| Field | Value |
|---|---|
| Version | v1.2 |
| Effective | 2026-08-02 |
| Last updated | 2026-08-02 |
| Controller | Millijoin AB (org. nr. 559069-3593), trading as EVERTIN |
| Contact | privacy@evertin.com |
Postal contact: Millijoin AB Mariestadsvägen 3 121 50 Johanneshov Sweden
1. Who we are
This Privacy Policy explains how Millijoin AB ("we", "us", "Millijoin"), a Swedish Aktiebolag (org-nr 559069-3593, registered office at Mariestadsvägen 3, 121 50 Johanneshov, Sweden), collects and uses personal data when you:
- visit our marketing website at evertin.com;
- sign in to the EVERTIN platform as a brand administrator to manage your flagship store; or
- use the EVERTIN app for iOS, or the same platform in a web browser, as a member of a brand's space.
EVERTIN is the multi-tenant platform we operate — a network of digital flagship stores for e-commerce brands. The legal entity that controls your personal data is Millijoin AB.
Note on end-shoppers. If you are a shopper buying from a brand's flagship store on EVERTIN, the brand you are buying from is the data controller for your shopper data, and Millijoin acts as a processor on the brand's behalf. The brand's own privacy policy governs that relationship. Brand administrators accept a controller-processor data processing agreement at signup that governs Millijoin's processing on their behalf; enterprise brands may sign an out-of-band DPA on request via privacy@evertin.com. This document covers the personal data that Millijoin controls directly.
2. What personal data we collect, why, and on what lawful basis
We apply data minimization — we collect the smallest dataset that lets us run the service — and purpose limitation — we only use data for the purpose it was collected for. Each processing activity below names its lawful basis under GDPR Article 6.
2.1 Visitors to evertin.com (marketing site)
| Data | Purpose | Lawful basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| IP address, user-agent, referrer, pages viewed | Operate the site, protect against abuse, basic traffic measurement | Legitimate interest (Art. 6(1)(f)) | 30 days in server logs |
| Strictly necessary cookies (session, CSRF) | Make the site work | Legitimate interest (Art. 6(1)(f)) — exempt from consent under ePrivacy | Session |
| Email address you submit in a contact / waitlist form | Reply to your enquiry; add to waitlist if you opted in | Legitimate interest (enquiry); consent (Art. 6(1)(a)) for waitlist | 24 months after last contact, then deleted |
We do not run analytics, marketing tracking, or non-essential cookies at v1 GA. See §7.
2.2 Brand administrators (EVERTIN customers)
When a brand signs up to use EVERTIN to operate a flagship store, the named brand administrator(s) become our direct customers.
| Data | Purpose | Lawful basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| Name, work email, brand name, role | Create your account, identify you when you sign in | Contract (Art. 6(1)(b)) | Duration of the contract + 12 months |
| Authentication metadata (login times, IP at login, device) | Account security, audit trail, abuse detection | Legitimate interest (Art. 6(1)(f)) | 12 months |
| Billing details (company name, VAT, billing email, payment metadata) | Invoice you, collect payment, meet bookkeeping obligations | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for bookkeeping | 7 years (Swedish Bokföringslagen) |
| Content you create in the admin (store configuration, copy, uploads) | Provide the service | Contract (Art. 6(1)(b)) | Duration of the contract + 30 days, then deleted |
| Support emails / messages | Resolve your support requests | Legitimate interest (Art. 6(1)(f)) | 24 months after the request is closed |
2.3 AI-assisted features
EVERTIN uses Anthropic Claude, reached through Vercel's AI Gateway, for a set of features inside the platform. Prompts we send and the outputs returned are processed by those providers on our instructions.
Where AI runs, and what we send:
| Feature | What we send | Who sees the output |
|---|---|---|
| Drafting help for brand administrators (posts, replies, on-brand copy) | The prompt and whatever context the admin chooses to include | The admin who asked |
| Community health and sentiment summaries | A capped, trimmed sample of recent message text from the brand's community, and the brand's name | The brand's administrators, as an aggregate summary — never as a per-person score shown to other members |
| Automatic brand-voice posts | The brand's own configured voice and context — not member messages | Everyone in that channel |
| AI replies in a direct message, where the brand has turned that on | The messages in that conversation | You and the brand's administrators |
| Scoring an application to join a brand's programme | The answers and uploads you submitted in that application form | The brand's administrators |
- Lawful basis: Contract (Art. 6(1)(b)) for the assistance you or the brand asked for; legitimate interest (Art. 6(1)(f)) for aggregate community-health summaries, which exist so a brand can look after its own space.
