Security and compliance
How we protect data and users
Security is fundamental to everything we build. This page summarises our GDPR roles, where data is processed, how incidents are reported and how to contact us about security.
Roles under the GDPR
Fjällklar AB is the data controller for turplanering.se. This means that we decide why and how personal data is processed in the service. As a customer, you can also use turplanering.se as a data processor when you process participant data for your tours. In that case, our data processing agreement supplements the terms.
The approved English legal documents, including the data processing agreement, will be linked from the legal pageafter legal review.
Where data is stored
All user data is stored within the EU and EEA and processed only for purposes that the user has expressly agreed to. Health declarations and emergency contact details are stored in encrypted form. Access is logged, and deleting an account removes the data instead of merely hiding it.
The approved English list of data processors will be published with the English legal documents.
Incident handling
Report suspected security incidents to [email protected]. Personal data breaches that may pose a risk to individuals are reported to the Swedish Authority for Privacy Protection, IMY, within 72 hours in accordance with Article 33 of the GDPR. Affected users are informed under Article 34 when required.
Security contact
If you find a vulnerability in one of our services, please write to [email protected] and describe the issue and how it can be reproduced. We follow responsible disclosure. Our RFC 9116 security contact is published at /.well-known/security.txt.
Accessibility
We aim to meet WCAG 2.2 level AA. Current status is described in the accessibility statement.
Data protection questions
Contact [email protected] about your personal data, access, rectification, erasure, data portability or objections. You may also lodge a complaint with IMY at imy.se.