Compliance at Permly

Designed for global mobility, locally protected. GDPR compliant and hosted exclusively within the EU/EEA.

GDPR CompliantEEA Data HostingSecure by Design

Permly is a platform for work‑permit compliance, relocation workflows, and employer documentation. We process personal data under GDPR and Swedish law, operate on EU/EEA‑only infrastructure, and apply a strict secure‑by‑design, least‑privilege model. The following sections detail our compliance with key regulations and our commitment to data protection.

Legal & Regulatory

Legal & Regulatory Compliance

Overview of key legal frameworks.

Compliant

General Data Protection Regulation

Regulation (EU) 2016/679

We comply with the EU GDPR as both a Data Controller and Processor. For employer clients, this includes formal Art. 28 Data Processing Agreements (DPAs). We also perform internal Data Protection Impact Assessments (DPIAs) for sensitive processing and apply strong security controls (encryption, access limits, audit logs).

Compliant

Swedish Data Protection Act

Lag (2018:218)

This complements the GDPR in Sweden. We follow IMY (Swedish Privacy Authority) guidance and apply national rules for lawful and secure processing of personal data.

Compliant

Public Access to Information & Secrecy Act / Archives Act

OOSL (2009:400) & Arkivlagen (1990:782)

We handle submissions to authorities and manage archival materials in line with Swedish secrecy and retention laws.

Compliant

Swedish Migration Agency Regulations

MIGRFS

Job offers and insurance details are automatically validated against current Migrationsverket requirements (e.g., salary thresholds, mandatory insurances) before submission to ensure compliance.

Compliant

Bookkeeping Act

Bokföringslagen (1999:1078)

We retain accounting‑related records for 7 years, as required by Chapter 7, Section 2 of the Swedish Bookkeeping Act.

Upcoming

EU Artificial Intelligence Act

Permly's tools classify as 'limited‑risk' under the draft EU AI Act. They only assist users (e.g., document drafting, classification) and never make legally binding decisions. We review these systems quarterly for bias, fairness, and performance.

AI & Automation

AI & Automation Practices

Transparency and safeguards for our AI use.

Permly deploys large‑language models (LLMs) and other AI components solely for low‑risk, assistive tasks. These tools help us deliver faster, safer, and more compliant permit case preparation, always under human oversight and in accordance with GDPR and the EU AI Act.

What we do

  • Draft summaries, form answers and guidance to accelerate case preparation.
  • Classify and tag uploaded documents to recommended categories, following the Controller's instructions.
  • Perform automatic redaction of direct identifiers where technically feasible before AI processing.
  • Host all AI processing exclusively on vetted EU/EEA cloud providers with full model versioning and change‑control.
  • Generate irreversibly anonymised aggregated benchmarking statistics (outside GDPR scope).
  • Offer per‑customer opt‑out from participation in anonymised benchmarking datasets.

What we don't do

  • Fine‑tune or train foundation models on identifiable client data.
  • Share personal data with non‑EEA AI providers or data brokers.
  • Make final binding immigration, employment or legal decisions using AI.
  • Create or file final documents without human approval.
  • Use AI for employee surveillance or productivity scoring.
  • Sell anonymised or aggregated statistics for marketing or advertising purposes.

AI outputs are assistive tools, not authoritative records. All content is reviewed and approved by humans before submission to any authority.

Cookies & Tracking

Cookies & Tracking

How we use cookies and respect your privacy choices.

Strictly Necessary

Always Active

Required for core functionality such as secure log‑ins, authentication, and user preferences. These cannot be disabled.

Analytics

Consent‑Based

Google Analytics with privacy‑enhanced settings to understand usage and improve performance. Only enabled if you consent.

Marketing

Not Used

We do not use marketing, advertising, or third‑party tracking cookies. No personal data is sold to third parties.

You can manage or withdraw your consent at any time via our cookie banner or in your browser settings. Disabling strictly necessary cookies may affect the Platform's functionality.

Legal Documentation

Legal Documentation

Access our key legal and compliance documents.

Privacy Policy

v1.0

View

Terms & Conditions

v1.0

View

Sub-Processor List

Latest update August 2025

View

DPIA Summary Report

Available on request

Request

Data Processing Agreement (DPA)

Available on request

Request

EU AI Act Classification

Available on request

Request
Updates & Commitments

Transparency

How we handle policy updates and our commitment to transparency.

Our Commitments

Significant changes

Major updates, for example, changes to why or how we process your personal data, are communicated proactively and before they take effect. In line with Articles 12–14 of the GDPR, these updates are clearly highlighted in our revised policies.

Minor clarifications

Smaller updates or clarifications are published immediately on our Platform. Version numbers always increase, and changes are logged.

Changelog

Every change is documented in our public changelog with dates and version history so you can always review what changed and when.

Need Help?

Questions about our policies, your rights, or how updates may affect you?

admin@permly.ai

We're here to help you understand our policies and how updates impact you.

Compliance Portal - Permly