Privacybeleid voor app-gebruikers

Laatst bijgewerkt:

1. Introduction to our policy

Solace AB (559519-7079), a company incorporated in Sweden with its registered address at Luntmakargatan 26, 111 37 Stockholm, Sweden (“Solace”, “we”, “our” or “us”), is committed to protecting and respecting your privacy.

Solace AB is the data controller of your personal data when you create and use a Solace account, use our app, or access the Solace Care Platform.

This Privacy Policy explains:

  • why and how we may use the personal information that we have obtained from interactions you (or others) may have with us as a business, including when you use our services, visit and use our mobile app (Solace), visit and use the Solace website portal (currently located at app.solace.care) (Solace Portal) or when you contact us.

  • with whom we share your personal information, and

  • the rights you have in connection with the information we use.

We maintain a separate Website Privacy Policy detailing how we process your personal information in connection with our website, solace.care more generally, please visit our Website Privacy Policy and our Cookies Policy.

If you are a User, please read this Privacy Policy carefully to ensure you fully understand it. In this Privacy Policy, a “User” is a person with a Solace account. A “Loved One” is a person a User adds or names in the Services, for example a family member, a beneficiary or a relative who has died. The Services are intended for adults aged 18 or over.

This Privacy Policy may change from time to time so please check this Privacy Policy occasionally to ensure that you are happy with any changes. For more information on changes to our Privacy Policy, please see section 7 (Updates and changes).

Controller and data protection contact:

Controller: Solace AB, reg. no. 559519-7079

Registered address: Luntmakargatan 26, 111 37 Stockholm, Sweden

General email: support@solace.care

We have appointed a Data Protection Officer (DPO). You can contact them at: privacy@solace.care

Postal address: DPO, Solace AB, Luntmakargatan 26, 111 37 Stockholm, Sweden

Access through a Partner

You may have access to Solace through an insurance company, insurance intermediary, employer, pension provider or other partner (a “Partner”), for example when Solace is included in your insurance. Solace and the Partner each decide over their own processing and are not joint controllers. Personal data moves between Solace and the Partner as described below.

  • Before you register, the Partner tells us that you are eligible for the Services. This may include your name, contact details, national identification number and a policy or membership reference. The Partner informs you about this disclosure. We use the data only to confirm your eligibility and invite you to register. Depending on our agreement with the Partner, we handle this data on the Partner’s behalf or as a separate controller.

  • When you register, you accept our Terms of Use and Solace becomes the controller of your account and the content you add. The Partner cannot see your documents, plans, chats or other content.

  • We tell the Partner whether and when your account was activated or deleted, because the Partner needs this to administer and pay for your access. We may also share statistics that do not identify you. If the insurance company offers it, you can choose to send information for an insurance claim to the insurance company through the Services.

  • If your access through the Partner ends, your account and content are not handed over to the Partner. You can continue as a private customer, download your content or delete your account. Data we handled on the Partner’s behalf is deleted or returned according to the Partner’s instructions.

2. How and why do we process your personal data?

When we use the term "personal data" in this Privacy Policy, we mean information that identifies, relates to, describes, or could reasonably be linked, directly or indirectly, to an individual. It does not include anonymised or aggregated data that is not reasonably capable of being associated with an individual.

Solace processes your personal data for specific purposes. This means that we always define “why” we process your personal data. For each purpose, we have identified a legal basis.

In this section we describe our different purposes for processing your personal data. For each purpose we state the following information:

  • What personal data is collected and processed.

  • The purposes for processing the data.

  • The legal basis Solace relies on to process this data.

Categories of personal data

Solace processes different types of personal data about you which we choose to categorise in the following ways:

  • Identity information (for example, first and last name and your national identification number).

  • Contact information (for example, email address, telephone number and address).

  • Payment information (for example, your bank details and account details, contractual details, and preferences relevant to our engagement).

  • User information (for example, information about the relationship to a Loved One, geolocation, and insights relevant to the user experience).

  • Device information (for example, IP address and browser settings, digital identifiers, device data (such as type, OS, browser version, language settings), and log-in credentials).

  • Work-related and Partner data (for example, your employer, the Partner through which you have access, and a policy or membership reference).

