Privacy Policy for Sambokoll
Effective as of 18 August 2026
See also: Terms of Service
This policy describes how Rendly AB processes personal data in Sambokoll. Your use of the service is governed by the terms of service.
1. Data controller
Rendly AB, corporate registration number 559569-5577, is the data controller for the processing of personal data in Sambokoll.
- Postal address: Storängsparken 9C, 614 32 Söderköping, Sweden
- Privacy questions and rights requests: privacy@rendly.se
- Support: support@rendly.se
When you create an account you confirm that you have read the policy. The confirmation is not a general consent to all processing of personal data. When consent is needed, for example for marketing, we ask separately.
2. Data we process
We may process the following data:
- Account and contact: email address, display name and account status information.
- Household: household name, memberships, invitations, roles and data that household members share with each other.
- Finances and content: budgets, income, expenses, cost sharing, balances, savings, savings goals, loans, assets, categories, notes and other data you enter yourself.
- Imports: files and transaction data from bank statements in, for example, CSV or Excel format, such as date, amount, description and category.
- Calculations: settings, assumptions and results from, among other things, forecasts and FIRE simulations.
- Login and technical data: one-time links and other necessary authentication information, IP address, login timestamps, device and browser information, and technical logs.
- Usage: which features are used, changes, exports and other events in the service.
- Communication: support messages, feedback and other contact with Rendly AB.
- Payment: subscription, price, invoicing details, payment status and limited information about the payment method. Full card details are to be processed by the payment service provider stated at the time of payment and are not stored by Rendly AB.
- Marketing: email address, consent, mailings and opt-ins/opt-outs.
Financial data is normally not a special category of personal data under the GDPR, but it is private and worthy of protection. A transaction description can sometimes indirectly reveal, for example, health, religion or trade-union membership. Sambokoll is not intended for such data. Avoid importing or entering sensitive data that is not needed, and delete or edit it when possible.
3. Where the data comes from
Data is provided by you, created when you use the service, or provided by another member who invites you or registers data in your household. Technical data is created automatically when the service is used.
An email address and the necessary login data are required to create and use an account. Financial data is voluntary, but some features cannot be used without it. Marketing is always voluntary.
4. Why we process data
| Purpose | Examples of data | Legal basis |
|---|---|---|
| Create accounts, send login links and provide Sambokoll's features. | Account, household, financial, content, import, calculation and usage data. | Performance of a contract, Article 6(1)(b) GDPR. |
| Display and synchronise shared information for the members of a household. | Household, financial, transaction and calculation data. | Performance of a contract, Article 6(1)(b). |
| Protect accounts, prevent abuse, troubleshoot and maintain operations and security. | IP address, logins, technical logs and relevant usage data. | Legitimate interest in a secure and functioning service, Article 6(1)(f). |
| Answer support requests, send necessary messages and handle feedback. | Account, contact, support and, where needed, technical data. | Performance of a contract, Article 6(1)(b), and legitimate interest in customer service and product development, Article 6(1)(f). |
| Manage trial periods, subscriptions, payment, bookkeeping and legal requirements. | Contact, subscription, invoicing and payment data. | Performance of a contract, Article 6(1)(b), and legal obligation, Article 6(1)(c). |
| Produce aggregate statistics and improve the service. | Limited technical and usage-related data, preferably aggregated or de-identified. | Legitimate interest in understanding, developing and improving the service, Article 6(1)(f). |
| Send newsletters and marketing when you have voluntarily signed up. | Email address, consent and mailing data. | Consent, Article 6(1)(a). |
When we rely on legitimate interest, we weigh Rendly AB's needs against your right to privacy and limit the processing to what is necessary. You have the right to object.
5. Sharing within the household
Data entered into a shared household becomes available to the members who have access to the household. The other members are recipients of the data and can use information you share. Therefore, check who the members are and do not enter data you do not want to share.
Rendly AB is responsible for the service's processing, but cannot control how another private individual uses information that person has already gained access to outside Sambokoll.
6. Cookies
Sambokoll uses cookies or equivalent local storage that are necessary for, among other things, login, session management, security and basic functionality. They are not used for behavioural advertising or cross-site tracking. Necessary technologies cannot be turned off without parts of the service ceasing to work.
If we introduce non-necessary cookies or similar tracking, we will inform you about them and obtain consent before they are used.
7. Recipients and suppliers
Only people at Rendly AB who need the data for their work have access to it. We do not sell personal data.
The following categories of recipients may process data on our behalf:
- Neon, LLC/Databricks, Inc. for the database, storage, backups and related technical services.
- Deno Land Inc. through Deno Deploy for application hosting, delivery of the service, networking and technical logs.
