Legal
Privacy Policy
This explains what personal data Portalora holds, why we hold it, who else touches it and what you can ask us to do with it. It is written to satisfy the GDPR, and to be readable by someone who has never heard of the GDPR.
1. Who is responsible
The controller of the personal data described here is:
- Company
- Sverige Analytics AB
- Registration number
- 559538-4917
- Registered office
- Umeå, Sweden (European Union)
- Privacy contact
- hello@portalora.com
We are not required to appoint a data protection officer and have not appointed one. Privacy questions go to the address above and are answered by us directly.
This policy covers the Portalora dashboard, portalora.com, and the websites we host for our customers. Section 6 explains the split of responsibility for people who visit a customer’s site.
2. What we collect, and why
We collect what the service needs to work, and we have kept the list short on purpose. There is no advertising network here, no analytics script, and nothing sold to anyone.
| What | Why we have it | Legal basis (GDPR Art. 6) |
|---|---|---|
| Your email address | Identifies your account, receives the login code, and is how we reach you about your sites. | Performance of a contract, Art. 6(1)(b) |
| Your password, stored only as a hash | Lets you sign in. We never hold the password itself and cannot read it. | Performance of a contract, Art. 6(1)(b) |
| Login codes and sessions, with the IP address and browser used | Completes each sign-in, keeps you signed in, and lets you see and end sessions on other devices. | Contract, Art. 6(1)(b); security, legitimate interest, Art. 6(1)(f) |
| The result of an email deliverability check at signup | Turns away disposable and undeliverable addresses, so accounts are reachable and signup is not abused. | Legitimate interest in preventing abuse, Art. 6(1)(f) |
| Your design brief, descriptions and change requests | They are what the website is generated from, and they are kept so a later change can build on the last version. | Performance of a contract, Art. 6(1)(b) |
| The generated files of your site, and its version history | This is your website. The history lets you see what changed and go back. | Performance of a contract, Art. 6(1)(b) |
| Pictures you upload | Published on your site. See section 4. | Performance of a contract, Art. 6(1)(b) |
| Your site’s address, and any custom domain you add | Serving the site, and verifying that the domain is yours before we serve or certificate it. | Performance of a contract, Art. 6(1)(b) |
| Build counts and the amount of AI processing used | Enforces the fair-use limits, and tells us what the service costs to run. | Legitimate interest in running the service sustainably, Art. 6(1)(f) |
| Server logs: request time, IP address, browser, page requested, errors | Keeping the service up, finding faults, and detecting attacks and abuse. | Legitimate interest in security and operation, Art. 6(1)(f) |
| Payment records, if you upgrade a site: what you paid, when, for which site, and the identifiers our payment provider gives us | Taking the payment, running the monthly subscription, showing you your own payment history, and keeping the books. | Contract, Art. 6(1)(b); legal obligation to keep accounts, Art. 6(1)(c) |
| Emails you send us | Answering you, and keeping a record of what was agreed. | Legitimate interest in handling enquiries, Art. 6(1)(f) |
Where we rely on a legitimate interest, we have weighed it against your interests and rights. In every case above the processing is what a user would expect from a hosting service, is limited to what the purpose needs, and is not used to profile anyone. You can object to it — see section 11.
Your card number never reaches us. Payment details are entered on our payment provider’s own page, and what comes back to us is the result: paid or not, how much, and a reference. We could not charge you outside the subscription you agreed to even if we wanted to.
We do not ask for special categories of data — health, beliefs, ethnicity, political opinions and so on. If you choose to publish such data on your own site, you decide that, and section 6 applies.
3. Your site and the AI model
Generating a website means sending text to an AI model over the internet. Specifically:
- On a first build we send your design brief — what the site is for, the look and colours you chose, the sections you want, the language, and the description you wrote.
- On a change we send the current files of your site and the change you asked for, so the model can return only what needs to differ.
- We do not send your email address, your account identity, or anything about you that is not part of the site being built. The credential we generate with is deliberately separate from any of our own accounts, so no personal context of ours is attached either.
The model provider is OpenAI, through its API. Under OpenAI’s API data-usage terms, content sent through the API is not used to train its models, and is retained only briefly for abuse monitoring before deletion.
