ExploreWorldAI and the GDPR
ExploreWorldAI is an EU regulatory intelligence platform for companies, not a travel service.
Valkiv Ventures AB, Kungsgatan 8, 111 43 Stockholm publishes this page so a customer, an auditor or a board can see which personal data the platform handles, on what legal basis, how long it is kept, where it goes, and where a complaint is made. Every point describes how the platform works today.
Reviewed: 2026-08-08
01 Your rights
Which rights do you have over your personal data?
You can ask what is held about you, correct it, have it deleted, restrict its use, take it with you, and object to processing based on legitimate interest. A request is answered within one month and is handled by a person, never by an automated reply.
- Access: a copy of the personal data held about you, and the purpose
- Rectification: an incorrect field is corrected on request
- Erasure: data is deleted unless accounting law requires the record
- Restriction: processing is paused while a dispute is examined
- Portability: data you provided is delivered in a machine-readable file
- Objection: reading of a public page stops and the cached page is deleted immediately
- Withdrawal of consent, where consent is the basis, without affecting past processing
- The right to complain to a supervisory authority, without going through us first
- What this means for you
- You do not need a lawyer to exercise a right. Send the request at /gdpr-request and a person answers within one month.
- Articles
- Articles 15 to 22
02 Legal basis
On what legal basis is each activity carried out?
Every activity has one named basis, and the basis is fixed per activity rather than chosen per case. Nothing runs on consent that a contract or a legitimate interest already carries.
- Account, workspace, payments and document reading: performance of a contract
- Reading a public page on the address you submit: legitimate interest in assessing a public business presence
- Support conversations: legitimate interest in running and improving support
- Invoices and accounting records: legal obligation under Swedish accounting law
- Cookies beyond what the site needs to work: your consent, withdrawable at any time
- Candidate matching: the customer's own basis as employer or agency, on their instruction
- The balancing test for legitimate interest is documented and available on request
- What this means for you
- You can map each activity to a basis in a procurement review without asking us for a separate document.
- Articles
- Article 6
03 Data categories
Which categories of personal data are handled?
The platform handles account details, publicly published business facts, the text of support questions, and billing references. No special categories under article 9 are collected, and no card data reaches the platform.
- Account: email address, name if your sign-in provider supplies it, account identifier
- Anonymous route: a generated identifier and a hashed recovery code, no email and no name
- Public reading: name, role, headline and publicly stated merits on the address submitted, masked before the answer leaves the engine
- Support: the question text, language and outcome
- Billing: invoice details, credit balance and transaction references, no card numbers
- No health data, no political opinions, no biometric identification, no data on children
- The full record of processing activities is published in the data processing agreement
- What this means for you
- You can see the complete list before you sign, and each row states its retention period and recipients.
- Articles
- Articles 9 and 30
04 Retention
How long is personal data kept?
Retention is set per activity and is short by design. A fetched public page is the shortest-lived record in the platform.
- A fetched public page is held for at most 15 minutes, then deleted
- Support conversations are masked after 7 days and deleted after 30 days
- Account and workspace data is kept while the subscription is active, and deleted on request
- Accounting records are kept for the period Swedish accounting law requires
- Submitted candidate text is not stored, only the fields the customer submits for the match
- Operational logs hold cost, model and decision metadata, not personal data
- What this means for you
- Nothing accumulates quietly. If you stop using the service, the data path ends with it.
- Articles
- Article 5(1)(e)
05 Transfers
Is personal data transferred outside the EU?
Processing takes place in the EU. Where a sub-processor operates outside the EU, the transfer runs on standard contractual clauses and the sub-processor is named on the sub-processor list.
- Hosting, database, storage and functions run in EU regions
- Payments, sign-in, model calls and public result summaries involve named sub-processors
- Transfers outside the EU run on standard contractual clauses with supplementary measures
- The sub-processor list is public and you are informed before a new one is engaged
- You may object to a new sub-processor
- Your data is not used to train external models
- What this means for you
- You can answer the transfer question in a supplier assessment from a published page instead of a questionnaire.
