LandingWeb
Privacy policy
How LandingWeb processes personal data for the marketing site, inquiries, and related studio operations. Structure for Sweden / GDPR — have counsel review before treating as production-final.
Last updated: 7 August 2026
Who is responsible
LandingWeb (“we”, “us”) is the controller for personal data processed through the public website at landingweb.app and related studio operations described here.
Questions: [email protected].
Email hello@landingweb.app.
What this notice covers
This notice covers the public marketing site, contact and get-started inquiry forms, and how we handle related communications.
Categories of personal data
Depending on how you use the site, we may process:
- Identity and contact data you submit (name, email, phone, company)
- Project details and messages from inquiry or wizard forms
- Technical data needed to run the site (for example remembering your cookie choice, and a short-lived helper so the same page is not counted twice in one visit)
- Coarse first-party analytics events (page path and referrer hostname) without storing your raw IP address on those events
- Measurement data via Google Analytics if you accept Analytics cookies
- Billing-related data when Stripe invoicing is enabled for your engagement
Purposes and legal bases
We process data to:
- Respond to inquiries and prepare proposals (legitimate interests / steps prior to a contract)
- Operate and secure the website, including bot protection when Turnstile is configured (legitimate interests)
- Understand marketing-site traffic with first-party analytics that do not store raw IP on Analytics rows (legitimate interests)
- Enable Google Analytics measurement cookies only with your consent (consent)
- Process invoices when Stripe billing is enabled (contract / legal obligation as applicable)
Processors and recipients
We use service providers (processors) where needed. When a feature is not enabled, that processor is not used for your data.
- Hosting provider for the application and database
- Cloudflare (edge delivery, security, and — when configured — Turnstile bot protection and email obfuscation)
- Google Analytics — measurement cookies only after you grant Analytics consent on the marketing site
- Email delivery (SMTP or Mailgun) when inquiry or notification email is enabled
- Stripe when billing or client invoices are enabled for a project
Retention
Inquiry and project records are kept while they are needed to handle your request and run the engagement, then for a limited period for business records and dispute handling, unless a longer period is required by law.
First-party analytics events are retained for operational reporting and then removed or aggregated according to our internal retention practice.
Your cookie choice stays in this browser until you clear site data or we ask again after a material update to the cookie panel.
Your rights
Under the GDPR you may have the right to access, rectify, erase, restrict, or object to certain processing, and to data portability where applicable. Where processing is based on consent, you may withdraw consent without affecting prior lawful processing.
To exercise rights, email [email protected]. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.
International transfers
Some processors (for example Google Analytics when consented, or email/hosting providers) may process data outside the EEA. Where that happens, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision, as applicable to that provider.
Security
We apply technical and organisational measures appropriate to a studio of this size, including HTTPS and rate limiting on public endpoints. No method of transmission or storage is perfectly secure.
Changes
We may update this notice. The “Last updated” date at the top of the page will change when we do. Material cookie-panel changes may also bump the consent version so you are asked again.