ExploreWorldAI and the GDPR

ExploreWorldAI is an EU regulatory intelligence platform for companies, not a travel service.

Valkiv Ventures AB, Kungsgatan 8, 111 43 Stockholm publishes this page so a customer, an auditor or a board can see which personal data the platform handles, on what legal basis, how long it is kept, where it goes, and where a complaint is made. Every point describes how the platform works today.

Reviewed: 2026-08-08

01 Your rights

Which rights do you have over your personal data?

You can ask what is held about you, correct it, have it deleted, restrict its use, take it with you, and object to processing based on legitimate interest. A request is answered within one month and is handled by a person, never by an automated reply.

  • Access: a copy of the personal data held about you, and the purpose
  • Rectification: an incorrect field is corrected on request
  • Erasure: data is deleted unless accounting law requires the record
  • Restriction: processing is paused while a dispute is examined
  • Portability: data you provided is delivered in a machine-readable file
  • Objection: reading of a public page stops and the cached page is deleted immediately
  • Withdrawal of consent, where consent is the basis, without affecting past processing
  • The right to complain to a supervisory authority, without going through us first
What this means for you
You do not need a lawyer to exercise a right. Send the request at /gdpr-request and a person answers within one month.
Articles
Articles 15 to 22

02 Legal basis

On what legal basis is each activity carried out?

Every activity has one named basis, and the basis is fixed per activity rather than chosen per case. Nothing runs on consent that a contract or a legitimate interest already carries.

  • Account, workspace, payments and document reading: performance of a contract
  • Reading a public page on the address you submit: legitimate interest in assessing a public business presence
  • Support conversations: legitimate interest in running and improving support
  • Invoices and accounting records: legal obligation under Swedish accounting law
  • Cookies beyond what the site needs to work: your consent, withdrawable at any time
  • Candidate matching: the customer's own basis as employer or agency, on their instruction
  • The balancing test for legitimate interest is documented and available on request
What this means for you
You can map each activity to a basis in a procurement review without asking us for a separate document.
Articles
Article 6

03 Data categories

Which categories of personal data are handled?

The platform handles account details, publicly published business facts, the text of support questions, and billing references. No special categories under article 9 are collected, and no card data reaches the platform.

  • Account: email address, name if your sign-in provider supplies it, account identifier
  • Anonymous route: a generated identifier and a hashed recovery code, no email and no name
  • Public reading: name, role, headline and publicly stated merits on the address submitted, masked before the answer leaves the engine
  • Support: the question text, language and outcome
  • Billing: invoice details, credit balance and transaction references, no card numbers
  • No health data, no political opinions, no biometric identification, no data on children
  • The full record of processing activities is published in the data processing agreement
What this means for you
You can see the complete list before you sign, and each row states its retention period and recipients.
Articles
Articles 9 and 30

04 Retention

How long is personal data kept?

Retention is set per activity and is short by design. A fetched public page is the shortest-lived record in the platform.

  • A fetched public page is held for at most 15 minutes, then deleted
  • Support conversations are masked after 7 days and deleted after 30 days
  • Account and workspace data is kept while the subscription is active, and deleted on request
  • Accounting records are kept for the period Swedish accounting law requires
  • Submitted candidate text is not stored, only the fields the customer submits for the match
  • Operational logs hold cost, model and decision metadata, not personal data
What this means for you
Nothing accumulates quietly. If you stop using the service, the data path ends with it.
Articles
Article 5(1)(e)

05 Transfers

Is personal data transferred outside the EU?

Processing takes place in the EU. Where a sub-processor operates outside the EU, the transfer runs on standard contractual clauses and the sub-processor is named on the sub-processor list.

  • Hosting, database, storage and functions run in EU regions
  • Payments, sign-in, model calls and public result summaries involve named sub-processors
  • Transfers outside the EU run on standard contractual clauses with supplementary measures
  • The sub-processor list is public and you are informed before a new one is engaged
  • You may object to a new sub-processor
  • Your data is not used to train external models
What this means for you
You can answer the transfer question in a supplier assessment from a published page instead of a questionnaire.
Articles
Articles 44 to 49

06 Impact assessment

Is a data protection impact assessment required?