- Articles
- Articles 44 to 49
06 Impact assessment
Is a data protection impact assessment required?
A DPIA is required where processing is likely to result in a high risk to individuals. The platform is built to stay below that line: no profiling, no systematic monitoring, no automated decision with legal effect.
- No profiling of individuals and no scoring of people as people
- No systematic monitoring of a publicly accessible area
- No special categories and no large-scale processing of sensitive data
- No automated decision with legal or similarly significant effect, a human always decides
- A screening assessment is documented per module and reviewed when a module changes
- Where a customer's own use raises the risk, we support their DPIA with the facts on this page
- What this means for you
- For standard use of the platform no DPIA is triggered on our side, and your own assessment can cite the rows above.
- Articles
- Article 35
07 Breach reporting
What happens if there is a personal data breach?
A suspected breach is investigated immediately, contained, and reported. As processor we notify the customer without undue delay; as controller we notify the supervisory authority within 72 hours where the breach is likely to be a risk.
- Notification to the supervisory authority within 72 hours where reporting is required
- Notification to the customer without undue delay when we act as processor
- Notification to affected individuals where the breach is a high risk to them
- An internal register of breaches, with cause, effect and corrective action
- A single reporting route: hello@exploreworldai.com, monitored on working days
- Access is limited to personnel bound by confidentiality, with audit trails per action
- What this means for you
- You get the information you need for your own notification, in time to meet your own deadline.
- Articles
- Articles 33 and 34
08 Supervisory authorities
Which supervisory authority oversees the platform?
The lead supervisory authority is the Swedish Authority for Privacy Protection, IMY, since the controller is established in Sweden. You may also complain to the authority in your own country of residence.
- Lead authority: Integritetsskyddsmyndigheten, IMY, Stockholm, Sweden
- You may complain to the authority where you live or work, or where the issue occurred
- Norway: Datatilsynet. Denmark: Datatilsynet. Finland: Tietosuojavaltuutetun toimisto
- A complaint to an authority does not require a complaint to us first
- We answer an authority's questions and provide the information article 28 requires
- No data protection officer is appointed, because the criteria in article 37 are not met
- What this means for you
- You have a route that does not depend on us, and we do not stand between you and the regulator.
- Articles
- Articles 51 to 59 and article 77
09 Penalties
What penalties apply under the GDPR?
The regulation sets two levels of administrative fine, and an authority may also order processing to stop. The levels below are the regulation's own figures, not an estimate.
- Lower level: up to 10 million euro, or 2 per cent of global annual turnover, whichever is higher
- Upper level: up to 20 million euro, or 4 per cent of global annual turnover, whichever is higher
- An authority may issue a warning, a reprimand, an order, or a ban on processing
- An individual may claim compensation for material or non-material damage
- A processor is liable in its own right for duties the regulation places on processors
- Our contractual liability is set out in the Terms of Use and the data processing agreement
- What this means for you
- The exposure sits with whoever controls the purpose. Our published record lets you show your own supervisor what you bought.
- Articles
- Articles 82 and 83
ExploreWorldAI and the GDPR
| ExploreWorldAI and the GDPR | What this means for you | Articles |
|---|---|---|
| 01 Your rights | You do not need a lawyer to exercise a right. Send the request at /gdpr-request and a person answers within one month. | Articles 15 to 22 |
| 02 Legal basis | You can map each activity to a basis in a procurement review without asking us for a separate document. | Article 6 |
| 03 Data categories | You can see the complete list before you sign, and each row states its retention period and recipients. | Articles 9 and 30 |
| 04 Retention | Nothing accumulates quietly. If you stop using the service, the data path ends with it. | Article 5(1)(e) |
| 05 Transfers | You can answer the transfer question in a supplier assessment from a published page instead of a questionnaire. | Articles 44 to 49 |
| 06 Impact assessment | For standard use of the platform no DPIA is triggered on our side, and your own assessment can cite the rows above. | Article 35 |
| 07 Breach reporting | You get the information you need for your own notification, in time to meet your own deadline. | Articles 33 and 34 |
| 08 Supervisory authorities | You have a route that does not depend on us, and we do not stand between you and the regulator. | Articles 51 to 59 and article 77 |
| 09 Penalties | The exposure sits with whoever controls the purpose. Our published record lets you show your own supervisor what you bought. | Articles 82 and 83 |
Definitions
The words used above, in the meaning the regulation gives them. Same wording as the Privacy Policy and the data processing agreement.