  • Information about Loved Ones (for example, contact person and names of children, date of birth and death, national ID numbers, legal, financial, and health documents, and additional background including gender, religion, marital status, and professional experience). The GDPR does not generally apply to information about people who have died, but we protect it with the same care.

  • Sensitive personal data (for example, health information in documents or chats, or funeral wishes that reveal religious beliefs). We process sensitive personal data only with your explicit consent (GDPR Art. 9.2.a). You can withdraw your consent at any time by deleting the information or contacting us. We may also process such data where another exception in GDPR Art. 9.2 applies, for example to establish or defend legal claims (GDPR Art. 9.2.f).

If you add information about another person, please do so only where you are entitled to and where it is needed for your planning. We process this information based on our and your legitimate interest (GDPR Art. 6.1.f) in helping you plan and manage end-of-life matters.

Where do we obtain personal data from?

Information you provide to us

When you interact with Solace in various ways, for example by submitting a form or discussing with one of our customer advisors, you will be providing information to us directly. The exact information we receive will depend on the context of our interaction.

Information we record about you

When you contact customer support or book an advisor call, we create a case linked to you. In the case we record your request and how we handle it.

In addition to information that you actively provide to us, you also provide us with information in other ways, consciously or unconsciously. For example, we use various types of tracking technology on our website, in the app and in our e-mails that are intended to provide us with statistics and help us improve our services and offerings.

More information about how our website uses cookies and how to turn them off can be found here.

Information we receive from other sources

We may obtain information about you from public registers when we need to verify or update your details.

When we carry out our Service we may also collect information from third parties such as your Partner (see Access through a Partner in section 1), government agencies, and other service providers such as funeral organising partners.

If a User invites you or names you as a family member, co-planner or beneficiary, we receive your name and contact details from that User. We may also receive information about you from other relatives. When we first contact you, we tell you where we got your details and refer you to this Privacy Policy.

We may combine personal data collected from different sources to enhance the accuracy of our records and improve our Services.

2.1 Processing necessary for providing the Basic User Profile

2.1.1 Categories of personal data

Identity information

  • Name, national identification number, and other personal identifiers

Contact information

  • Email address and phone number

Device information

  • IP address, device type, and usage patterns (if applicable)

2.1.2 Purpose of processing

Your identity information is processed for the following purposes:

  • To provide users with an account and personalised experience.

  • To manage user registration and account authentication.

  • To identify you securely, where relevant with your national identification number, and to confirm your eligibility when you access Solace through a Partner.

Your contact information is processed for the following purposes:

  • To communicate important account-related updates.

  • To provide customer support.

Your device information is processed for the following purposes:

  • To improve platform functionality based on usage behaviour.

  • To ensure system security.

2.1.3 Legal basis

The legal basis for this processing is the performance of a contract (GDPR Art. 6.1.b) to provide you with the agreed Service.

We process your national identification number only where this is clearly justified for secure identification (GDPR Art. 87 and, in Sweden, Chapter 3 Section 10 of the Swedish Data Protection Act (2018:218)).

2.2 Processing necessary for providing Legacy Planning

2.2.1 Categories of personal data

Identity information

  • Name and any personal identifiers associated with uploaded documents

Contact information

  • Email or phone number linked to the user account

Device information

  • Device metadata related to uploaded documents

Content information

  • Documents, wishes and notes you add, for example wills, funeral wishes, overviews of assets and insurance, and instructions for Loved Ones. This content may include information about Loved Ones and sensitive personal data.

2.2.2 Purpose of processing

Your identity and contact information is processed for the following purposes:

  • To associate legacy planning documents with the correct account.

  • To enable secure communication about legacy planning.

  • To store your content securely and make it available to you and to the Loved Ones you choose, according to your instructions.

Your device information is processed for the following purposes:

  • To ensure secure uploading and access to legacy planning documents.

2.2.3 Legal basis

The legal basis for this processing is the performance of a contract (GDPR Art. 6.1.b).

We also rely on our legitimate interest (GDPR Art. 6.1.f) to allow users to manage and share their legacy planning safely.