The model has no access to our servers or filesystem. It returns file contents as data, and our own software writes the files, checking every path against a strict allowlist. A description written by one customer cannot affect another customer’s site.
Do not put personal data into a description that you would not publish. Everything you describe is intended to end up on a public web page, so treat the brief box as public writing.
4. Pictures you upload
Pictures are stored so they can be served on your site, which means they are public to anyone who has the address.
- Every upload is decoded and re-encoded rather than stored as it arrived. That is a security measure — it guarantees the bytes we serve are ones we produced — and it has a privacy effect too: EXIF metadata, including GPS coordinates, camera serial numbers and timestamps, is dropped in the process and never reaches the web.
- The stored filename is generated by us. Your original filename is kept only so the dashboard can show you which picture is which, and never appears in a URL.
- If a picture shows an identifiable person, you are responsible for having the right to publish it. See section 6.
- Deleting a picture in the dashboard removes the file from disk.
6. Visitors to your website
If you are a Portalora customer, this is the part to read twice.
For the content of your own website, you are the controller and we are your processor. You decide what goes on the page — customer photographs, staff names, testimonials, an address, a phone number — and you are responsible for having the right to publish it, and for telling the people concerned what you do with their data. We process it only to host and serve it, on your instructions, which are the actions you take in the dashboard. This policy, together with our Terms of Service, is the agreement under Art. 28 GDPR for that processing. We will help you, at your cost only where the effort is unreasonable, to answer requests from people whose data is on your site.
For the technical delivery of the site we are the controller of the server logs described in section 2 — the request, its time, the IP address, the browser. We keep them to serve the site, keep it up and defend it against attack, and we do not build visitor profiles, do not track people between sites, and run no analytics.
If you publish personal data on your site, we recommend you put your own privacy notice on it. Portalora does not write one for you and cannot know what you collect offline.
7. Who else processes data
We keep the list of companies involved as short as we can. These are all of them:
| Who | What they do for us | What they see | Where |
|---|---|---|---|
| Webdock ApS | The server that runs Portalora, and the disks your sites and our database sit on. | Everything stored, as the infrastructure it runs on. | Denmark (EU) |
| Backblaze (B2 Cloud Storage) | Holds our off-site backups, so a lost server does not mean a lost website. | The backup archives: our database, and every site’s files and pictures. | Stored in the EU (Amsterdam); the company itself is US-based |
| OpenAI | Generates the websites. | Design briefs, change requests and site files. Not your identity. | United States |
| Resend | Delivers our emails — login codes, account notices. | Your email address and the contents of those emails. | United States |
| Reoon | Checks at signup that an address is real and not disposable. | The email address being signed up. | Outside the EU/EEA |
| Mollie B.V. | Takes the payment when you upgrade a site, and runs the monthly subscription after it. | Your email address, the amount, which site it is for, and the card or bank details you enter on their checkout page — those never reach us. | Netherlands (EU) |
| Cloudflare | DNS for our domains, and the proxy in front of portalora.com and the dashboard. | Requests to those two hostnames, including IP addresses. | Global network, EU included |
| Let’s Encrypt (ISRG) | Issues the HTTPS certificates. | Hostnames only — which become public in Certificate Transparency logs. | United States |
Each of them is bound by a data processing agreement that permits them to act only on our instructions. Beyond this list, we disclose personal data only where the law requires it — a court order, or a valid request from a Swedish or EU authority — or where it is necessary to establish or defend a legal claim. If Portalora were ever sold or merged, data would pass to the buyer under this same policy, and we would tell you before that happened.
We never sell personal data, and we never share it for advertising.
8. Data outside the EU/EEA
Your account, your sites, our database and our backups are all stored in the EU. Some of the providers in section 7 are established outside it — and Backblaze, though it stores our backups on European disks, is a US company that could be reached by US process. Either way that means a transfer under Chapter V of the GDPR.
Those transfers are made under the European Commission’s Standard Contractual Clauses, together with the additional safeguards we assess as necessary — data minimisation, encryption in transit, and short retention at the recipient. Where a provider is certified under the EU–US Data Privacy Framework, we rely on that as well. You can ask us for a copy of the relevant safeguards at the address in section 16.
