1. Personal Data Responsibility and Basis for Processing

This Privacy Notice applies when LegalWorks Nordic AB ("LegalWorks," "we," "our," "us"), business registration number 559046-3922, located at Olof Palmes gata 11, 111 37 Stockholm, Sweden, processes personal data relating to individuals using LegalWorks services ("you," "your"). LegalWorks's processing of personal data complies with the General Data Protection Regulation (EU) 2016/679 ("GDPR").

This Privacy Notice applies to representatives of our customers, visitors to our website, and potential customers (prospects) who contact us or whose contact details we receive in the course of our business activities. In relation to the processing described in this Privacy Notice, LegalWorks acts as an independent controller. We do not process personal data as a processor on behalf of our customers under this Privacy Notice.

Processing of personal data when using LegalWorks services is based on an agreement with the company that you, the data subject, represent. Other instances include when you submit a contact request through our website or subscribe to our newsletter. We may also process your personal data if, we believe, the company you represent may be interested in our services. Additionally, we process personal data to comply with legal obligations under applicable laws and governmental decisions. We collect personal data directly from you or from the company you represent, for example when you contact us, enter into an agreement with us or are specified as a contact person in that agreement. We may also collect your contact details from publicly available sources, such as the website of the company you represent or public company registers. Additionally, during a recruitment or an application for a consultant service, we may collect information about you from the references that you have provided.

2. Personal data processed

Personal data refers to any information that can be directly or indirectly linked to a living person. LegalWorks collects and processes various types of personal data within the scope of its activities.

The following personal data LegalWorks may collect from you:

  • Identification details – e.g. first and  last name.
  • Contact details - e.g. address, email address, phone number and job title.
  • Payment information - e.g. Data necessary for payments, invoicing, or financial transactions with LegalWorks.
  • Social media activity - e.g. information on interactions with us via social media.
  • Employment related information – e.g. employment history, educational or professional background, job title and function, or other personal data concerning your preferences relevant for recruitment services.
  • Information given in surveys, including contact information, career information, work related preferences and other subject related information.

Additionally, we collect information about the organization you belong to and its contact details.

3. The purposes of the processing

LegalWorks processes your personal data for the following purposes:

  • To maintain adequate records of you.
  • To provide, administer and correspond legal services or other services or solutions.
  • To fulfil contractual obligations.
  • To provide services and communicate with you.
  • To send information about our activities.
  • To handle inquiries and complaints.
  • To administer and manage our relationship with you as a recruit in our recruitment and interim service.
  • To facilitate invoicing.
  • To comply with legal obligations imposed by authorities and applicable laws.

We may also market our services through third‑party platforms, such as LinkedIn, X (Twitter) and similar websites. In such cases, those platforms are responsible for their own processing of personal data in accordance with their privacy policies.

For detailed information on the purposes and legal basis for processing, please refer to the table below.

4. Retention of personal data

Personal data is retained as long as necessary to fulfil the specified purposes. Most personal data is automatically deleted after the statutory retention period following contract termination.

For instance, under the Swedish Accounting Act, LegalWorks is required to retain specific personal data (e.g., invoices and accounting documents) for seven years. Such data will only be used for accounting purposes.

Customer-related data is retained while you are considered a LegalWorks customer. After contract termination, most of your data will be deleted unless retention is required for other purposes. Certain data, such as identity and contact details, will be kept for 36 months for marketing purposes.

If you contact us on behalf of a company that does not become a customer, your identity and contact details will be stored for up to 12 months from our last interaction for the purpose of following up on your request and offering our services. After that period, your personal data will be deleted or anonymised.

For full details on data retention periods, see the table below.

5. Deletion of personal data

Personal data will be deleted or anonymized when it is no longer necessary for retention. Once deletion is executed, it cannot be reversed, and no individual can be linked to the remaining information.

Purpose Legal basis Categories of personal data Storage time
Customer management Agreement
  • Identification details
  • Contact details
As long as you are a customer.
Managing enquiries from potential customers (prospects) who do not enter into an agreement with us Legitimate interest
  • Identification details
  • Contact details
Maximum 12 months from the last interaction with you or the company you represent.
To abide to laws and regulations Legal obligation
  • Identification details
  • Contact details
  • Payment information
As long as we are obliged to store the data according to applicable law or government decision, such as 7 years in accordance with the Swedish Accounting Act.
Social media marketing Legitimate interest
  • Information on identity
  • Contact details
  • Social media activity
Maximum 36 months after you ceased to be considered a customer of ours or you attended a webinar organized by us.
Marketing by letter, telephone or e-mail. Legitimate interest
  • Identification details
  • Contact details
Maximum 36 months after you ceased to be considered a customer of ours or you attended a webinar organized by us.

You can opt out of marketing at any time by contacting us at info@legalworks.se
Manage registrations for, follow-up after and development of our webinars Legitimate interest
  • Information on identity
  • Contact details
36 months after webinar was held.
Recruiting or providing opportunities for consultant services Legitimate interest
  • Information on identity
  • Contact details
  • Information on education, employment and other employment related information
Maximum 36 months after you ceased to be considered a consultant of ours or the recruitment was finalised.
Investigate any complaints Legitimate interest
  • Identification details
  • Contact details
12 months after the end of the customer relationship.
Preventing and investigating possible fraud Legitimate interest
  • Identification details
  • Contact details
  • Payment information
12 months after the end of the customer relationship.

6. Recipients of personal data

LegalWorks collaborates with various companies, including partners and suppliers. As a result, we may share your personal data with third parties when necessary. The following types of recipients may process your data:

  • Notification services - Used for communication (e.g. marketing e-mails). These services only access your contact details and are contractually bound to maintain confidentiality.
  • Authorities - LegalWorks may be legally required to disclose information to authorities. In some cases, we may be prohibited from informing you about such disclosures.

LegalWorks primarily processes data within the EU/EEA. If we, in the future, use service providers established outside the EU/EEA or if data is transferred outside this region for any other reason, we will ensure that appropriate safeguards are in place, such as an adequacy decision by the European Commission or standard contractual clauses.


7. Information Security

As a data controller, LegalWorks implements appropriate technical and organizational measures to safeguard personal data, adhering to GDPR regulations. We maintain internal policies and procedures to address security risks and prevent unauthorized access or leaks.

In the event of a security breach (a "personal data breach"), we may contact you in accordance with Article 34 of the GDPR.

8. Your Rights

You have the following rights regarding our processing of your personal data:

  • Right to Restrict Processing:
    You may request that processing be limited to storage or object to certain processing activities. For instance, you may choose to unsubscribe from newsletters and other mailings by following a link in these mailings or by sending an e-mail to info@legalworks.se.
  • Right to Object:
    You may object to processing based on legitimate interests or for direct marketing purposes. Contact us at info@legalworks.se.
  • Right of Access:
    You may request a record of how your data is processed, which will be provided within one month. Request this by emailing info@legalworks.se.
  • Right to Rectification:
    You may request corrections to inaccurate personal data or add missing details. Contact us at info@legalworks.se.
  • Right to Data Portability:
    You can request the transfer of your data to another company or yourself, except for legally retained data. Email info@legalworks.se.
  • Right to Erasure:
    You may request deletion of personal data not required for legal compliance or certain other activities such as contractual obligations. Email info@legalworks.se.

If you believe we are not complying with this privacy policy, we encourage you to contact us at info@legalworks.se. You also have the right to file a complaint with the Swedish Data Protection Authority (www.imy.se).

This Privacy Notice was last updated on XX January 2026