Skip to content
Portalora
How it works Who it’s for Features Pricing Trust
Log in Get started

Legal

Privacy Policy

Version 1.1In force from 23 August 2026

This explains what personal data Portalora holds, why we hold it, who else touches it and what you can ask us to do with it. It is written to satisfy the GDPR, and to be readable by someone who has never heard of the GDPR.

What’s in here

  1. Who is responsible
  2. What we collect, and why
  3. Your site and the AI model
  4. Pictures you upload
  5. Cookies
  6. Visitors to your website
  7. Who else processes data
  8. Data outside the EU/EEA
  9. How long we keep things
  10. How we protect it
  11. Your rights
  12. Complaints
  13. Children
  14. Automated decisions
  15. Changes to this policy
  16. How to reach us

1. Who is responsible

The controller of the personal data described here is:

Company
Sverige Analytics AB
Registration number
559538-4917
Registered office
Umeå, Sweden (European Union)
Privacy contact
hello@portalora.com

We are not required to appoint a data protection officer and have not appointed one. Privacy questions go to the address above and are answered by us directly.

This policy covers the Portalora dashboard, portalora.com, and the websites we host for our customers. Section 6 explains the split of responsibility for people who visit a customer’s site.

2. What we collect, and why

We collect what the service needs to work, and we have kept the list short on purpose. There is no advertising network here, no analytics script, and nothing sold to anyone.

WhatWhy we have itLegal basis (GDPR Art. 6)
Your email address Identifies your account, receives the login code, and is how we reach you about your sites. Performance of a contract, Art. 6(1)(b)
Your password, stored only as a hash Lets you sign in. We never hold the password itself and cannot read it. Performance of a contract, Art. 6(1)(b)
Login codes and sessions, with the IP address and browser used Completes each sign-in, keeps you signed in, and lets you see and end sessions on other devices. Contract, Art. 6(1)(b); security, legitimate interest, Art. 6(1)(f)
The result of an email deliverability check at signup Turns away disposable and undeliverable addresses, so accounts are reachable and signup is not abused. Legitimate interest in preventing abuse, Art. 6(1)(f)
Your design brief, descriptions and change requests They are what the website is generated from, and they are kept so a later change can build on the last version. Performance of a contract, Art. 6(1)(b)
The generated files of your site, and its version history This is your website. The history lets you see what changed and go back. Performance of a contract, Art. 6(1)(b)
Pictures you upload Published on your site. See section 4. Performance of a contract, Art. 6(1)(b)
Your site’s address, and any custom domain you add Serving the site, and verifying that the domain is yours before we serve or certificate it. Performance of a contract, Art. 6(1)(b)
Build counts and the amount of AI processing used Enforces the fair-use limits, and tells us what the service costs to run. Legitimate interest in running the service sustainably, Art. 6(1)(f)
Server logs: request time, IP address, browser, page requested, errors Keeping the service up, finding faults, and detecting attacks and abuse. Legitimate interest in security and operation, Art. 6(1)(f)
Payment records, if you upgrade a site: what you paid, when, for which site, and the identifiers our payment provider gives us Taking the payment, running the monthly subscription, showing you your own payment history, and keeping the books. Contract, Art. 6(1)(b); legal obligation to keep accounts, Art. 6(1)(c)
Emails you send us Answering you, and keeping a record of what was agreed. Legitimate interest in handling enquiries, Art. 6(1)(f)

Where we rely on a legitimate interest, we have weighed it against your interests and rights. In every case above the processing is what a user would expect from a hosting service, is limited to what the purpose needs, and is not used to profile anyone. You can object to it — see section 11.

Your card number never reaches us. Payment details are entered on our payment provider’s own page, and what comes back to us is the result: paid or not, how much, and a reference. We could not charge you outside the subscription you agreed to even if we wanted to.

We do not ask for special categories of data — health, beliefs, ethnicity, political opinions and so on. If you choose to publish such data on your own site, you decide that, and section 6 applies.

3. Your site and the AI model

Generating a website means sending text to an AI model over the internet. Specifically:

  • On a first build we send your design brief — what the site is for, the look and colours you chose, the sections you want, the language, and the description you wrote.
  • On a change we send the current files of your site and the change you asked for, so the model can return only what needs to differ.
  • We do not send your email address, your account identity, or anything about you that is not part of the site being built. The credential we generate with is deliberately separate from any of our own accounts, so no personal context of ours is attached either.

The model provider is OpenAI, through its API. Under OpenAI’s API data-usage terms, content sent through the API is not used to train its models, and is retained only briefly for abuse monitoring before deletion.