| Definitions | What this means for you |
|---|---|
| Personal data | Any information relating to an identified or identifiable living person, including an identifier such as a name, an email address or an online identifier. |
| Processing | Any operation performed on personal data: collection, reading, storage, use, disclosure, masking or deletion. |
| Controller | The party that decides why and how personal data is processed. For accounts, support and billing this is Valkiv Ventures AB. For a customer's own runs it is the customer. |
| Processor | The party that processes personal data on the controller's documented instructions. ExploreWorldAI acts as processor when a customer runs a report or submits a document. |
| Legal basis | The ground in article 6 that makes a processing activity lawful: contract, legal obligation, legitimate interest or consent. |
| Legitimate interest | A lawful ground where the interest in processing is weighed against the rights of the individual, and the balancing test is documented. |
| Special categories | Data on health, ethnicity, political opinions, religion, trade union membership, sex life, genetics or biometrics. The platform does not collect these. |
| Data protection impact assessment | A documented assessment required when processing is likely to result in a high risk to individuals, under article 35. |
| Personal data breach | A security incident leading to accidental or unlawful destruction, loss, alteration, disclosure of, or access to personal data. |
| Sub-processor | A third party engaged by the processor to carry out part of the processing, listed publicly and bound by the same duties. |
| Standard contractual clauses | Contract terms approved by the European Commission that make a transfer of personal data outside the EU lawful. |
| Supervisory authority | The public authority that monitors the application of the regulation. The lead authority here is IMY in Sweden. |
- Personal data
- Any information relating to an identified or identifiable living person, including an identifier such as a name, an email address or an online identifier.
- Processing
- Any operation performed on personal data: collection, reading, storage, use, disclosure, masking or deletion.
- Controller
- The party that decides why and how personal data is processed. For accounts, support and billing this is Valkiv Ventures AB. For a customer's own runs it is the customer.
- Processor
- The party that processes personal data on the controller's documented instructions. ExploreWorldAI acts as processor when a customer runs a report or submits a document.
- Legal basis
- The ground in article 6 that makes a processing activity lawful: contract, legal obligation, legitimate interest or consent.
- Legitimate interest
- A lawful ground where the interest in processing is weighed against the rights of the individual, and the balancing test is documented.
- Special categories
- Data on health, ethnicity, political opinions, religion, trade union membership, sex life, genetics or biometrics. The platform does not collect these.
- Data protection impact assessment
- A documented assessment required when processing is likely to result in a high risk to individuals, under article 35.
- Personal data breach
- A security incident leading to accidental or unlawful destruction, loss, alteration, disclosure of, or access to personal data.
- Sub-processor
- A third party engaged by the processor to carry out part of the processing, listed publicly and bound by the same duties.
- Standard contractual clauses
- Contract terms approved by the European Commission that make a transfer of personal data outside the EU lawful.
- Supervisory authority
- The public authority that monitors the application of the regulation. The lead authority here is IMY in Sweden.
Where to send a request
One route in, one person answering. A request is answered within one month, and we tell you if the answer needs longer.
- Controller
- Valkiv Ventures AB, reg. no. 556995-1311
- Address
- Kungsgatan 8, 111 43 Stockholm, Sweden
- hello@exploreworldai.com
- VAT
- SE556995131101
- Supervisory authority
- Integritetsskyddsmyndigheten (IMY), Sweden
- Regulation
- Regulation (EU) 2016/679
Binding texts
ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.
Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.