Legal

Privacy Policy

What SansaGroup AB collects, why it is processed, how long it is retained, and your rights under GDPR.

Last updated: 2026-08-11

1. Controller and contact

SansaGroup AB, through its Sansavision subdivision, is the data controller for personal data processed through Grasp services, Studio, marketplace and contact channels. Contact: privacy@sansavision.com. We process personal data in accordance with the EU/EEA General Data Protection Regulation (GDPR) and the Swedish Data Protection Act.

2. Data we collect and legal bases

Account and onboarding data: name, email, company, job role, general use case, selected data modalities, preferred way of working and project timing. Optional onboarding answers help us tailor the service, support the account and understand aggregate customer needs; they are not used for third-party advertising. For sellers, we also process payout identity required by Stripe and tax law. The legal bases are contract performance, steps requested before entering a contract and our legitimate interest in operating and improving a business-to-business service.

Transaction data: orders, license keys with terms snapshots, and download audit logs (contract performance and our legitimate interest in enforcing licenses and preventing abuse). Usage data: search queries and page views used to operate and rank the catalog (legitimate interest). Security logs: IP addresses and user agents for abuse prevention (legitimate interest and legal obligation).

Sales inquiry data: name, work email, company, project type, modalities, estimated volume, timeline, project brief, source page and consent timestamp. We use this information to respond, qualify the request, prepare a proposal and maintain a business record. The legal bases are steps requested before entering a contract and our legitimate interest in operating business-to-business sales. Do not include special-category personal data or confidential source files in the form.

Business-development data: for a limited set of relevant organisations, we may record public company information, a work contact, professional role, the public source, our reason for believing the service may be relevant, communications and follow-up tasks. Before using legitimate interest for direct business-to-business outreach, we document the purpose and source, limit the information collected, and consider the contact’s rights. One-to-one outreach may use a message-specific link to record that the recipient chose to visit Grasp and to provide immediate suppression. We do not use tracking pixels to infer opens, and we do not claim to know whether a message was read or discarded. You may object at any time; an objection or do-not-contact instruction is retained so further outreach can be prevented.

Marketing measurement data: with analytics consent, we record page path, referring page, campaign parameters, calls-to-action, coarse country code, device class, visit duration, scroll depth, exit path and a random first-party identifier retained for up to 30 days. We do not store the visitor’s IP address, form content, advertising identifier, keystrokes, fingerprint or cross-site profile in the marketing-events table. This information is used to understand which Grasp material leads to a project conversation.

Dataset content uploaded by sellers is stored for delivery to licensed users and for preview generation. We do not use seller or buyer datasets to train our own models.

3. Processors and international transfers

We use service providers for hosting, security, email delivery and payments. Those providers process information under contractual terms and act as processors or independent controllers as described in their documentation. Where personal data is transferred outside the EU/EEA, we use an applicable lawful transfer mechanism and supplementary safeguards where required. We never receive or store payment-card numbers.

4. Cookies and tracking

Essential cookies keep signed-in users authenticated and remember the privacy choice made in the cookie panel. The consent cookie is named grasp_consent, contains the choice, consent version and decision time, and expires after 180 days. Authentication cookies last only as required for the signed-in session. Essential cookies do not require analytics consent because the requested service and preference control cannot operate reliably without them.

If you actively allow analytics, Grasp records first-party page paths, referring pages, campaign parameters, calls-to-action, coarse country, device class and limited engagement measurements. A random first-party visitor identifier lasts for up to 30 days so navigation can be understood as a journey; it is not an advertising identifier and is not combined with third-party data. Optional analytics remain disabled until consent is granted. There is no third-party advertising, fingerprinting or cross-site tracking. You may withdraw or change the choice at any time using Cookie choices in the site footer; the analytics identifier is removed and optional measurement stops immediately for later activity.

5. What is public

Listings, previews, sample episodes, seller storefronts, and aggregate catalog statistics are public by design — preview-first discovery is the product. Your email, download history, license keys, and payout details are never public.

6. Retention

License keys and their terms snapshots are retained for the life of the license as proof of rights. Transaction records are retained as required by applicable accounting law. Abandoned uploads are deleted after 7 days. Account data is deleted within 30 days of closure, except records we must retain by law. Sales inquiries and related opportunity records are retained by default for 24 months after closure, unless a longer period is required for an active contract, legal obligation or documented dispute. Clearly irrelevant, withdrawn or disqualified prospect records may be removed sooner. A minimal suppression record may be retained after an objection to ensure the person is not contacted again. Marketing events are retained for aggregate measurement and reviewed for deletion on a shorter operational schedule.

7. Your rights

Under the GDPR you have the rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY). To exercise your rights, contact privacy@sansavision.com. Rights are subject to our legal retention obligations, including license-key snapshots that constitute your own proof of rights.