2.3 Processing necessary for providing Loss Support

2.3.1 Categories of personal data

Identity information

  • User name (if linked to checklist progress)

Device information

  • Usage data and interactions with the checklist

Loss information

  • Information you add about the person who has died and the estate, for example name, date of death, your relationship, estate or insurance documents and contact details of other heirs.

2.3.2 Purpose of processing

Your identity information is processed for the following purposes:

  • To identify the user’s checklist progress.

Your device information is processed for the following purposes:

  • To track user interactions with the checklist.

  • To provide relevant recommendations and improvements.

2.3.3 Legal basis

The legal basis for this processing is the performance of a contract (GDPR Art. 6.1.b).

2.4 Processing necessary for providing AI Chat Support

2.4.1 Categories of personal data

Identity information

  • Name (if associated with chat account)

Contact information

  • Email (if linked to chat service)

Device information

  • Chat content you enter, which may include information about Loved Ones or sensitive personal data, interaction metadata, and device identifiers

2.4.2 Purpose of processing

Your identity and contact information is processed for the following purposes:

  • To associate chat interactions with your account.

Your device information is processed for the following purposes:

  • To provide AI-assisted guidance and responses.

  • To improve AI features and personalise recommendations. We do not use your chat content to train third-party AI models.

  • To ensure quality control and resolve support issues.

2.4.3 Legal basis

The legal basis for this processing is the performance of a contract (GDPR Art. 6.1.b).

The chat shows clearly that you are interacting with AI (EU AI Act, Regulation (EU) 2024/1689, Art. 50). AI providers process the chats on our behalf with the safeguards described in section 2.13.4.

2.5 Processing necessary for providing Family Sharing

2.5.1 Categories of personal data

Identity information

  • Name of the user and invited family members

Contact information

  • Email addresses of users and family members

Device information

  • Interaction and access logs

2.5.2 Purpose of processing

Your identity and contact information is processed for the following purposes:

  • To allow users to share platform access with family members.

  • To enable collaborative uploads and editing of personal data.

  • To notify family members of shared content and updates.

Your device information is processed for the following purposes:

  • To log and monitor access to shared data for security purposes.

2.5.3 Legal basis

The legal basis for this processing is the performance of a contract (GDPR Art. 6.1.b).

For the data of family members you invite, we rely on legitimate interest (GDPR Art. 6.1.f) in letting you share access with them. You decide what to share and can revoke access at any time.

2.6 Processing necessary for providing beneficiary contact information

2.6.1 Categories of personal data

Identity information

  • Name of beneficiaries

Contact information

  • Email addresses of beneficiaries

2.6.2 Purpose of processing

Your identity and contact information is processed for the following purposes:

  • To designate beneficiaries who can access legacy planning data after the user’s death.

  • To facilitate secure communication with beneficiaries.

  • To verify a death, for example with a death certificate, before we give beneficiaries access.

2.6.3 Legal basis

For your own data, the legal basis is the performance of a contract (GDPR Art. 6.1.b).

For beneficiaries’ data, we rely on legitimate interest (GDPR Art. 6.1.f) in letting you decide who may access your legacy planning data.

2.7 Processing necessary for Service Communication

2.7.1 Categories of personal data

Identity information

  • Name

Contact information

  • Email address, phone number

Device information

  • Device identifiers for notifications

2.7.2 Purpose of processing

Your identity and contact information is processed for the following purposes:

  • To contact users regarding service updates, maintenance, or security notices. These communications are mandatory for service use.

  • To facilitate customer service interactions, notify users about changes, and provide relevant information regarding their accounts and services.

Your device information is processed for the following purposes:

  • To send notifications to the last phone you used to log in to the Service.

2.7.3 Legal basis

The legal basis for this processing is the performance of a contract (GDPR Art. 6.1.b).

2.8 Processing necessary for evaluating and improving our Service and conducting research

2.8.1 Categories of personal data

Identity information

  • Name (if linked to usage data)

Contact information

  • Email address (if linked to research participation)

Device information

  • Usage data, interaction logs, device metadata and, if you have accepted analytics cookies, session analytics

2.8.2 Purpose of processing

Your identity and contact information is processed for the following purposes:

  • To link usage behaviour to account information.

  • To invite selected users to participate in research.

