New essays from the team — on casting, gifting, and what performance actually means
settr
Privacy policy

Privacy policy.

How Settr collects, uses, shares, and protects personal data — for clients, for creators in the indexed graph, and for visitors to this site. Plain English. No hidden clauses.

last updated · 28 May 2026 effective · 28 May 2026 version · v2.5
/01

Who we are and what this covers

Settr AB ("Settr", "we") is the data controller for personal data processed through the Settr platform and through the managed service. Our HQ is in Stockholm, Sweden.

This policy covers three groups of people: clients and their named contacts; creators represented in the indexed creator graph; and visitors to settr.com.

/02

What data we collect

We collect only what we need to operate the service. Three categories:

Client data
Contact name, business email, role, company, billing details, and the brand brief shared with Settr for the engagement.
Creator data
Public-profile data, post-level engagement metrics, audience signals (where the creator has granted Graph-API permission), and commercial cadence signals derived from public content.
Site data
Visitor IP, user-agent, referrer, page interactions, and identifiers collected through cookies and similar technologies on settr.com — for security, debugging, aggregate traffic analysis, and B2B website identification and marketing as described in section 10.

We do not buy personal data from data brokers. We do not collect special-category data (health, religion, political opinions, etc.) and we do not knowingly process personal data of children under sixteen.

/03

How we use data

We use data for the following purposes — and nothing else:

  • To deliver the service. Run the platform, operate the managed pod, score and route content, generate reports.
  • To improve the service. Aggregate signals, retrain weights, audit routing decisions, fix bugs. Always on aggregated or de-identified data where possible.
  • To meet legal obligations. Accounting, tax, regulatory reporting, lawful requests from authorities.
  • To communicate. Operational notices about your engagement; security and policy updates; opted-in newsletters.
  • To market Settr on this website. Identify business visitors to settr.com and send or coordinate follow-up communications about Settr's products and services, including through online data partners described in section 10.

We do not sell personal data in the sense of exchanging client or creator records for third-party lists. We do not train external generative-AI models on client briefs or creator content. This marketing site may use third-party identification and advertising technologies for Settr's own B2B outreach, as set out in sections 05 and 10.

/04

Lawful basis (GDPR)

For data subjects in the EEA, UK, and Switzerland, our lawful bases are:

Contract
Where processing is necessary to perform the engagement order with the client, or to take pre-contractual steps at the data subject's request.
Legitimate interest
Where processing is necessary for Settr's or a third party's legitimate interest — indexing public creator data, fraud prevention, service security — and that interest is not overridden by the data subject's rights.
Legal obligation
Where processing is required to comply with a legal duty Settr is subject to.
Consent
Where you have given clear, opt-in consent — for example, to receive a newsletter or to connect Graph-API permissions.
/05

Who we share data with

We share personal data with a small number of vetted sub-processors that help us run the service. A current list is available on request. Each sub-processor is bound by a data-processing agreement consistent with this policy.

Typical categories of sub-processor:

  • Cloud infrastructure — EU-hosted compute, storage, and object delivery.
  • Email and communications — transactional and operational email delivery.
  • Customer support — help-desk software used by the operator team.
  • Analytics and observability — site analytics; application monitoring.
  • Website identification and B2B marketing — vendors that use cookies and similar technologies to associate visits to settr.com with professional or contact profiles so Settr (or providers on our behalf) can send relevant communications. Our current provider for this purpose is RB2B (operated by Retention.com).
  • Accounting and billing — invoicing, payment processing, tax reporting.

Where we use website identification partners, that use may be treated as sharing personal information for cross-context behavioral advertising under some U.S. state laws (for example, California). You can opt out as described in section 10. We do not share client or creator platform data with those partners for their own unrelated marketing. Authorities receive data only in response to a lawful request — and we publish a transparency report each year.

/06

International transfers

Where personal data leaves the EEA, we rely on the European Commission's Standard Contractual Clauses (SCCs) and, where relevant, the UK addendum and the Swiss FDPIC equivalent. We perform a transfer-impact assessment for each material sub-processor before onboarding.

/07

Data retention

We keep personal data only as long as it is needed for the purposes set out above. After that, we delete or aggregate it.

  • Client contacts — for the term of the engagement plus eighteen months.
  • Operational logs — thirteen months, then aggregated.
  • Billing records — ten years, as required by German commercial law.
  • Creator-graph entries — refreshed daily; entries removed when a creator deletes the source profile or requests removal.
/08

Your rights

If you are a data subject in the EEA, UK, or Switzerland, you have the right to access your data, correct it, delete it, restrict processing, object to processing based on legitimate interest, and request portability of data you provided to us.

You also have the right to lodge a complaint with a supervisory authority. Settr's lead authority is the Swedish Authority for Privacy Protection (IMY).

If you are a resident of California or another U.S. state with a comprehensive privacy law, you may have additional rights to know, delete, or correct personal information we hold about you, and to opt out of certain sharing for cross-context behavioral advertising. Use the opt-out link in section 10 or contact privacy@settr.com.

To exercise any of these rights, write to privacy@settr.com or use the dedicated account-deletion request page. We respond within thirty days.

/09

How we keep data safe

We use industry-standard technical and organisational measures — encryption in transit and at rest, access controls on a need-to-know basis, audit logging, regular dependency review, and annual penetration testing. We do not promise that any system is impenetrable, but we do promise to notify you of any personal-data breach affecting your data within seventy-two hours of becoming aware.

/10

Cookies, similar technologies, and opt-out

settr.com uses strictly necessary cookies for session, security, and core site function. We also use analytics and identification technologies to understand traffic and support our B2B marketing.

When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including by association with your email or online profiles. We (or service providers on our behalf) may then send communications and marketing to these emails or profiles. You may opt out of receiving this advertising by visiting https://app.retention.com/optout.

Our website identification partner is RB2B (Retention.com). Their processing is intended for U.S. visitors; we do not use this service to deliberately target the EEA, UK, or Switzerland. If you are in those regions and believe your data was processed, contact privacy@settr.com.

A cookie preference banner is not yet shown on this site. Until it is added, use the opt-out link above for interest-based advertising from our data partners. For other privacy rights, see section 08 or write to privacy@settr.com.

/11

Changes to this policy

We may update this policy from time to time. Material changes are communicated to clients by email and published on this page with a new "last updated" date. Continued use of the service after the effective date constitutes acceptance.

Privacy questions or rights requests?

Write to our DPO at privacy@settr.com. We respond within thirty days.

Contact Settr