The model has no access to our servers or filesystem. It returns file contents as data, and our own software writes the files, checking every path against a strict allowlist. A description written by one customer cannot affect another customer’s site.

Do not put personal data into a description that you would not publish. Everything you describe is intended to end up on a public web page, so treat the brief box as public writing.

4. Pictures you upload

Pictures are stored so they can be served on your site, which means they are public to anyone who has the address.

  • Every upload is decoded and re-encoded rather than stored as it arrived. That is a security measure — it guarantees the bytes we serve are ones we produced — and it has a privacy effect too: EXIF metadata, including GPS coordinates, camera serial numbers and timestamps, is dropped in the process and never reaches the web.
  • The stored filename is generated by us. Your original filename is kept only so the dashboard can show you which picture is which, and never appears in a URL.
  • If a picture shows an identifiable person, you are responsible for having the right to publish it. See section 6.
  • Deleting a picture in the dashboard removes the file from disk.

5. Cookies

The dashboard sets one cookie: a session cookie that keeps you signed in. It holds a random token, nothing about you, and it is strictly necessary for the service — so it needs no consent banner, and there is nothing for you to opt out of apart from not signing in. It is deleted when you log out, and expires on its own.

portalora.com sets no cookies at all. There is no analytics, no advertising pixel and no third-party script anywhere on this site or in the dashboard.

Websites we generate for customers get no cookies from us either. If a customer asks for something on their own site that sets one — an embedded video, a map, a booking widget — that is their choice and their responsibility to disclose.

6. Visitors to your website

If you are a Portalora customer, this is the part to read twice.

For the content of your own website, you are the controller and we are your processor. You decide what goes on the page — customer photographs, staff names, testimonials, an address, a phone number — and you are responsible for having the right to publish it, and for telling the people concerned what you do with their data. We process it only to host and serve it, on your instructions, which are the actions you take in the dashboard. This policy, together with our Terms of Service, is the agreement under Art. 28 GDPR for that processing. We will help you, at your cost only where the effort is unreasonable, to answer requests from people whose data is on your site.

For the technical delivery of the site we are the controller of the server logs described in section 2 — the request, its time, the IP address, the browser. We keep them to serve the site, keep it up and defend it against attack, and we do not build visitor profiles, do not track people between sites, and run no analytics.

If you publish personal data on your site, we recommend you put your own privacy notice on it. Portalora does not write one for you and cannot know what you collect offline.

7. Who else processes data

We keep the list of companies involved as short as we can. These are all of them:

WhoWhat they do for usWhat they seeWhere
Webdock ApS The server that runs Portalora, and the disks your sites and our database sit on. Everything stored, as the infrastructure it runs on. Denmark (EU)
Backblaze (B2 Cloud Storage) Holds our off-site backups, so a lost server does not mean a lost website. The backup archives: our database, and every site’s files and pictures. Stored in the EU (Amsterdam); the company itself is US-based
OpenAI Generates the websites. Design briefs, change requests and site files. Not your identity. United States
Resend Delivers our emails — login codes, account notices. Your email address and the contents of those emails. United States
Reoon Checks at signup that an address is real and not disposable. The email address being signed up. Outside the EU/EEA
Mollie B.V. Takes the payment when you upgrade a site, and runs the monthly subscription after it. Your email address, the amount, which site it is for, and the card or bank details you enter on their checkout page — those never reach us. Netherlands (EU)
Cloudflare DNS for our domains, and the proxy in front of portalora.com and the dashboard. Requests to those two hostnames, including IP addresses. Global network, EU included
Let’s Encrypt (ISRG) Issues the HTTPS certificates. Hostnames only — which become public in Certificate Transparency logs. United States

Each of them is bound by a data processing agreement that permits them to act only on our instructions. Beyond this list, we disclose personal data only where the law requires it — a court order, or a valid request from a Swedish or EU authority — or where it is necessary to establish or defend a legal claim. If Portalora were ever sold or merged, data would pass to the buyer under this same policy, and we would tell you before that happened.

We never sell personal data, and we never share it for advertising.

8. Data outside the EU/EEA

Your account, your sites, our database and our backups are all stored in the EU. Some of the providers in section 7 are established outside it — and Backblaze, though it stores our backups on European disks, is a US company that could be reached by US process. Either way that means a transfer under Chapter V of the GDPR.

Those transfers are made under the European Commission’s Standard Contractual Clauses, together with the additional safeguards we assess as necessary — data minimisation, encryption in transit, and short retention at the recipient. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that as well. You can ask us for a copy of the relevant safeguards at the address in section 16.

