Privacy policy for the Grunda plugin
Effective 2 October 2026. Applies to the Grunda plugin in ChatGPT and the Grunda connector in Claude.
Datini Labs AB (Swedish company registration number 559593-4901), Stockholm, Sweden, provides Grunda and is the controller of the personal data described here. Questions and requests: grunda.co/kontakt.
What the plugin does
The plugin lets you prepare a document or agreement for signing with BankID, see who has signed, look up a Swedish company by its organisation number, and create a Swedish invoice as a PDF. It needs no account. When you use a tool, ChatGPT or Claude sends us only the information that tool needs. We do not receive the rest of your conversation, and the tools do not send your content to any AI model.
Personal data we collect
- Documents for signing: the agreement text written in the conversation or the PDF you upload, its title and any message to the signers. These can contain personal data about the parties, such as names, roles and contact details.
- Signers: the names and e-mail addresses of the people who should sign, if you give them.
- Invoices: what you give for the invoice: the seller's and the customer's names, organisation numbers, addresses and e-mail, the invoice lines, and bankgiro or IBAN.
- Company lookups: organisation numbers. They identify companies, not people. Sole traders, whose number is a personal identity number, are never looked up.
- An owner code for drafts: a one-way code made from the anonymous user ID that ChatGPT sends with each call, stored with a draft so that only you can update it from the conversation.
- Technical data: the IP address of each call and ChatGPT's anonymous user ID, used in memory to limit the number of calls per minute, and the request logs our hosting provider records, which include IP addresses.
- Usage counts: which tool was called, from which assistant, and whether it worked. The counts carry no identifier for you and none of the content.
- When a document is signed on grunda.co: BankID provides each signer's name and personal identity number, which are printed on the signature page of the signed document. We keep BankID's evidence of the signature (the signature value and the OCSP response) and the IP address used when signing.
We do not collect personal identity numbers through the tools (they are rejected, also inside free text), payment card details, passwords or other credentials, location data or your conversation history.
Why we use it
- To create the draft, the invoice or the lookup result you asked for, and to tell you who has signed.
- To let the parties sign with BankID on grunda.co, and to prove the signatures afterwards on the verification page that every signed document links to.
- To check that the companies in an agreement or an invoice exist and are active.
- To keep the service secure and prevent abuse, with call limits and request logs.
- To see how the tools are used, as counts without any identifier.
The legal basis is the service you ask for (GDPR article 6(1)(b)) and our legitimate interest in security and in knowing which tools are used (article 6(1)(f)). We never sell personal data, use it for advertising, or use it to train AI models.
Who receives it
- Hosting and storage: Vercel (servers in Stockholm) and Supabase (database and file storage in Stockholm).
- The people you invite to sign: they receive the document and, when everyone has signed, the signed copy by e-mail.
- E-mail delivery: Resend, only after you press Send on grunda.co.
- BankID signing: TIC Identity (The Intelligence Company AB, Sweden), which runs the BankID transaction.
- Statistics Sweden (SCB): receives organisation numbers only, to return the company's registered details.
- Analytics: PostHog, in the EU, receives the usage counts without identifiers.
Some of these providers are companies based outside the EU. Transfers are covered by Chapter V of the GDPR, for example the EU standard contractual clauses. OpenAI and Anthropic run the conversation and decide, under their own terms, what is sent to our tools; our answers go back into the conversation.
How long we keep it
- Drafts: seven days. A draft that is not sent is deleted when it expires. The owner code goes with the draft, or when you send it.
- Sent documents: the document and the signed PDF are deleted 30 days after sending, and a round that is not completed is deleted in full. The signature records (names, times and BankID's evidence) and the document's checksum are kept so that the verification link in the signed document keeps working. You can ask us to delete them earlier.
- Invoices: not stored. The invoice exists only inside its encrypted download link, which stops working after 30 days.
- Company lookups: the register's answer is kept in memory for at most 12 hours, so the same company is not fetched twice, and never in a database.
- Call limits: in the server's memory only, never written to storage.
- Request logs: kept by our hosting provider for at most 30 days.
- Usage counts: kept as statistics. They cannot be linked to you.
Your choices and controls
- Nothing reaches Grunda unless one of the plugin's tools is called in your conversation, and ChatGPT asks for your permission before a draft is created.
- You decide what goes into a document. Nothing is sent to anyone until you have reviewed the draft and pressed Send on grunda.co. If you do not, the draft is deleted after seven days.
- You can disconnect or remove the plugin in the settings of ChatGPT or Claude at any time.
- You can ask us for a copy of your data, correction, deletion, restriction or data portability, and object to our processing, through grunda.co/kontakt. You can also complain to the Swedish Authority for Privacy Protection (IMY).
Changes
We update this policy when the plugin changes, and the date at the top shows the current version. The rest of Grunda, including signing on grunda.co, is described in our full privacy policy in Swedish at grunda.co/integritet.