A DPIA is required where processing is likely to result in a high risk to individuals. The platform is built to stay below that line: no profiling, no systematic monitoring, no automated decision with legal effect.

  • No profiling of individuals and no scoring of people as people
  • No systematic monitoring of a publicly accessible area
  • No special categories and no large-scale processing of sensitive data
  • No automated decision with legal or similarly significant effect, a human always decides
  • A screening assessment is documented per module and reviewed when a module changes
  • Where a customer's own use raises the risk, we support their DPIA with the facts on this page
What this means for you
For standard use of the platform no DPIA is triggered on our side, and your own assessment can cite the rows above.
Articles
Article 35

07 Breach reporting

What happens if there is a personal data breach?

A suspected breach is investigated immediately, contained, and reported. As processor we notify the customer without undue delay; as controller we notify the supervisory authority within 72 hours where the breach is likely to be a risk.

  • Notification to the supervisory authority within 72 hours where reporting is required
  • Notification to the customer without undue delay when we act as processor
  • Notification to affected individuals where the breach is a high risk to them
  • An internal register of breaches, with cause, effect and corrective action
  • A single reporting route: hello@exploreworldai.com, monitored on working days
  • Access is limited to personnel bound by confidentiality, with audit trails per action
What this means for you
You get the information you need for your own notification, in time to meet your own deadline.
Articles
Articles 33 and 34

08 Supervisory authorities

Which supervisory authority oversees the platform?

The lead supervisory authority is the Swedish Authority for Privacy Protection, IMY, since the controller is established in Sweden. You may also complain to the authority in your own country of residence.

  • Lead authority: Integritetsskyddsmyndigheten, IMY, Stockholm, Sweden
  • You may complain to the authority where you live or work, or where the issue occurred
  • Norway: Datatilsynet. Denmark: Datatilsynet. Finland: Tietosuojavaltuutetun toimisto
  • A complaint to an authority does not require a complaint to us first
  • We answer an authority's questions and provide the information article 28 requires
  • No data protection officer is appointed, because the criteria in article 37 are not met
What this means for you
You have a route that does not depend on us, and we do not stand between you and the regulator.
Articles
Articles 51 to 59 and article 77

09 Penalties

What penalties apply under the GDPR?

The regulation sets two levels of administrative fine, and an authority may also order processing to stop. The levels below are the regulation's own figures, not an estimate.

  • Lower level: up to 10 million euro, or 2 per cent of global annual turnover, whichever is higher
  • Upper level: up to 20 million euro, or 4 per cent of global annual turnover, whichever is higher
  • An authority may issue a warning, a reprimand, an order, or a ban on processing
  • An individual may claim compensation for material or non-material damage
  • A processor is liable in its own right for duties the regulation places on processors
  • Our contractual liability is set out in the Terms of Use and the data processing agreement
What this means for you
The exposure sits with whoever controls the purpose. Our published record lets you show your own supervisor what you bought.
Articles
Articles 82 and 83

ExploreWorldAI and the GDPR

ExploreWorldAI and the GDPR
ExploreWorldAI and the GDPRWhat this means for youArticles
01 Your rightsYou do not need a lawyer to exercise a right. Send the request at /gdpr-request and a person answers within one month.Articles 15 to 22
02 Legal basisYou can map each activity to a basis in a procurement review without asking us for a separate document.Article 6
03 Data categoriesYou can see the complete list before you sign, and each row states its retention period and recipients.Articles 9 and 30
04 RetentionNothing accumulates quietly. If you stop using the service, the data path ends with it.Article 5(1)(e)
05 TransfersYou can answer the transfer question in a supplier assessment from a published page instead of a questionnaire.Articles 44 to 49
06 Impact assessmentFor standard use of the platform no DPIA is triggered on our side, and your own assessment can cite the rows above.Article 35
07 Breach reportingYou get the information you need for your own notification, in time to meet your own deadline.Articles 33 and 34
08 Supervisory authoritiesYou have a route that does not depend on us, and we do not stand between you and the regulator.Articles 51 to 59 and article 77
09 PenaltiesThe exposure sits with whoever controls the purpose. Our published record lets you show your own supervisor what you bought.Articles 82 and 83

Definitions

The words used above, in the meaning the regulation gives them. Same wording as the Privacy Policy and the data processing agreement.