- Retention at the provider: Anthropic retains prompt and response data for up to 30 days under their standard API retention policy, and does not use it to train its models. We have not yet executed Anthropic's Zero Retention Addendum for our workspace; that work is tracked separately.
- What we never do: we do not send your data to any AI provider for advertising, and we do not permit any provider to train models on it.
- Automated decision-making: the drafting, summary, and reply features assist people — they do not decide anything about you. Application scoring is advisory: a human administrator makes the decision to accept or decline. A brand may additionally set its own deterministic eligibility rules (for example a minimum follower count) that set an application aside without a person reading it first; if that happens to you, you can ask for a human to review it by writing to the brand, or to us at privacy@evertin.com.
2.4 People using the EVERTIN app (iOS) or the platform in a browser
Everyone inside EVERTIN — brand administrators, their staff and creators, and the members of a brand's space — uses the same product, whether through the iOS app or a web browser. This section sets out, in one place, everything the app collects, so you can see it without cross-referencing the sections above.
Where you are a member of a brand's space rather than our own customer, the brand is the data controller for your data and Millijoin is its processor (see the note in §1). We still describe the collection here, because it is our software doing it.
| Data | Purpose | Lawful basis (GDPR Art. 6) | Retention |
|---|---|---|---|
| Name and email address | Create and sign in to your account; identify you to the space you joined | Contract (Art. 6(1)(b)) | Until you delete your account |
| Profile photo | A photo is required before you can enter a brand's space, so members are recognisable to each other | Contract (Art. 6(1)(b)) | Until you delete it or your account |
| Messages, posts, replies, reactions, and files you upload | Deliver what you send to the space you sent it to | Contract (Art. 6(1)(b)) | Until you or the brand delete them, or the account is deleted |
| Camera and photo-library access | Only when you choose to attach or take a photo. The app asks your permission first, and only reads the images you pick. We never access the camera or your library in the background | Consent (Art. 6(1)(a)) — via the iOS permission prompt | Not stored beyond the image you chose to upload |
| Device notification token | Deliver push notifications, and only if you turn notifications on | Consent (Art. 6(1)(a)) | Until you turn notifications off, sign out, or delete your account |
| Reports and blocks you submit | Keep the space safe; act on abuse | Legitimate interest (Art. 6(1)(f)) | 24 months after the report is closed |
| Sign-in metadata (login times, IP at login, device type) | Account security and abuse detection | Legitimate interest (Art. 6(1)(f)) | 12 months |
Deleting your account from inside the app. Open your profile, choose Delete account, and confirm. This removes your account and the personal data attached to it, subject only to the legal retention windows in §5 (for example, bookkeeping records where you were a paying customer). You can also ask us at privacy@evertin.com and we will do it for you.
What we do not do. We do not track you across other companies' apps or websites, we do not run advertising or advertising identifiers, we do not sell your data, and we do not let any AI provider train models on it. Some message text is sent to our AI providers so a brand can see how its community is doing — §2.3 sets out exactly which features do that and what they receive.
3. How we share your personal data — subprocessors
We use the following processors (subprocessors) to run EVERTIN. Each is bound by a Data Processing Agreement (DPA) and, where applicable, Standard Contractual Clauses (SCCs) for transfers outside the EEA/UK.
| Subprocessor | Purpose | Country | Transfer mechanism | DPA |
|---|---|---|---|---|
| Vercel Inc. | Application hosting, edge compute, CDN, cron jobs, bot detection (BotID), and the AI Gateway that routes our model calls | USA (with EU regions for compute where configured) | EU SCCs + UK IDTA | Signed |
| Supabase Inc. | Database, authentication, object storage | EU (Ireland — AWS eu-west-1) for EVERTIN production | EU SCCs as backstop | Signed |
| Anthropic PBC (base DPA) | AI inference for content-drafting features (Claude) | USA | EU SCCs | Signed |
| Anthropic PBC (Zero Retention Addendum) | Reduces Anthropic's prompt/response retention to zero (see §2.3) | USA | EU SCCs | Not yet executed |
| Resend, Inc. | Transactional email delivery (account, billing, notifications) | USA | EU SCCs | Signed |
Internal company operations are agent-orchestrated via Paperclip. Paperclip is not engaged as a subprocessor of customer personal data; company personnel (human or agent) may incidentally access production data under our internal access controls when handling support, security, or engineering tasks. These activities are governed by our internal Acceptable Use and access policies rather than a standalone DPA.