Your device information is processed for the following purposes:

  • To analyse user behaviour and interactions.

  • To tailor user experiences, content recommendations, and preferences.

  • To improve our services and conduct research.

2.8.3 Legal basis

The legal basis for this processing is legitimate interest (GDPR Art. 6.1.f) in improving services and research. If analytics require storing or reading information on your device, we ask for your consent first (ePrivacy Directive 2002/58/EC Art. 5.3 and, in Sweden, Chapter 9 Section 28 of the Electronic Communications Act (2022:482)).

2.9 Processing necessary for marketing services and products

2.9.1 Categories of personal data

Identity information

  • Name

Contact information

  • Email, phone number, and other consented communication channels

Device information

  • Device identifiers for marketing notifications, Cookie data

2.9.2 Purpose of processing

Your identity and contact information is processed for the following purposes:

  • To send newsletters, updates, special offers, and relevant marketing communications about services, features, offers, and events where consent has been given.

  • To inform you of our products or services via notification or email.

  • To send you promotional marketing emails and marketing newsletters (you can unsubscribe from any mailing lists at any point).

  • We may provide such notices through any of the contact means available to us (e.g., phone, mobile or email) or through the Services.

Your device information is processed for the following purposes:

  • To deliver marketing notifications on the relevant device.

  • If you have accepted marketing cookies, your cookie data is processed to show you targeted advertising and to measure the reach of our marketing campaigns.

2.9.3 Legal basis

The legal basis is your consent (GDPR Art. 6.1.a). For email marketing to existing Users about our own similar services, we may instead rely on legitimate interest (GDPR Art. 6.1.f) where marketing law allows it (in Sweden, Section 19 of the Marketing Practices Act (2008:486)). If you access Solace through a Partner, we send you marketing only with your consent. The Partner does not decide this, and your consent stays valid after your access through the Partner ends until you withdraw it.

You have the right to withdraw your consent (to “opt out”) of any marketing communications at any time. You can opt-out (e.g. email) by using the unsubscribe link available in every newsletter or in every commercial message you receive from us or in case of electronic direct marketing by following the instructions in the communication, or contacting privacy@solace.care.

2.10 Processing necessary for in-app tracking and optimising ad campaigns

2.10.1 Categories of personal data

Device information

  • App events (installation, registration, account activation)

  • Mobile identifiers (IDFA, Google Play Services ID)

  • Pseudonymised IP addresses

2.10.2 Purpose of processing

Your device information is processed for the following purposes:

  • To understand how users interact with our Applications.

  • To measure the performance of and optimise our ad campaigns.

2.10.3 Legal basis

The legal basis for this processing is our legitimate interest (GDPR Art. 6.1.f) in measuring and improving the reach of our Services. If the law requires consent for storing or reading information on your device, for example mobile advertising identifiers, we ask for it first. We never share information about your loss, your health or the content of your account with advertising platforms.

You can object to this processing at any time (see section 5).

Users can opt out at any time via device settings (App Tracking Transparency on iOS and Ads Personalization on Android).

2.11 Processing necessary for legal compliance

2.11.1 Categories of personal data

Identity information

  • Name, identifiers related to legal inquiries

Contact information

  • Email, phone number

Payment information

  • Transaction records, if relevant

Device information

  • Access logs, metadata

2.11.2 Purpose of processing

Your identity, contact, payment, and device information may be processed for the following purposes:

  • To comply with legal obligations and regulatory inquiries.

  • To enforce agreements and respond to official requests.

2.11.3 Legal basis

The legal basis for this processing is our legal obligation (GDPR Art. 6.1.c).

2.12 Processing necessary for security and fraud prevention

2.12.1 Categories of personal data

Identity information

  • Name, identifiers linked to accounts

Contact information

  • Email, phone number

Payment information

  • Transaction and account details for fraud detection

Device information

  • IP addresses, device metadata, login attempts, and security logs

2.12.2 Purpose of processing

Your identity, contact, payment, and device information is processed for the following purposes:

  • To monitor and prevent security threats, fraud, and abuse.

  • To ensure platform integrity and protect user accounts and data.

