How Daana handles personal data
Daana AB builds data-platform software and offers data-platform services to companies. This page explains what personal data we hold about people we contact for work, and about people who contact us, why we hold it, and how to make us stop.
Who we are
Daana AB, a Swedish company, organisation number 559093-5671, c/o UnitedSpaces, Torsgatan 26, 113 21 Stockholm, Sweden. Daana AB is the controller of the data described here. Questions about this page or your data go to hello@getdaana.com, or reply "no" to any message from us.
The Swedish supervisory authority is Integritetsskyddsmyndigheten (IMY), imy.se.
Whom this page is about
- People in data and executive roles at companies, whom we contact about our product and services, by LinkedIn or by work email.
- People who contact us first, through a form on our website, by email or on LinkedIn.
- People we meet at conferences, podcasts and other events, and people a colleague of ours met and introduced to us.
What we collect, and where it comes from
- Your name, job title and employer.
- Your work email address or your LinkedIn profile address, whichever we use to reach you.
- Facts about your role or your company that bear on whether our work is relevant to you, each with the place we found it: your LinkedIn profile, your company's website, a public talk or article, an event programme, or a public register of companies.
- Our conversation with you, once there is one: the messages, and the meetings we book.
- If you filled in a form on our website: what you typed into it.
We do not collect private contact details, information about your private life, or any special category of data (such as health, religion or political views). We do not buy contact lists.
Why we hold it, and on what legal basis
- To contact you about our product and services in your professional role, and to follow up when you answer. The basis is our legitimate interest in reaching the people who decide on data platforms at the companies we can help (GDPR Article 6(1)(f)). We have weighed that interest against yours: we write to few people, each message is written for one person and read and approved by one of us before it goes out, and one reply stops it.
- To answer a request you sent us through our website, such as a request for an assessment. The basis is taking steps at your request before a possible contract (Article 6(1)(b)).
- To keep a record that you asked us not to contact you, so that we never do so again. The basis is our legal obligation to respect your objection, and our legitimate interest in honouring it.
How we use it
We use software to keep track of our conversations, to draft messages and to remind us of follow-ups. Some of that drafting is done by an AI system. No message is sent to you without one of us reading and approving it, and no decision with legal or similar effects on you is made by automated means.
How long we keep it
- People we found and did not choose to contact: deleted 30 days after we found them.
- People we contacted who never replied: deleted 12 months after our last message.
- People we work with or talk business with: kept while the conversation or the work is active, then deleted 24 months after it ends.
- Backups: kept for 30 days, so a deletion reaches the backups within 30 days.
- A record that you objected or asked to be deleted: kept indefinitely, as a one-way code made from your email address or LinkedIn address, not the address itself, so that we can recognise and respect your choice if we come across you again.
Who else processes it
We use these service providers, each acting on our instructions:
- Supabase: our database and our software services, hosted in Stockholm, Sweden.
- Anthropic: the AI system that helps us draft messages and keep track of conversations.
- Unipile: the connection between our software and our LinkedIn and email accounts.
- Google Workspace: our email and calendar.
- Slack: our internal messaging, where we review and approve messages before they are sent.
[ processor agreements and transfers to be confirmed ] We are reviewing each provider's data-processing agreement, including where each one processes data and what protects any processing outside the EU and EEA. We will name the position here once each agreement has been read.
We do not sell your data, and we do not share it with anyone else for their own purposes.
Your rights
You can ask us at any time to:
- tell you what we hold about you and give you a copy;
- correct anything that is wrong;
- delete what we hold about you;
- restrict how we use it;
- stop contacting you. An objection to direct marketing always wins: we stop, without weighing it against our interest.
If you sent us a request through our website, you can also ask for your data in a format you can take elsewhere.
To use any of these rights, reply "no" or "delete" to any message from us, or write to hello@getdaana.com. We answer within one month. If you think we have handled your data wrongly, you can complain to Integritetsskyddsmyndigheten (imy.se).
Changes to this page
We change this page when what we do changes, and date each version. This version: 2026-10-05.