9. How long we keep things
| What | Kept for |
|---|---|
| Account and email address | As long as the account exists, then deleted when it is closed. |
| Login codes | Ten minutes, or until used — whichever is first. |
| Sessions | Until you log out or the session expires. |
| Sites, briefs and change requests | Until you delete the site or close the account. |
| Version files on disk | The five most recent versions of each site. |
| Pictures | Until you delete them, or the site they belong to. |
| Database backups on the server | A rolling set of the ten most recent snapshots, then overwritten. |
| Off-site backups | Hourly copies for about three days, and daily copies for thirty days, then overwritten. |
| Server logs | Rotated on the server; typically a few weeks. |
| Emails with us | Up to two years after the conversation ends. |
| Records needed for accounting, if you ever pay us | Seven years, as Swedish bookkeeping law requires. |
When you delete a site, its files, its pictures and its web address go immediately. When an account is closed, its rows are deleted from the database; copies inside backup snapshots and off-site archives disappear as those are overwritten, within the periods in the table above. Payment records are the one exception: Swedish bookkeeping law requires us to keep them for seven years, so they outlive the account they belong to.
10. How we protect it
- Everything travels over HTTPS. Your sites are served over HTTPS too, always.
- Passwords are stored only as a slow, salted hash. Signing in also needs a fresh one-time code sent to your email, so a leaked password is not enough on its own.
- Uploaded pictures are re-encoded before they are stored, so no file we did not produce is ever served from a customer’s domain.
- The dashboard runs a strict Content Security Policy and CSRF protection on every form, and auth forms carry a proof-of-work check that runs entirely on our own server — no third-party captcha, and nothing about you sent to one.
- Access to the server is limited to the people who operate the service, over key-based authentication.
- Database snapshots are taken before every deployment.
- Backups are copied off the server to separate storage in the EU on a schedule, and every upload is checked by reading it back rather than trusted to have worked.
No system is perfectly secure. If a breach ever puts your rights at risk, we will notify the Swedish Authority for Privacy Protection within 72 hours as Art. 33 requires, and tell you directly where Art. 34 requires it.
11. Your rights
Under the GDPR you can ask us to:
- Show you what personal data we hold about you, and give you a copy (Art. 15).
- Correct anything that is wrong or incomplete (Art. 16).
- Delete your data — the right to be forgotten (Art. 17).
- Restrict what we do with it while a dispute about it is resolved (Art. 18).
- Hand it over in a portable, machine-readable form, to you or to another provider (Art. 20).
- Stop processing based on a legitimate interest, by objecting to it (Art. 21). We then stop unless we have compelling grounds that override your interests.
- Withdraw consent, where we ever relied on it, without affecting what was done before you withdrew it (Art. 7(3)).
Write to hello@portalora.com from the address on your account. We answer within one month, and tell you if a complex request needs longer, up to two further months. It costs nothing unless a request is manifestly unfounded or excessive. We may need to check that the request really comes from you before we act on it.
If the data you are asking about is on someone else’s Portalora site rather than your own, ask the owner of that site — they are the controller, and we act on their instructions. If you cannot reach them, write to us and we will pass it on.
12. Complaints
Tell us first if you can; we would rather fix it than have it escalate. But you have the right to complain to a supervisory authority at any time — ours is:
Integritetsskyddsmyndigheten (IMY)
Box 8114, 104 20 Stockholm, Sweden
imy.se
You may also complain to the authority in the EU country where you live or work.
13. Children
Portalora is not meant for children. You must be at least 16 to hold an account, and we do not knowingly collect data from anyone younger. If you believe a child has created an account, tell us and we will remove it.
14. Automated decisions
We do not make decisions with legal or similarly significant effects about you by purely automated means, and we do not profile you.
Two automated checks do exist, and neither is a decision about you as a person: the deliverability check on a signup address, and the automatic limits on builds and AI usage. If either turns you away and you think it is wrong, write to us and a person will look at it.
15. Changes to this policy
We update this policy when the service or the law changes. The current version and its date are always at the top of this page. If a change materially affects how we handle your data, we will email the address on your account before it takes effect.
16. How to reach us
Sverige Analytics AB
Registration number 559538-4917
Umeå, Sweden (European Union)
Privacy contact: hello@portalora.com
Version 1.1, in force from 23 August 2026. See also our Terms of Service.