2.12.3 Legal basis

The legal basis for this processing is our legitimate interest (GDPR Art. 6.1.f) in securing the platform and preventing unauthorised access.

2.13 Processing involving internal artificial intelligence tools

Solace staff members use AI-powered tools to support internal business operations related to the provision and improvement of our Services. These tools assist staff in case management, service delivery, quality assurance, and operational efficiency. This section covers such internal use and is distinct from the AI Chat Support feature available to members (see section 2.4).

2.13.1 Categories of personal data

Identity information

  • Your name and account identifiers, where necessary to provide context for case-specific support or analysis

Contact information

  • Email address and phone number, where included in support-related communications or case documentation

Service information

  • Case details, service usage patterns, interaction history, and transaction information. Where possible, personal data is anonymised or pseudonymised for analysis

Device information

  • Interaction metadata and usage patterns associated with your account

2.13.2 Purpose of processing

Your identity, contact, service, and device information may be processed for the following purposes:

  • To assist Solace staff in managing cases and providing responsive, effective customer support.

  • To support internal analysis and research to improve the quality and features of our Services.

  • To assist in drafting communications, documentation, and case notes relating to your account and service experience.

  • To improve operational efficiency in case management, quality assurance, and customer support processes.

2.13.3 Legal basis

The legal basis for this processing is our legitimate interest (GDPR Art. 6.1.f) in improving service quality, providing efficient customer support, and maintaining operational excellence. We have assessed that your interests and rights do not override this interest.

2.13.4 Processors and safeguards

AI service providers act as our processors under data processing agreements that include:

  • Processing solely on our written instructions

  • Standard Contractual Clauses or another valid transfer mechanism, for example the EU-U.S. Data Privacy Framework, where providers are located outside the EU/EEA

  • No use of your data to train the providers’ AI models

  • No retention of personal data after processing, or only strictly limited retention

  • Appropriate technical and organisational security measures

  • Regular supplier reviews

2.13.5 Storage and retention

AI service providers may keep personal data only as long as their agreement with us allows, and never longer than needed to complete the task. Internal records, case documentation, and notes generated with AI assistance follow the standard retention periods applicable to the relevant service category (see retention schedule in section 6).

3. Automated decision making

We use artificial intelligence tools to assist our staff in providing and improving our Services. These tools support our team by analysing information, suggesting actions, and generating content. However, AI tools do not make automated decisions that produce legal or similarly significant effects on you (GDPR Art. 22). We do not use AI to decide on insurance eligibility, pricing or claims. All decisions affecting your account, services, rights, or eligibility are made or reviewed by our staff members. We remain responsible for all decisions and their outcomes.

If the use of AI in our decision-making processes changes materially in the future, for example if AI starts to make decisions about your account on its own, we will update this Privacy Policy and inform you of the change.

4. How we share your personal data

We use trusted third-party service providers (processors and sub-processors) to deliver, support and improve the Solace Services. These providers may process your personal data on our behalf and only in accordance with our instructions.

The main categories of such providers are:

  • Cloud infrastructure and hosting providers for our app, databases and storage.

  • Authentication and identity providers for secure sign-in and access management.

  • Analytics and product tooling providers to understand and improve how the Services are used.

  • Communication providers (e.g. email, SMS, in-app messaging).

  • Payment and billing providers (where applicable).

  • Customer support tools we use to handle your requests.

  • Professional advisers (e.g. legal, accounting, auditors).

  • AI and technology service providers assisting with internal business operations (case management support, communication analysis, and service improvement).

We enter into data processing agreements with all such providers, including appropriate safeguards for any international transfers, and require them to implement suitable technical and organisational measures.

Transfers outside the EU/EEA

Our platform is hosted in the EU/EEA, and we aim to process your personal data only within the EU/EEA. When we need to share your personal data with recipients outside the EU/EEA, we ensure that this only happens to countries that are sufficiently secure (have an adequate level of protection) or that we take other appropriate safeguards. These appropriate safeguards include, among other things, that we use standard contracts approved by the EU Commission (EU Commission Standard Contractual Clauses) or the EU-U.S. Data Privacy Framework. We also assess the legislation of the recipient country before the transfer. When we believe that the laws of the recipient country do not provide adequate protection for your personal data, we take special measures so that the protection of your data remains when it is transferred to the relevant country outside the EU/EEA. You can ask for information about these safeguards and for a list of our sub-processors at privacy@solace.care.

