Privacy notice
Last updated 11 September 2026
This site sets no cookies and stores nothing on your device. It does record that a visit happened. This page says exactly what that means, why we do it, how long we keep it, and how to stop it.
Who is responsible
Automatik IT Scandinavia AB (org.nr 556805-7540, VAT SE556805754001) is the data controller for this website.
Sky City, Arlanda Airport, Box 150 98, SE-190 45 Stockholm-Arlanda, Sweden
info@automatikit.com · +46 735 00 00 23
We have not appointed a data protection officer; we are not required to.
No cookies, and nothing stored on your device
Our measurement uses no cookies, no local storage, no session storage and no device fingerprinting. It never reads anything from your browser's storage and never writes anything to it.
That is why you are not being asked to accept anything. The consent rule people know as the "cookie law" (Article 5(3) of the ePrivacy Directive, implemented in Sweden in the Electronic Communications Act) applies to storing information on, or reading information from, your equipment. We do neither, so there is nothing to consent to, and a banner would ask you to agree to something we do not do. The rest of this page covers what we do instead, which is still governed by the GDPR.
What is recorded when you visit
When you open a page, your browser sends us the following:
- The page you opened
- Path and query string. Parameters commonly used for secrets or addresses
(
email,token,passwordand similar) are removed before the request leaves your browser, and the fragment after#is never sent. - Where you came from
- The origin of the referring site only. A visit from a Google search records
https://www.google.comand never what you searched for. Moving between pages on this site records nothing. - Campaign tags
- The
utm_source,utm_mediumandutm_campaignvalues, if the link you followed carried them. - Your browser's language
- The primary tag only: "sv", not "sv-SE".
- Approximate location
- Country and city, looked up from your IP address against a local database (MaxMind GeoLite2). The lookup happens on our own server; your IP address is not sent anywhere for this.
- Browser, operating system and device type
- Read from the user-agent string your browser sends with every request, for example "Firefox, Windows, Desktop".
- The date and time
- In UTC.
- A short-lived counting value
- So that one person reading five pages is counted once rather than five times. It is produced by shortening your IP address so that what remains identifies your network rather than your device, combining that with this site's own secret key and today's date, and putting the result through a keyed hash (HMAC-SHA256). The value we store is not your IP address and does not contain it, and without the secret key it cannot be worked back to one. Because the date is part of it, a different value replaces it every night, so we cannot recognise you tomorrow as the same person who visited today. It is not a cookie and not an account, and it differs from one site to the next, so it cannot follow you anywhere else.
Your IP address is not stored
Your IP address necessarily reaches our server, because that is how the internet works. It is used to derive the country, the city and the daily key described above, and it is then discarded. It is not written to our analytics records.
What we do not do
- We do not track you across other websites. We have no way to.
- We do not fingerprint your device.
- We do not run advertising or share anything with advertising networks.
- We do not sell or rent personal data to anyone.
- We make no automated decisions about you that produce legal or similarly significant effects.
The notification email
Once a day, our system sends one internal email to info@automatikit.com. It names the site and the date and points at the dashboard. It contains nothing about you: not the page you opened, not your location, not your browser, not the time you arrived, and not even how many people came. It does not say whether anyone visited at all, and it is worded identically every day, so its arrival tells a reader nothing either. It is a prompt to go and look at the figures, which stay in our analytics dashboard behind a login, covered by everything else on this page.
Why we do this, and on what basis
To understand whether this site works and who it reaches, and to know when there is new data to review.
The legal basis is our legitimate interest under Article 6(1)(f) GDPR. In weighing that interest against your privacy we took the following into account: the data is minimal and deliberately kept that way, your IP address is not retained, the identifier cannot follow you across days or across sites, no profile is built, nothing is shared or sold, and anyone who signals an objection through their browser is excluded automatically and before anything is collected. We consider that a visitor to a business website would not be surprised by it. If you disagree, the objection right below is real and we will act on it.
How to stop it
Automatically: if your browser or an extension sends a Global Privacy Control signal, or Do Not Track, we collect nothing at all. The check happens before any data is read, so opting out this way means there is nothing to delete afterwards. Global Privacy Control is built into some browsers and available as an extension for the rest.
By asking: email info@automatikit.com and we will stop and delete what we hold. You do not have to explain why.
How long it is kept
- Analytics records: 90 days, then deleted. This is done by a scheduled job on our server rather than by hand, so it happens whether or not anyone remembers. Nothing about a visit survives it.
- The daily notification emails: they stay in our mailbox until we delete them, and we do not promise a schedule for that. There is nothing in them to protect: each one says only that a named site had activity on a given date.
Who else is involved
We use a small number of providers, each acting on our instructions:
- Hetzner Online GmbH: server hosting, in Germany (EU).
- Microsoft Ireland Operations Ltd: our email (Microsoft 365). The daily notification emails pass through it, though they carry nothing about you, and so does any message you send us, including one asking us to stop or to say what we hold. Microsoft may process data outside the EU/EEA under the European Commission's standard contractual clauses and the EU-US Data Privacy Framework.
The location lookup uses a database file stored on our own server, so no data about you is sent to a location provider.
Your rights
You can ask us for a copy of what we hold about you, to correct it, to delete it, to restrict how we use it, to receive it in a portable form, and to object to the processing described here. Because we rely on legitimate interest rather than consent, the right to object applies directly.
In practice there is a limit worth being honest about: the daily key is not reversible and changes every night, so we usually cannot find "your" records from an email address alone. If you want your data removed, telling us roughly when you visited is the practical way for us to act on it, and the fastest route is to turn on Global Privacy Control so nothing is collected in the first place.
Write to info@automatikit.com. If you are not satisfied with our answer you can complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), Box 8114, 104 20 Stockholm, imy.se.
Changes
If we change what we collect or why, we will change this page and the date at the top of it.
← Back to automatikit.com