Privacy Policy
Last updated: 7 October 2026
This policy explains how Cooach Group ("Cooach", "we", "us") processes personal data when you visit coora.dev, use the Cooach OS platform and its assistant Coora, or are in contact with us. We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law in Sweden and Spain.
1. Data controller
Cooach AB (Sweden) is the data controller for processing described in this policy, together with the Cooach group companies that provide services to you. Contact: privacy@coora.dev.
When a customer company uses Cooach OS to process data about its own employees, suppliers or customers (for example bookkeeping, payroll or HR data), the customer company is the data controller and Cooach acts as data processor under a data processing agreement (DPA).
2. Personal data we process
- Identity and contact data: name, e-mail, phone, title, company and role.
- Identification data: personal identity number and verification result when you sign in with BankID or another e-ID.
- Company and registry data: roles, signatory rights, ownership and beneficial owners obtained from public registers and data providers such as Roaring.
- Financial data: accounting entries, invoices, bank accounts, balances and transactions that you or your company connect to the platform.
- HR and payroll data processed on behalf of customer companies: employment, salary, absence, tax and cost-centre allocation.
- Content you provide: documents, agreements, messages and questions to Coora.
- Technical data: IP address, device and browser information, log data and cookies.
3. Purposes and legal basis
- To provide and administer the platform and your account — performance of contract (Art. 6.1 b).
- To verify identity and authority to represent a company (KYC, signatory checks) — legal obligation and legitimate interest (Art. 6.1 c and f).
- To retrieve bank balances and transactions for liquidity follow-up, and to verify supplier bank accounts against fraud — performance of contract and legitimate interest; account access always requires your explicit consent with your bank (PSD2).
- To comply with bookkeeping, tax and anti-money-laundering rules — legal obligation (Art. 6.1 c).
- To improve security, prevent misuse and develop our services — legitimate interest (Art. 6.1 f).
- To send information and marketing about our services — legitimate interest or consent, which you can withdraw at any time.
4. Coora and automated analysis
Coora uses AI models to suggest postings, summarise documents, review agreements and prepare reports. Suggestions are always reviewed and approved by a person; Coora does not take decisions with legal or similarly significant effects for you. Customer data is not used to train external AI models.
5. Sources
We collect data directly from you, from the company you represent, from e-ID providers (BankID), from public registers and data providers (e.g. Roaring, Bolagsverket), from banks via open-banking connections you approve, and from accounting systems you connect (e.g. Fortnox).
6. Recipients and processors
We share data only when needed: with hosting and cloud providers, e-ID and registry providers, open-banking providers, e-signature providers (e.g. Scrive), accounting system providers, AI providers and professional advisers. All processors are bound by data processing agreements. Authorities receive data only when required by law.
7. Transfers outside the EU/EEA
Data is primarily stored within the EU/EEA. If data is transferred outside the EU/EEA, we ensure an adequate level of protection, for example through an adequacy decision or the EU Standard Contractual Clauses.
8. Retention
- Account data: for as long as the account is active and up to 24 months thereafter.
- Accounting material: 7 years (Sweden) or 6 years (Spain) according to bookkeeping law.
- KYC and anti-money-laundering data: 5 years after the business relationship ends.
- Log data: normally up to 12 months.
9. Security
We protect data with encryption in transit and at rest, strict access control per company and role, audit logs of access and changes, and regular security reviews. No view shows data from a company other than the one you are authorised for.
10. Your rights
You have the right to access, rectification, erasure, restriction, data portability and to object to processing based on legitimate interest, and to withdraw consent at any time. Contact privacy@coora.dev. If the data is processed on behalf of your employer or another customer company, we forward your request to them.
You can lodge a complaint with the Swedish Authority for Privacy Protection (IMY, imy.se) or the Spanish Data Protection Agency (AEPD, aepd.es).
11. Cookies
We use necessary cookies to make sign-in and the platform work, and — only with your consent — analytics cookies to improve the website.
12. Changes
We may update this policy. Material changes are announced on the website or in the platform. The current version is always available at coora.dev/privacy.