Other recipients

We may also disclose personal data to other recipients. The Partner through which you have access receives only the information described under Access through a Partner in section 1. Referral partners, for example grief support, legal or funeral services, receive the information needed for a referral when you ask us to refer you. If a referral reveals health information, we ask for your explicit consent first. Loved Ones receive what you choose to share with them. Authorities receive personal data when the law requires it. A buyer or successor may receive personal data in a merger or acquisition. We do not sell personal data to third parties.

5. Data subject rights

GDPR gives you as an individual a number of different rights to your personal information. Solace has procedures in place to enable you to exercise your rights. You also always have the right to file a complaint with the Swedish Authority for Privacy Protection (IMY), or with the supervisory authority in the EU/EEA country where you live or work (GDPR Art. 77), if you believe that the processing of your personal data is in violation of the law. More general information about your data protection rights can be found on the IMY website together with the authority's contact details.

If you want to exercise your rights, or have questions about your rights in relation to Solace, please contact us by e-mail at privacy@solace.care.

We will handle your request without undue delay and in any event within one (1) month of receiving it. If your request is particularly complex or we receive a number of requests from you, we may extend this period by up to two (2) further months. If we need to extend the period, we will inform you within one month of receiving your request and explain why the extension is necessary.

We will provide information and take action on your request free of charge, unless your request is manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request in accordance with applicable law.

These rights also apply if you are a Loved One whose personal data a User has added to the Services.

Right of access

You have the right to be informed that we are processing your personal data and to have access to your personal data, i.e. you can receive a so-called register extract of the processing carried out. You also have the right to receive certain information about the processing as such (for example, for what purpose we are processing the data).

Right to rectification

The personal data we process about you must be accurate and up-to-date. You have the right to have inaccurate personal data about you corrected and the right to have incomplete data completed.

Right to erasure (“right to be forgotten”)

As a data subject, you have the right to have your personal data deleted by us to a certain extent. Please note that this does not apply to information that we need for the purpose of fulfilling legal obligations or defending ourselves against legal claims, or information that we need to perform our contract with you.

However, you may have the right to have your personal data erased if your personal data is no longer necessary for the purposes for which they were processed or if the processing is based on your consent and you withdraw this without there being any other legal basis for continued processing. You may also have the right to erasure if a processing is based on a balancing of interests and there are no compelling legitimate grounds that outweigh your interests. Furthermore, you may request erasure if the processing is for direct marketing purposes and you object to this. You also have the right to have your personal data erased if it has been processed unlawfully, or if erasure is required to comply with a legal obligation.

Right to object

You have the right to object to Solace processing of your personal data based on one of our legitimate interests. If you object to such processing, we may only continue to process the data if we demonstrate compelling legitimate grounds for us to process the data and where our interests outweigh your interests, for example where the processing is for the establishment, exercise or defence of legal claims.

Object to direct marketing

Processing for direct marketing purposes will cease immediately if you object to such processing. Please note that you always have the right to withdraw your consent to receive advertising from us. You can do this either by clicking "unsubscribe" at the bottom of the email you receive from us or by contacting us.

When you object to direct marketing, we will save information about this on our internal blocking list in order to be able to accommodate your request not to be contacted by us.

Right to restriction of processing

You have the right to request that our processing of your personal data be restricted if the data is processed incorrectly, for example, is inaccurate, if the processing is unlawful, if the data is no longer needed for the purposes. If you have objected to the processing of your personal data based on our legitimate interest, you may request that we restrict the processing while we investigate whether we have the right to continue with it. This right also applies while awaiting an assessment of whether the alleged error exists. When a restriction ceases, you have the right to be informed.

Right to data portability

In certain cases, you have the right to obtain information that you have provided to us and to have the information transferred to another data controller. This right applies when we process personal data automatically and with your consent or on the basis of a contract.

Right to withdraw consent

If our processing of personal data is based on your explicit consent, you have the right to withdraw it at any time. However, the withdrawal does not affect the lawfulness of the processing carried out based on the consent before the withdrawal. You can withdraw your consent, for example, by contacting us at privacy@solace.care.

