LandingWeb

Privacy policy

How LandingWeb processes personal data for the marketing site, inquiries, and related studio operations. Structure for Sweden / GDPR — have counsel review before treating as production-final.

Last updated: 7 August 2026

Who is responsible

LandingWeb (“we”, “us”) is the controller for personal data processed through the public website at landingweb.app and related studio operations described here.

Questions: [email protected].

Email hello@landingweb.app.

What this notice covers

This notice covers the public marketing site, contact and get-started inquiry forms, and how we handle related communications.

Categories of personal data

Depending on how you use the site, we may process:

  • Identity and contact data you submit (name, email, phone, company)
  • Project details and messages from inquiry or wizard forms
  • Technical data needed to run the site (for example remembering your cookie choice, and a short-lived helper so the same page is not counted twice in one visit)
  • Coarse first-party analytics events (page path and referrer hostname) without storing your raw IP address on those events
  • Measurement data via Google Analytics if you accept Analytics cookies
  • Billing-related data when Stripe invoicing is enabled for your engagement

Purposes and legal bases

We process data to:

  • Respond to inquiries and prepare proposals (legitimate interests / steps prior to a contract)
  • Operate and secure the website, including bot protection when Turnstile is configured (legitimate interests)
  • Understand marketing-site traffic with first-party analytics that do not store raw IP on Analytics rows (legitimate interests)
  • Enable Google Analytics measurement cookies only with your consent (consent)
  • Process invoices when Stripe billing is enabled (contract / legal obligation as applicable)

Cookies and similar technologies

The marketing site uses a first-party consent panel. Strictly necessary storage keeps the site working (including remembering your cookie choice). The Google tag may load with Consent Mode denied by default; Analytics cookies and storage are enabled only if you accept them. We do not use this banner for advertising or remarketing tags.

Details and a full table are on the Cookies page. You can change your marketing Analytics choice anytime via Cookie settings in the footer.

Processors and recipients

We use service providers (processors) where needed. When a feature is not enabled, that processor is not used for your data.

  • Hosting provider for the application and database
  • Cloudflare (edge delivery, security, and — when configured — Turnstile bot protection and email obfuscation)
  • Google Analytics — measurement cookies only after you grant Analytics consent on the marketing site
  • Email delivery (SMTP or Mailgun) when inquiry or notification email is enabled
  • Stripe when billing or client invoices are enabled for a project

Retention

Inquiry and project records are kept while they are needed to handle your request and run the engagement, then for a limited period for business records and dispute handling, unless a longer period is required by law.

First-party analytics events are retained for operational reporting and then removed or aggregated according to our internal retention practice.

Your cookie choice stays in this browser until you clear site data or we ask again after a material update to the cookie panel.

Your rights

Under the GDPR you may have the right to access, rectify, erase, restrict, or object to certain processing, and to data portability where applicable. Where processing is based on consent, you may withdraw consent without affecting prior lawful processing.

To exercise rights, email [email protected]. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or another competent supervisory authority.

International transfers

Some processors (for example Google Analytics when consented, or email/hosting providers) may process data outside the EEA. Where that happens, we rely on appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision, as applicable to that provider.

Security

We apply technical and organisational measures appropriate to a studio of this size, including HTTPS and rate limiting on public endpoints. No method of transmission or storage is perfectly secure.

Changes

We may update this notice. The “Last updated” date at the top of the page will change when we do. Material cookie-panel changes may also bump the consent version so you are asked again.

Back to LandingWeb

Privacy policy · LandingWeb