We publish and keep this list current at evertin.com/legal/subprocessors. We will give brand administrators reasonable advance notice of any new subprocessor and a chance to object before that subprocessor processes their personal data.
We do not sell personal data and do not share it with advertisers or data brokers.
4. International transfers
Some of our subprocessors are located in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses (SCCs), the UK International Data Transfer Addendum (UK-IDTA) where UK personal data is involved, and, where available, additional safeguards such as encryption in transit and at rest. For each US-based subprocessor we maintain a Transfer Impact Assessment per EDPB guidance; the relevant TIA is available to data subjects and supervisory authorities on request. A copy of the relevant clauses is available on request from privacy@evertin.com.
5. How long we keep your personal data
Retention windows are listed alongside each data category in section 2. Where we don't have a fixed window, we keep data only for as long as we need it for the purpose it was collected, and then delete or anonymise it. Production database backups are taken daily and retained for 7 days, after which they are overwritten.
6. Your rights
Under the GDPR you have the right to:
- Access a copy of the personal data we hold about you;
- Rectify inaccurate or incomplete data;
- Erase ("right to be forgotten") your data, subject to legal retention requirements (e.g. bookkeeping);
- Restrict or object to processing based on legitimate interest;
- Data portability — receive a machine-readable copy of the data you provided;
- Withdraw consent at any time, where consent is the lawful basis;
- Lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten — IMY, https://imy.se), or the supervisory authority in your country of residence.
To exercise any of these rights, email privacy@evertin.com. We respond within 30 days of receiving a verifiable request, in line with GDPR Art. 12(3). Identity verification may be required to protect against impersonation.
We do not charge for the first copy of your data; subsequent or manifestly excessive requests may attract a reasonable fee.
7. Cookies
EVERTIN v1 GA does not set non-essential cookies and does not run analytics or marketing tracking. The only cookies set are strictly necessary cookies used to keep you signed in and to protect against CSRF; under the ePrivacy Directive these are exempt from the consent requirement. No cookie banner is therefore necessary at launch. If we add analytics or other non-essential tracking in the future, this policy will be updated and a consent surface deployed before that feature ships.
8. Security
We protect personal data with technical and organisational measures appropriate to the risk, including encryption in transit (TLS), encryption at rest for database and object storage, least-privilege access controls, and audit logging. Detailed security commitments are documented in our Security Overview, available on request from privacy@evertin.com.
If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours of becoming aware, in line with GDPR Art. 33. Where the risk is high, we will also notify you directly without undue delay.
9. Children
EVERTIN is not directed at children. You must be 16 or older to create an account and use the app, unless a brand has verifiable parental consent under applicable law (including GDPR Art. 8 in the EU/EEA) — see our Acceptable Use Policy. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact privacy@evertin.com and we will delete it.
10. Changes to this policy
We will post any material change to this policy at evertin.com/privacy, update the version number and date at the top, and — where the change affects an active processing activity for which you have an account — notify you by email at least 14 days before the change takes effect.
Version history
| Version | Date | Summary of changes |
|---|---|---|
| v1.2 | 2026-08-02 | Extended to cover the EVERTIN iOS app and everyone who uses the platform, not only brand administrators. New §2.4 lists everything the app collects — profile photo, messages and uploads, camera / photo-library access, notification token, reports and blocks — and documents deleting your account from inside the app. §2.3 rewritten to name every feature that sends data to an AI provider, including community sentiment summaries and application scoring, and to state the position on automated decisions. §9 restated as a 16+ minimum age. Corrected the subprocessors URL. |
| v1.1 | 2026-05-29 | §2.3 (AI-assisted features) updated to accurately reflect Anthropic's standard 30-day API retention; Zero Retention Addendum is noted as not yet executed for our workspace. Policy restructured to name a lawful basis (GDPR Art. 6) for every processing activity, with separate carve-outs for marketing-site visitors, brand administrators, and AI-assisted features. |
| v1.0 | 2026-05-28 | Initial publication. |
Tobias Svenlöv, VD, Millijoin AB (org. nr. 559069-3593)
Other legal docs: Terms of Service · Acceptable Use Policy · Cookie Policy · Subprocessors