6. Security and data storage

Data security

We implement appropriate technical and organisational security measures (GDPR Art. 32). These include encryption in transit and at rest, access controls and logging, within an information security management system based on ISO/IEC 27001. Users are encouraged to take precautions, such as using strong passwords and avoiding the sharing of sensitive information online. However, please be aware that regardless of any security measures used or implemented, we cannot and do not guarantee the absolute protection and security of any personal data stored with us or with any third parties.

How long do we store your personal data?

We store personal data for the duration that we consider reasonably necessary to support and enhance our relationship with you while delivering our Services and offerings, ensuring compliance with legal obligations, and safeguarding against potential claims. Once retention is no longer required, data is securely deleted or anonymised.

If an individual requests the deletion of their personal data, we will evaluate the request based on legal and contractual requirements.

Account and content data

Your account data and the content you add are stored for as long as you have an account. We delete or anonymise them when the account is deleted, either at your request or after three (3) years without activity. We notify you before we delete an inactive account. If we are informed that a User has died, we keep the account for 12 months so that designated Loved Ones can access it according to the User’s instructions, and then delete it unless the law requires otherwise. For data we handle on a Partner’s behalf, the Partner’s instructions also apply.

Payment information

Your payment information is saved for as long as you have an account and then for seven (7) years after the end of the relevant financial year, as bookkeeping law requires (in Sweden, Chapter 7 Section 2 of the Accounting Act (1999:1078)).

Device information

Your device information is stored for as long as you have an account. We delete it or make it completely unidentifiable when the account is deleted, either at your request or after three (3) years without activity.

In order to detect and fix errors, we save error logs in our systems. Since these logs may contain personal data, they are deleted after a maximum of 60 days. We always strive to minimise the storing of unnecessary data, therefore this storing period is often much shorter than 60 days.

Cookie data

If you have consented to third-party cookies being stored on your computer or mobile devices, the cookies will be removed when you uninstall them or when the cookie expires.

Customer service requests

If you have contacted our customer service team, the inquiry will be stored for 365 days before it is deleted.

Processing category

Storage period

Processing necessary for providing the Basic User Profile

As long as you have an account. The data is deleted or made completely unidentifiable when the account is deleted, either at your request or after three (3) years without activity.

Processing necessary for providing Legacy Planning

Same as for the Basic User Profile.

Processing necessary for providing Loss Support

Same as for the Basic User Profile.

Processing necessary for providing AI Chat Support

Same as for the Basic User Profile.

Processing necessary for providing Family Sharing

Same as for the Basic User Profile.

Processing necessary for providing beneficiary contact information

Same as for the Basic User Profile.

Processing necessary for Service Communication

For the duration of the user account or as required for ongoing service notifications.

Processing necessary for evaluating and improving our Service and conducting research

Up to 2 years, unless anonymised for research purposes.

Processing necessary for marketing services and products

Until consent is withdrawn or for the duration necessary to provide relevant marketing communications.

Processing necessary for in-app tracking and optimising ad campaigns

Up to 2 years, anonymised for statistical analysis after that.

Processing necessary for legal compliance

As required by law or regulatory authorities.

Processing necessary for security and fraud prevention

Up to 3 years, unless required longer for legal or security purposes.

Processing involving internal AI tools

AI service providers may keep personal data only as long as their agreement with us allows. Internal records, case documentation, and notes generated with AI assistance follow standard retention periods applicable to the relevant service category.

7. Additional notices and contact details

Updates and changes

Solace is constantly working to develop our business and our digital services. This means that we will also update this privacy policy on an ongoing basis in connection with our plans to change how we use your personal data.

We publish the updated version in the app and on our website. If we make material changes, we notify you in the app or by email before they take effect. If you do not agree with the changes, you can delete your account at any time.

For privacy-related inquiries, contact:

Data Protection Officer
Solace AB
Luntmakargatan 26, 111 37 Stockholm
Email: privacy@solace.care

Please see our Terms of Use for further legal information about Solace AB.

Version 1.4. Effective date 17.09.2026.