforms, company websites and public registers.
Where we obtain personal data about you from a source other than you, we provide the information required by Article 14 GDPR through this Privacy Notice, including by referring to it in our communications with you.
How we share personal data
We disclose personal data only to the extent needed for the purposes described in section 4, to the following categories of recipient:
service providers that help us host, operate, secure, support, analyse, market and administer the Service and our business, including cloud hosting and infrastructure providers (the production environment for the Service is currently primarily hosted using cloud infrastructure provided by Amazon Web Services), support, communications and email delivery providers, analytics providers, marketing, advertising and CRM providers, and billing, payment and accounting providers;
Camphouse group companies, for the purposes described in section 4;
professional advisers, including lawyers, auditors, accountants, insurers and consultants, who are bound by professional or contractual confidentiality obligations;
governmental, regulatory and tax authorities, courts and law enforcement authorities, where we are legally required to disclose personal data, or where disclosure is necessary to establish, exercise or defend legal claims, to protect our rights or property, or to protect the personal safety of users of the Service or of the public; and
parties involved in a corporate transaction, including potential purchasers, investors, lenders and counterparties and their advisers, in connection with a transaction of the kind described in section 4.
Recipients act in different legal capacities. Many of our providers process personal data as processors on our documented instructions and are engaged under a written data processing agreement. Others, including certain advertising and social media platforms, payment providers, professional advisers, and public authorities and courts, act as independent controllers, or in some cases joint controllers, for some or all of their processing and pursue their own purposes on their own legal bases; their own privacy notices apply to that processing.
This section concerns recipients relevant to Camphouse’s processing as controller. Subprocessors engaged in relation to Customer Data are addressed separately in the DPA and its subprocessor schedule, which is made available to customers.
International transfers
Our Site infrastructure is hosted within the EU. Some personal data collected through the Site may nevertheless be processed by service providers or other recipients outside the European Economic Area (EEA), including in the United States. The same applies to personal data processed in connection with our other activities, where a service provider, group company or other recipient is established, or processes personal data, outside the EEA. Where personal data is transferred outside the EEA, we rely on:
an adequacy decision adopted by the European Commission under Article 45 GDPR, where the transfer is covered by such a decision;
appropriate safeguards under Article 46 GDPR, in particular the EU Standard Contractual Clauses, together with supplementary technical, organisational and contractual measures where our assessment of the transfer indicates that they are needed; or
another lawful transfer mechanism under Chapter V GDPR that applies to the transfer.
We determine the applicable mechanism for each transfer. You may contact us at security@camphouse.io for further information about the safeguards applicable to a specific transfer, including how to obtain a copy of the relevant clauses. Transfers of personal data within Customer Data are governed by the DPA.
Retention of personal data
We retain personal data only for as long as necessary for the purposes described in this Privacy Notice.
The retention period depends on the nature of the personal data, the purposes for which it is processed, the duration of our relationship with you or your organisation, and applicable legal, accounting, security and regulatory requirements. We may also retain information for as long as reasonably necessary to establish, exercise or defend legal claims, taking applicable limitation periods into account.
Certain information must be retained for specific periods under applicable law. For example, accounting records are generally retained for seven years after the end of the calendar year in which the relevant financial year ended.
Business contact and marketing data is retained for as long as we have a legitimate business need to retain it, taking into account our relationship with you or your organisation, your engagement with our communications, and any objection or withdrawal of consent. If you unsubscribe or object to direct marketing, we keep a minimal suppression record so that your preference continues to be respected.
When personal data is no longer required, we delete or anonymise it. Where immediate deletion is not possible, for example because information remains temporarily within backup systems, we securely retain the information until deletion is possible.
Retention of personal data contained in Customer Data is governed by the applicable Customer Agreement, the DPA and the customer’s instructions, including the customer’s own use of deletion functionality in the Service.
How we protect personal data
We maintain technical and organisational measures designed to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access, at a level of security appropriate to the risk. They include access control and authentication, encryption, logging and monitoring, secure development practices, backup and recovery, personnel training and confidentiality obligations, and supplier assessment.
Camphouse maintains an information security management system certified to ISO/IEC 27001 and a SOC 2 Type II report based on an independent examination of relevant controls.
Your data protection rights
Subject to the conditions and exceptions in applicable data protection law, you have the following rights in relation to your personal data:
Access: to be told whether we process personal data about you and, if so, to receive a copy of that data and information about the processing.
Rectification: to have inaccurate personal data corrected and incomplete personal data completed.
Erasure: to have personal data deleted, for example where it is no longer needed for the purpose for which it was collected, you have withdrawn your consent, or you have successfully objected to the processing.
Restriction: to have our processing restricted, for example while we verify the accuracy of personal data or consider an objection.
Data portability: to receive personal data you have provided to us in a structured, commonly used and machine-readable format, and to have it transmitted to another controller, where the processing is based on your consent or on a contract with you and is carried out by automated means.
Objection: to object to processing based on our legitimate interests. You have an unconditional right to object at any time to processing for direct marketing purposes, including related profiling; if you object, we will stop that processing.
Withdrawal of consent: to withdraw your consent at any time where the processing relies on consent, including consent to non-essential cookies and to marketing communications. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
Complaint: to lodge a complaint with a supervisory authority.
To exercise your rights, contact us at security@camphouse.io. We reserve the right to limit our assistance with such requests to the extent required by applicable law.
You may unsubscribe from our marketing emails at any time using the unsubscribe link in the message, or by contacting us. You can manage or withdraw your cookie consent at any time through our Cookie Settings; see section 11.
If you consider that our processing of your personal data infringes data protection law, you may lodge a complaint with the Swedish supervisory authority, Integritetsskyddsmyndigheten (IMY), Box 8114, 104 20 Stockholm, Sweden, imy@imy.se, www.imy.se. You may also have the right to lodge a complaint with another competent supervisory authority, in particular the authority in the EU or EEA country where you live or work or where the alleged infringement took place.
Cookies and similar technologies
We use cookies and similar technologies on the Site for necessary website functionality, for preferences, for analytics and for marketing and advertising, including retargeting, campaign measurement, conversion tracking and account-based marketing. Some of these technologies are implemented through server-side tag management on a Camphouse subdomain. Technologies that are not strictly necessary are used only on the basis of your consent, where consent is required by applicable law, which we collect and manage through our consent management platform.
Detailed information about the individual cookies and similar technologies we use, including the provider, purpose, type and storage duration of each, together with the means to give, manage or withdraw your consent, is available in the Camphouse Cookie Policy and Cookie Settings on the Site.
Third-party websites and services
The Site and the Service may contain links to, or integrations with, websites and services operated by third parties. We do not control those websites and services, and their processing of personal data is governed by their own privacy notices. We recommend that you review the relevant notice before providing personal data to a third party.
Changes to this Privacy Notice
We may update this Privacy Notice from time to time, for example to reflect changes in our services, our organisation, applicable law or regulatory guidance. The current version is always published on the Site, with the date of the last update shown at the top of the notice. Where a change materially affects how we process your personal data or the rights available to you, we will provide additional notice by appropriate means, such as by email or a notice in the Service, where required by applicable law or otherwise appropriate.
Last updated: 10 September 2026