- Suppliers for necessary emails, support, error reporting and operational monitoring.
- Payment service, invoicing and accounting providers when payment is used.
Data may also be disclosed to authorities, courts or advisers when required by law or needed to establish, exercise or defend legal claims. We enter into data processing agreements when a supplier processes personal data on our behalf.
8. Transfers to the United States and other countries
Unlike a service operated solely within the EU, Sambokoll uses US suppliers:
- The database is provided by Neon, LLC, which is a US company and part of the US company Databricks, Inc.
- The application runs on Deno Deploy, provided by the US company Deno Land Inc. Deno Deploy is a globally distributed platform.
This means that personal data may be stored or processed in, transferred to, or accessed from the United States and, depending on the suppliers' infrastructure and subcontractors, other countries outside the EU/EEA. This may include content in the database as well as IP addresses, request data, authentication data and technical logs.
For transfers to the United States, Rendly AB uses a valid basis under Chapter V of the GDPR:
- For Neon/Databricks, the transfer may rely on the European Commission's adequacy decision under the EU–U.S. Data Privacy Framework, as long as the receiving entity's certification is active and covers the processing.
- For Deno and other recipients not covered by an applicable adequacy decision, the transfer is protected by the supplier's data processing agreement, the European Commission's standard contractual clauses and, where needed, supplementary technical and organisational measures.
US legislation may in some cases give US authorities the right to request access to data. Rendly AB therefore limits which data the suppliers may process and uses contractual and technical safeguards.
You can contact privacy@rendly.se for information about the mechanism used for a particular supplier and to obtain a copy of the relevant safeguards, subject to the limitations needed to protect trade secrets and security.
9. Retention periods
Accounts, households and financial content are kept while the account is active or until the data, the household or the account is deleted.
If no login or other activity has taken place for twelve months, we send one or more warnings by email. The account and its content are deleted no later than one month after the last warning if the account is still inactive.
When an account is deleted, the data is removed from the active service without undue delay. Copies may remain in protected backups for at most twelve months. They are only used for restoration, and a previously requested deletion will be carried out again if a backup is restored.
- Technical logs are kept for at most twelve months.
- Closed support cases are kept for at most twelve months.
- Marketing data is kept until you withdraw your consent or the data is no longer needed. Limited information may be retained to honour an opt-out.
- Accounting records, for example invoice documentation, are kept for seven years after the end of the calendar year in which the relevant financial year ended, in accordance with the Swedish Bookkeeping Act.
Some data may be kept longer if required by law or needed to establish, exercise or defend legal claims. In that case, only the data needed for that purpose is kept.
If a household has several members, deletion of your own account may need to be separated from deletion of the household's shared content. Before deletion, we show or explain what is removed and what remains for other members.
10. Necessary messages and marketing
We send necessary messages about, for example, login, security, your account, support, payment, operations and planned deletion. They are part of the service and do not require marketing consent.
Newsletters and marketing are sent only after a voluntary and separate sign-up, or when another legal basis exists under applicable marketing rules. You can unsubscribe at any time via the link in the mailing or by contacting privacy@rendly.se.
11. Security
We use technical and organisational measures to protect data against unauthorised access, loss, alteration and dissemination. The measures include, among other things, encrypted transmission, access control, logging, backups and restricted access for staff and suppliers.
No internet-based service is entirely risk-free. Therefore, protect your email, do not share login links, and do not enter security codes, bank passwords or full card details.
12. Automation and profiling
Sambokoll can automatically categorise transactions and calculate budget outcomes, cost sharing, forecasts and FIRE simulations. The results are used as information for you and your household.
Rendly AB does not use personal data for automated decisions under Article 22 GDPR that have legal or similarly significant consequences for you. Nor do we use financial data for advertising profiles.
13. Your rights
Depending on the circumstances, you have the right to:
- receive information about, and access to, the personal data we process about you
- have inaccurate or incomplete data corrected
- request deletion or restriction of the processing
- object to processing based on legitimate interest, and always object to direct marketing
- receive certain data in a structured, commonly used and machine-readable format
- withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal
These rights are not absolute. For example, we may need to keep invoice documentation under the Swedish Bookkeeping Act, or certain data to handle legal claims. We may need to verify your identity before carrying out a request.
Contact privacy@rendly.se to exercise your rights. We normally respond within one month.
If you believe we are processing your data incorrectly, you can lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY). You are welcome to contact us first so that we can try to resolve the matter.
14. Changes to the policy
We may update the policy when the service, the suppliers or the processing changes. The current version will always be available in Sambokoll. In the event of material changes, we will inform you in the service or by email before the change takes effect, when appropriate or required by law.