9. How long we keep things

WhatKept for
Account and email addressAs long as the account exists, then deleted when it is closed.
Login codesTen minutes, or until used — whichever is first.
SessionsUntil you log out or the session expires.
Sites, briefs and change requestsUntil you delete the site or close the account.
Version files on diskThe five most recent versions of each site.
PicturesUntil you delete them, or the site they belong to.
Database backups on the serverA rolling set of the ten most recent snapshots, then overwritten.
Off-site backupsHourly copies for about three days, and daily copies for thirty days, then overwritten.
Server logsRotated on the server; typically a few weeks.
Emails with usUp to two years after the conversation ends.
Records needed for accounting, if you ever pay usSeven years, as Swedish bookkeeping law requires.

When you delete a site, its files, its pictures and its web address go immediately. When an account is closed, its rows are deleted from the database; copies inside backup snapshots and off-site archives disappear as those are overwritten, within the periods in the table above. Payment records are the one exception: Swedish bookkeeping law requires us to keep them for seven years, so they outlive the account they belong to.

10. How we protect it

  • Everything travels over HTTPS. Your sites are served over HTTPS too, always.
  • Passwords are stored only as a slow, salted hash. Signing in also needs a fresh one-time code sent to your email, so a leaked password is not enough on its own.
  • Uploaded pictures are re-encoded before they are stored, so no file we did not produce is ever served from a customer’s domain.
  • The dashboard runs a strict Content Security Policy and CSRF protection on every form, and auth forms carry a proof-of-work check that runs entirely on our own server — no third-party captcha, and nothing about you sent to one.
  • Access to the server is limited to the people who operate the service, over key-based authentication.
  • Database snapshots are taken before every deployment.
  • Backups are copied off the server to separate storage in the EU on a schedule, and every upload is checked by reading it back rather than trusted to have worked.

No system is perfectly secure. If a breach ever puts your rights at risk, we will notify the Swedish Authority for Privacy Protection within 72 hours as Art. 33 requires, and tell you directly where Art. 34 requires it.

11. Your rights

Under the GDPR you can ask us to:

  • Show you what personal data we hold about you, and give you a copy (Art. 15).
  • Correct anything that is wrong or incomplete (Art. 16).
  • Delete your data — the right to be forgotten (Art. 17).
  • Restrict what we do with it while a dispute about it is resolved (Art. 18).
  • Hand it over in a portable, machine-readable form, to you or to another provider (Art. 20).
  • Stop processing based on a legitimate interest, by objecting to it (Art. 21). We then stop unless we have compelling grounds that override your interests.
  • Withdraw consent, where we ever relied on it, without affecting what was done before you withdrew it (Art. 7(3)).

Write to hello@portalora.com from the address on your account. We answer within one month, and tell you if a complex request needs longer, up to two further months. It costs nothing unless a request is manifestly unfounded or excessive. We may need to check that the request really comes from you before we act on it.

If the data you are asking about is on someone else’s Portalora site rather than your own, ask the owner of that site — they are the controller, and we act on their instructions. If you cannot reach them, write to us and we will pass it on.

12. Complaints

Tell us first if you can; we would rather fix it than have it escalate. But you have the right to complain to a supervisory authority at any time — ours is:

Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
imy.se

You may also complain to the authority in the EU country where you live or work.

13. Children

Portalora is not meant for children. You must be at least 16 to hold an account, and we do not knowingly collect data from anyone younger. If you believe a child has created an account, tell us and we will remove it.

14. Automated decisions

We do not make decisions with legal or similarly significant effects about you by purely automated means, and we do not profile you.

Two automated checks do exist, and neither is a decision about you as a person: the deliverability check on a signup address, and the automatic limits on builds and AI usage. If either turns you away and you think it is wrong, write to us and a person will look at it.

15. Changes to this policy

We update this policy when the service or the law changes. The current version and its date are always at the top of this page. If a change materially affects how we handle your data, we will email the address on your account before it takes effect.

16. How to reach us

Sverige Analytics AB

Registration number 559538-4917
Umeå, Sweden (European Union)

Privacy contact: hello@portalora.com

Version 1.1, in force from 23 August 2026. See also our Terms of Service.

Portalora

Websites you describe in plain language — built, hosted and looked after for you.

A Swedish company. Your site, its pictures and its backups stay in the EU.

Product

  • Features
  • Pricing
  • AI builder
  • How it works
  • Who it’s for
  • Questions

Company

  • Who we are
  • Where your data lives
  • Contact us

Account

  • Log in
  • Get started
  • Terms of Service
  • Privacy Policy

© 2026 Sverige Analytics AB · Org.nr 559538-4917 · Umeå, Sweden

hello@portalora.com