Last updated: 14 August 2026
This Privacy Policy explains how Harbour Consulting AB collects, uses, shares, stores and protects personal data when you visit harbourconsulting.se, contact us, book or pay for a consultation, upload materials, or communicate with us about an institutional or commercial partnership.
1. Controller and contact
Harbour Consulting AB is the data controller for the processing described in this policy.
Email: [email protected]
Location: 418 42 Gothenburg, Sweden
2. Services covered by this policy
This policy covers our website and our activities relating to international education, academic writing guidance, study applications, doctoral applications, career development, Nordic residence-permit process guidance, entrepreneurship and self-employment consultation, and cooperation with schools, universities, employers and other organisations. A separate privacy notice or data-processing agreement may apply where an institutional partner engages us for a specific project.
3. Personal data we collect
Depending on how you interact with us, we may collect:
- Contact and identity data: name, email address, telephone number, optional WeChat ID, and correspondence preferences.
- Booking and billing data: customer type, company name where applicable, consultation category, selected dates and time periods, duration, booking status, billing country and address, VAT or tax-registration number, price and transaction references.
- Consultation information: information you provide in forms, emails, meetings and follow-up correspondence.
- Uploaded materials: documents you choose to provide, such as a CV, academic records, application drafts, employment information, business plans or immigration-related materials.
- Partnership information: professional contact details, job title, organisation, meeting notes, project requirements, referrals, proposals, agreements and records needed to manage cooperation with schools, universities, employers and other organisations.
- Payment information: Stripe processes card, bank and supported wallet payments. We receive transaction status, amount, currency and reference data, but not your complete card number or card security code.
- Technical and usage data: IP address, browser and device information, security and diagnostic logs, cookie identifiers and consent preferences.
Please provide only information relevant to the service. Do not upload passports, national identity numbers, health records or other highly sensitive information unless it is genuinely necessary and we have specifically requested it. If special-category data is necessary, we will identify an appropriate legal condition and, where required, ask for explicit consent.
4. Where personal data comes from
We normally collect data directly from you. We may also receive professional contact details from an organisation you represent, a person who refers you with permission, a payment provider, or publicly available professional sources. If an institution or other partner provides personal data about students, applicants, staff or other individuals, the partner must have a lawful basis for doing so. We provide additional information to the individual where required by law.
5. Purposes and legal bases
- Enquiries and requested information: to respond and take steps at your request before entering into a contract.
- Consultation bookings and delivery: to create and administer bookings, reserve selected time periods, deliver consultations, communicate about preparation and follow up the service. The legal basis is performance of a contract or pre-contractual steps.
- Payments, VAT, invoicing and accounting: to process transactions, prevent fraud, issue receipts or invoices and comply with Swedish bookkeeping, tax and other legal obligations.
- Partnership development and management: to assess proposals, arrange meetings, prepare agreements and manage institutional relationships. The legal basis is pre-contractual steps, performance of a contract, legal obligations, or our legitimate interest in developing and administering relevant professional cooperation.
- Service quality, security and legal claims: to protect the website and booking system, troubleshoot faults, prevent misuse, keep appropriate records and establish, exercise or defend legal claims. The legal basis is our legitimate interests and, where applicable, legal obligations.
- Optional cookies and direct marketing: consent where consent is required. You may withdraw consent at any time.
We do not sell personal data. We do not use consultation or partnership data for automated decision-making that produces legal or similarly significant effects.
6. Sharing and service providers
We share personal data only where necessary for the purposes above. Recipients may include:
- website hosting, WordPress, security, backup and consent-management providers;
- Stripe and participating banks or payment-method providers for payment processing;
- Resend and our email provider for booking confirmations, receipts, service messages and correspondence;
- professional advisers, accountants, insurers and public authorities where necessary or legally required;
- schools, universities, employers or other cooperation partners where you have asked us to make an introduction, where sharing is necessary for an agreed service, or where another lawful basis applies.
We do not provide uploaded consultation materials or detailed client information to a cooperation partner merely because we have a relationship with that organisation. We will explain the intended disclosure and obtain consent where consent is the appropriate legal basis. Service providers acting as processors may use personal data only to provide the contracted service and under appropriate data-protection terms.
7. International transfers
Some providers, payment networks, email services or cooperation partners may process data outside Sweden or the European Economic Area. Where the GDPR requires safeguards, we rely on an adequacy decision, the European Commission’s Standard Contractual Clauses, or another lawful transfer mechanism, together with supplementary measures where appropriate.
8. Retention
- General enquiries are normally retained for up to 12 months after the last meaningful contact.
- Incomplete booking and related technical records are normally retained for up to 90 days, unless needed for security, fraud prevention or a dispute.
- Consultation correspondence and uploaded materials are normally retained for up to 24 months after the last consultation or the end of the engagement. You may request earlier deletion where no legal or contractual reason requires continued retention.
- Partnership contact records and working correspondence are normally retained for the active relationship and up to 24 months afterwards. Agreements, project records and accounting material may be retained longer where required by law or necessary for legal claims.
- Booking, receipt, invoice, VAT and payment records forming part of our accounting records are retained for the period required by Swedish bookkeeping and tax law, normally at least seven years.
- Security logs and cookie-consent records are retained only for as long as reasonably necessary for security, troubleshooting and demonstrating consent.
Specific information may be kept longer where necessary to comply with law, resolve a complaint, or establish, exercise or defend legal claims. Data that is no longer required is deleted or anonymised.
9. Security and materials
We use proportionate technical and organisational measures, including access controls, restricted access to uploaded materials, secure service providers, backups and website security controls. Access is limited to people who need the information for the relevant service. No method of internet transmission or storage is completely secure, so please avoid sending unnecessary sensitive information by ordinary email.
The booking system permits optional uploads only after payment. Current technical limits are up to 10 files, with a maximum of 20 MB per file. Technical limits do not mean that every document is appropriate to upload.
10. Your rights
Subject to the GDPR and applicable exceptions, you may request access, correction, deletion, restriction of processing or data portability, and you may object to processing based on legitimate interests. Where processing is based on consent, you may withdraw consent at any time without affecting earlier lawful processing.
To exercise a right, contact [email protected]. We may need to verify your identity. You may also lodge a complaint with the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten, through IMY or with another competent EEA supervisory authority.
11. Cookies
Essential cookies support website operation, security, booking and payment functions. Optional analytics or marketing cookies are used only after consent where required. The consent banner describes available categories and allows you to accept, reject or adjust optional cookies. You can later change your choice through Cookie Settings.
12. Children and student services
Paid consultations are ordinarily booked by adults. Where guidance concerns a person under 18, a parent or legal guardian should make or approve the booking and participate where appropriate. Institutional partners remain responsible for obtaining any notices, permissions or consents required for data they provide about minors.
13. Changes to this policy
We may update this policy when our services, booking technology, providers, partnership activities or legal obligations change. The current version and update date will be published on this page. Material changes may also be communicated directly where appropriate.
14. Contact
Questions about this policy or our handling of personal data can be sent to [email protected].