Definitions
DefinitionsWhat this means for you
Personal dataAny information relating to an identified or identifiable living person, including an identifier such as a name, an email address or an online identifier.
ProcessingAny operation performed on personal data: collection, reading, storage, use, disclosure, masking or deletion.
ControllerThe party that decides why and how personal data is processed. For accounts, support and billing this is Valkiv Ventures AB. For a customer's own runs it is the customer.
ProcessorThe party that processes personal data on the controller's documented instructions. ExploreWorldAI acts as processor when a customer runs a report or submits a document.
Legal basisThe ground in article 6 that makes a processing activity lawful: contract, legal obligation, legitimate interest or consent.
Legitimate interestA lawful ground where the interest in processing is weighed against the rights of the individual, and the balancing test is documented.
Special categoriesData on health, ethnicity, political opinions, religion, trade union membership, sex life, genetics or biometrics. The platform does not collect these.
Data protection impact assessmentA documented assessment required when processing is likely to result in a high risk to individuals, under article 35.
Personal data breachA security incident leading to accidental or unlawful destruction, loss, alteration, disclosure of, or access to personal data.
Sub-processorA third party engaged by the processor to carry out part of the processing, listed publicly and bound by the same duties.
Standard contractual clausesContract terms approved by the European Commission that make a transfer of personal data outside the EU lawful.
Supervisory authorityThe public authority that monitors the application of the regulation. The lead authority here is IMY in Sweden.
Personal data
Any information relating to an identified or identifiable living person, including an identifier such as a name, an email address or an online identifier.
Processing
Any operation performed on personal data: collection, reading, storage, use, disclosure, masking or deletion.
Controller
The party that decides why and how personal data is processed. For accounts, support and billing this is Valkiv Ventures AB. For a customer's own runs it is the customer.
Processor
The party that processes personal data on the controller's documented instructions. ExploreWorldAI acts as processor when a customer runs a report or submits a document.
Legal basis
The ground in article 6 that makes a processing activity lawful: contract, legal obligation, legitimate interest or consent.
Legitimate interest
A lawful ground where the interest in processing is weighed against the rights of the individual, and the balancing test is documented.
Special categories
Data on health, ethnicity, political opinions, religion, trade union membership, sex life, genetics or biometrics. The platform does not collect these.
Data protection impact assessment
A documented assessment required when processing is likely to result in a high risk to individuals, under article 35.
Personal data breach
A security incident leading to accidental or unlawful destruction, loss, alteration, disclosure of, or access to personal data.
Sub-processor
A third party engaged by the processor to carry out part of the processing, listed publicly and bound by the same duties.
Standard contractual clauses
Contract terms approved by the European Commission that make a transfer of personal data outside the EU lawful.
Supervisory authority
The public authority that monitors the application of the regulation. The lead authority here is IMY in Sweden.

Where to send a request

One route in, one person answering. A request is answered within one month, and we tell you if the answer needs longer.

Controller
Valkiv Ventures AB, reg. no. 556995-1311
Address
Kungsgatan 8, 111 43 Stockholm, Sweden
Email
hello@exploreworldai.com
VAT
SE556995131101
Supervisory authority
Integritetsskyddsmyndigheten (IMY), Sweden
Regulation
Regulation (EU) 2016/679

Binding texts

ExploreWorldAI is operated by Valkiv Ventures AB (Reg. no. 556995-1311), Kungsgatan 8, 111 43 Stockholm, Sweden. EU-hosted, with data processing assessed against the GDPR. Contact: hello@exploreworldai.com.

Machine-readable summaries for AI agents: /llms.txt and /llms-full.txt.