Privacy notice.
Plain language, because that's how we write. This notice covers personal data submitted through diadrom.com.
Reviewed by counsel · 16 August 2026 · analytics section revised 19 August · newsletter section revised 24 August · whistleblowing added 25 August
What we collect, and why
Enquiry form. Name, organisation, work email and the context you describe. We use it for one thing: responding to your enquiry — no marketing follows. Three further things are stored alongside it so the reply can start in the right place: the page you sent it from, the subject the link carried if it carried one, and where you arrived from — a page on this site, or the bare name of the site that linked you, never the full address. The enquiry is kept in our own database, on the same infrastructure as this site, so a message cannot be lost to a mislaid email. That database is created under Cloudflare's EU jurisdiction, which restricts where it runs and stores data to the European Union rather than merely preferring it.
The short question form. On our articles and product pages there is a smaller version asking only for your question and an email address. It reaches the same inbox and is recorded the same way; it exists so that one technical question does not require filling in a briefing.
Newsletter. Your work email, used for the newsletter and nothing else. Every issue has one-click unsubscribe. Two things are stored beside it: which page you subscribed from, and — if you arrived through a campaign link such as one posted on LinkedIn — the campaign parameters that link carried (utm_source, utm_medium, utm_campaign). They tell us which of our own posts is worth writing. They describe the link you followed, not you, and they are not combined with anything else we hold. Where the form asked you to tick a consent box, that you did so is recorded with the subscription.
Investor announcements. The subscription form on ourinvestor pages — on the overview, the press archive and every release — belongs to MFN (Modular Finance AB), who distribute our regulatory announcements. It is embedded in our page, but your address is submitted to them and the subscriber list is theirs — we never receive or store it. Their terms and privacy policy are linked inside the form, and you unsubscribe with them.
Job applications. Our careers site runs on Teamtailor and opens in a separate window. Anything you submit there is handled under Teamtailor's notice and our recruitment processing, not this one.
Whistleblowing reports. Our reporting channel is operated by Hailey HR and opens on their site. A report is submitted to them, not to us through this website, and nothing you write there passes through our servers or this notice — it is handled under our whistleblowing procedure. The page that links to it, /whistleblowing, deliberately carries no analytics: the measurement used on the rest of this site records outbound link clicks together with their destination, and a channel that depends on reporting being safe should not log who reached for it.
Analytics. We count page views with Plausible, so we can see which articles are read and which pages fail people. It sets no cookies, does not fingerprint your browser, and does not follow you to any other site. What it records is the page, the site that linked you if one did, and a coarse reading of browser, device type and country. None of it identifies you, and none of it is combined with anything else we hold.
One detail we would rather state than gloss over: the script reads a single value from your browser's local storage on each page view, named plausible_ignore. It is the mechanism that lets us keep our own visits out of the figures. Nothing is written there, and no identifier is stored or read — but it is a read from your device, so we say so rather than describe the measurement as touching nothing at all. There is no tag manager and there are no advertising scripts.
Tracking, only if you accept it. Separately from the counting above, we can link the pages you read to your newsletter subscription, so that what we send you follows what you actually care about rather than going to everyone. This is the one thing on this site that puts cookies on your device — three of them, named sib_cuid,sib_name and sib_type, set by Brevo — and it is also the one thing that connects browsing to a named person rather than to a count. It is off until you say yes. If you decline, or simply leave the question alone, nothing loads and no cookie is set.
The legal basis is your consent, asked for before anything runs rather than after. You can withdraw it whenever you like, and it should be no harder than giving it was:
Done. The cookies are deleted and tracking has stopped.
Withdrawing stops the tracking from that moment. It does not make what happened before unlawful, and it does not reach back into what Brevo already recorded — for that, ask us to erase it and we will.
Keeping the forms usable. When a form is submitted we read the IP address the request arrives with and use it to count submissions, so that one connection cannot flood the forms. The address is used for that count and nothing else — it is not stored with your message and never reaches Brevo.
Server logs. Cloudflare records the ordinary request data every website visit produces — address requested, time, IP, browser. We deliberately keep personal data out of what our own code writes there: when a submission fails we log the error code, never the message or the address.
Press-release images. Our press pages reproduce announcements as MFN distributes them, and any images in them are served from MFN's own servers. Opening such a page therefore tells MFN your IP address and browser, before you interact with anything. The pages themselves, and every other image on this site, come from us.
Where it lives, and who processes it
The services that touch personal data on our behalf are Brevo, which sends the reply to your enquiry and runs the newsletter; Cloudflare, which hosts and delivers this site and therefore processes the request data every visit produces; Plausible, which counts page views; MFN for investor subscriptions and for the images in press releases; Teamtailor for recruitment; and Hailey HR for whistleblowing reports. Brevo is a French company and states that it stores customer data in the EU. Cloudflare serves this site over a global network, so transfers outside the EU are part of how it is delivered. We keep enquiries only as long as the dialogue — and any engagement that follows — requires.
What we never do
We don't sell personal data. An enquiry does not put you on the newsletter and does not feed the tracking described above — those are separate things you opt into separately, and writing to us is not one of them. And we ask you not to include classified, export-controlled or otherwise sensitive information in the form — that conversation belongs in a proper channel, which we'll gladly set up.
Your rights & contact
You can request access to, correction of or deletion of your personal data at any time. Write to viktor.eliasson@diadrom.se, or to Diadrom Holding AB (publ), Första Långgatan 17, 413 27 Göteborg, Sweden.