1. Who is responsible for your data?
Resly AB, company registration number 559266-6563, Kånnavägen 40, 341 31 Ljungby, Sweden, is responsible for personal data processed for its own purposes, such as customer relationships, payments, bookkeeping and enquiries. Contact us at support@resly.se.
For documents, recipient details and signing workflows supplied by our customers, the customer normally determines the purpose and acts as controller. Resly processes data on its behalf under a Data Processing Agreement (DPA). If you receive an envelope, first contact the sender’s organisation about the document and its retention. We assist the customer in handling your request.
2. What data do we receive and from where?
We receive names, work contact details, company information, addresses, account details and billing information from you or the organisation you represent. When you contact us, we receive your message and the information you provide. Payment and invoice status may come from Stripe and Fortnox.
In the signing service, we receive information from senders and signatories: documents and document names, names, email addresses, sometimes telephone numbers and messages, IP addresses, timestamps, verification information and signing evidence. Dates of birth may be included depending on settings. Sender-supplied personal identity numbers are stored for the envelope and matched during eID verification. Identity numbers returned by eID are not stored if the sender has not supplied them. Resly does not insert identity numbers into the generated document; customer-uploaded contents may nevertheless contain such information.
While website analytics is on, we collect visited pages, clicks, timestamps, browser and device information, and visitor and session identifiers. Session recordings can reproduce how you use the page with forms excluded as described in section 7. Technical errors may include error messages and information about where in the code an error occurred.
Customers may submit documents containing special category data. The customer is responsible for information and legal authorisation for that content. This policy does not authorise Resly to use customer documents for other purposes.
3. Purposes and legal bases for Resly’s own processing
Customer relationships and accounts: we use contact and company details to administer the relationship and communicate with customer representatives. The basis is our legitimate interest in providing and administering the service for the customer organisation (Article 6(1)(f)). If you personally are a contracting party, Article 6(1)(b) applies to processing necessary for the contract.
Payments and invoicing: information is needed to collect payments and manage receivables, based on our legitimate interest in being paid, or contract where you personally are a party. Retention of accounting records is based on a legal obligation under bookkeeping law (Article 6(1)(c)).
Contact and support: we process contact details and case contents to answer questions and resolve issues, based on our legitimate interest in effective customer service. Troubleshooting customer documents is performed on customer instructions under the DPA.
Security and legal claims: necessary access and event information is used to protect the service, investigate misuse and establish, exercise or defend legal claims. Processing for our own purposes is based on legitimate interests. Processing solely on the customer’s behalf is covered by the DPA. The allocation of roles for logs must be verified before this policy takes effect.
Website analysis and improvement: we use PostHog with analytics on by default and an option to turn it off for visitor analytics, session replay and collection of technical errors. The purpose is to understand how the website is used, improve website content and navigation and diagnose errors. Section 7 explains the scope and how to change your choice.
Information needed for accounts, billing or identification is required to provide the respective function. Without it we may be unable to provide that function. Website analytics can be turned off. You can use the website, send an enquiry and book a demo even if you decline.
4. Who receives the data?
Authorised Resly personnel handle data for their work. Two people have administrative production access for incident handling and customer-requested troubleshooting. Support uses Chatwoot in Resly’s own environment at support.resly.se. Chat messages, information you provide and technical data needed for the chat are processed there. The former Help Scout widget has been removed from the website. Internal operational monitoring is separate from website error collection through PostHog.
Elastx provides hosting and storage in Sweden. Twilio receives telephone numbers and signing links for SMS. Postmark receives email addresses, document names, optional messages and a document copy if the customer enables attachments. Freja is used directly for electronic identification and ZignSec for BankID. Necessary data for each identification is transferred to those services.
Stripe handles card payments and Fortnox invoicing and bookkeeping. They receive customer billing details, including company name, contact person, email address, address and price/invoice information. Their roles may vary between processing on our behalf and their own statutory or other independent purposes.
Cal.com is used for demo bookings. When the booking calendar loads, Cal.com receives technical connection data; when you book, it receives the contact and booking information you provide. Booking and support chat are separate from your PostHog analytics preference.
While analytics is on, PostHog receives website analytics, session recordings and technical errors as described in section 7. Resly determines the purposes of this processing and uses PostHog as a processor. Google Analytics and Google Tag Manager are no longer used on the public website. Data may also be disclosed to authorities where required by law or to advisers where needed for legal claims, with appropriate confidentiality. Exact provider entities, roles and processing must be completed in the provider register before publication as an effective policy.
5. Where is data processed?
Resly’s own hosting, database and backups are at Elastx in Sweden. Data sent to external services may be processed in other countries. For example, Postmark’s published terms cover processing in the US and other countries. We therefore cannot generally state that all personal data stays in Sweden.
For website analytics, we have selected PostHog Cloud EU, with data storage in Frankfurt, Germany. Selecting the EU region is not in itself a guarantee that all provider access and all subprocessor activities take place within the EEA; these are covered by the transfer safeguards review below.
Transfers outside the EEA require a valid basis, such as an applicable adequacy decision or European Commission standard contractual clauses with necessary assessments and safeguards. Exact countries, recipients and bases for Resly’s actual accounts must be verified before this policy takes effect. Contact support@resly.se for information and a copy of applicable safeguards.
6. How long is data retained?
Customer documents and related envelope data: until the customer deletes the envelope or company account. After subscription cancellation, a read-only account remains until the customer deletes it. Deletion removes data from the active environment; copies may remain in backups for up to 90 days.
Access logs: one year in the cluster. They may contain envelope IDs after deletion; an ID no longer opens a document but logs are not automatically considered anonymous.
Bookkeeping: accounting records are retained through the seventh year after the end of the calendar year in which the financial year ended. This obligation does not mean all customer details or documents must be retained for that period.
Stripe and Fortnox: deleting a Resly account does not automatically delete information in those services. Manual action is currently required. A deletion procedure must be implemented to distinguish statutory accounting records from other contact, customer and payment information.
Website analytics: retention periods for events, errors and session recordings in Resly’s PostHog project need to be confirmed and documented before this policy is finalised. Your opt-out remains stored until you change it or clear website data. This does not determine how long PostHog retains analytics data. Declining further collection does not automatically erase previously collected data; erasure requests are handled under section 8.
Support cases, other customer administration and statistics: fixed retention periods or sufficiently precise deletion criteria must be decided and implemented before this policy takes effect. For legal claims, only necessary information should be kept for as long as justified by the claim or relevant limitation period. This policy does not authorise general indefinite retention.
8. Your rights
You may request access to your personal data and correction of inaccuracies. Where conditions are met, you may request erasure, restriction or data portability. You may object to processing based on legitimate interests and withdraw consent for future processing. Rights are not absolute; for example, bookkeeping requirements may limit erasure.
Contact support@resly.se. We may need to verify your identity proportionately. We normally respond within one month. If a permitted extension is needed, we inform you within the first month. For data controlled by a customer, we help direct your request to that customer.
You may complain to the Swedish Authority for Privacy Protection (IMY) or a competent supervisory authority where you live or work, such as Datatilsynet in Norway. Whether any automated decision-making with legal or similarly significant effects occurs must be confirmed before publication; no assertion about such processing is made here.
9. Changes and contact
This information was updated on 8 September 2026. Described planned changes apply only once implemented. Material future changes will be communicated appropriately; fresh consent will be obtained where required. Contact: support@resly.se, Resly AB, Kånnavägen 40, 341 31 Ljungby.