Last updated: September 30, 2026
This Privacy Policy describes how Avidemic AB (reg. no. 559252-4267, Sweden), operating the Validemic service (“Validemic”, “we”, “us”), collects, uses and protects personal data when you use validemic.com and the Validemic platform. For privacy questions or to exercise your rights, contact us at privacy@validemic.com or write to Avidemic AB, Sweden.
Workspace content. Everything a university stores in its Validemic workspace, such as vendor reviews, uploaded documents, policies, DPIAs, agreements, survey answers and the names of colleagues and vendor contacts in it, is processed on behalf of that university. The university is the controller and we are its processor under Article 28 GDPR, bound by a data processing agreement. The university’s own privacy notice applies to that data, and requests about it should go to the university; if you contact us, we pass the request on and help the university answer it. The same applies to vendors who answer an assessment or sign an agreement through a link a university sent them.
Everything else. For user accounts, sign-in and security, our website, contact and demo requests, billing and our own email, Avidemic AB is the controller. The rest of this policy describes that processing.
You need to provide account details to use the platform; everything else is optional. We do not make decisions based solely on automated processing that produce legal or similarly significant effects (Art. 22). The AI in Validemic prepares material and cites its sources; people make every decision.
We never sell personal data and we show no advertising. Service providers process personal data on our behalf only under GDPR data processing agreements. The platform’s providers (hosting, backup storage, AI inference and transactional email) are all EU companies processing in the EU; the complete list with locations and safeguards is on our Compliance page. Our own email, which receives contact-form requests and messages you send us, runs on Google Workspace, provided by Google Ireland Limited. Beyond these, we disclose personal data only where the law requires it, for example to a court or authority.
Workspace content and account data are stored and processed only in the EU/EEA. The one exception is our own email: Google may process email in other countries, including the United States. Those transfers rely on the EU-US Data Privacy Framework, under which Google is certified, and on the European Commission’s standard contractual clauses. Please upload vendor documents to your workspace rather than emailing them to us.
Validemic stores customer content on servers in Sweden, with encrypted nightly backups in Finland. Data is encrypted in transit with TLS 1.2 or higher, and backups are encrypted before they leave our servers. Access within a workspace is role-based, and single sign-on through your institution’s identity provider is available on request. We sign a data processing agreement (DPA) with every institutional customer.
Under the GDPR you have the right to:
Email privacy@validemic.com to use these rights. We answer within one month. For workspace content, we forward your request to the university that controls it. You can also complain to the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se), or to the data protection authority where you live or work.
Validemic uses only strictly necessary cookies: those required for logging in, keeping your session active and remembering your language and cookie preferences. Because we set no optional cookies, no cookie consent is required beyond this notice.
We may update this policy from time to time to reflect changes in our practices or for legal reasons. The date at the top shows the latest version, which is always available at validemic.com/privacy.