Legal

Privacy policy

mapzaa is a register of street furniture, not of people. We collect the little personal data the service genuinely needs, keep it in the EU, and run no analytics and no trackers at all — which is why this site has no cookie banner.

Version 1.0 · Last updated 17 September 2026

1. Who is responsible

The controller for the personal data described here is Sverige Analytics AB, registration number 559538-4917, Umeå, Sweden (EU) — [email protected].

There are two different situations, and it matters which one applies:

  • For this website and for the accounts people sign in with, we are the controller — we decide what is collected and why.
  • For whatever your organisation records inside its own register, your organisation is the controller and we are a processor acting on its instructions. See section 4.

2. This website

www.mapzaa.com is a set of static pages. It loads no analytics, no advertising and no third-party scripts; the typefaces are served from our own domain rather than a font network. Visiting these pages sets no cookies and requires no consent banner.

As with any website, our infrastructure providers process the technical information needed to deliver a page — your IP address and the request itself — and may keep short-lived operational logs for security and abuse prevention. Our own application logs record only the request method, the path and how long the request took; they do not record IP addresses.

If you email [email protected], we keep that correspondence so we can answer it and so there is a record of what was agreed.

3. Account data

For each person with access to the dashboard we hold:

  • Name and email address — to identify the account, send the sign-in code and let colleagues see who changed what.
  • A password hash, computed with argon2id. We never store the password itself and cannot recover it.
  • Role and organisation — administrator or member, and which organisation the seat belongs to.
  • Session records — for each active sign-in, a hash of the session token, the IP address and browser user-agent it was created from, and its creation and expiry times. These exist so that a session can be reviewed and revoked.
  • Sign-in codes and invitation tokens — stored only as hashes, with an expiry and an attempt count.
  • Timestamps — when the account was created and when its email address was verified.

We do not profile users, and no automated decision-making within the meaning of Article 22 of the GDPR takes place.

4. Data in your register

mapzaa is designed for physical assets, and the fields it ships with — category, status, coordinates, address, description — are about objects, not people. But because custom fields are yours to define, your organisation could put personal data into them (a named inspector, a resident's complaint, a contractor's phone number).

Where that happens, your organisation is the controller and we act only as its processor. We process that content solely to provide the service, on your instructions, and we do not use it for anything else. If your organisation needs a data processing agreement under Article 28 of the GDPR, email [email protected] and we will put one in place.

Our advice is the boring one: keep personal data out of the register unless you have a reason and a lawful basis to hold it there.

5. Cookies

The dashboard sets only cookies that are strictly necessary to sign you in and to protect the forms you submit. There are no analytics, advertising or tracking cookies anywhere in mapzaa.

  • mz_session — keeps you signed in. Up to 30 days.
  • mz_csrf — protects forms against cross-site request forgery.
  • mz_pending — holds a sign-in between the password step and the emailed code. Minutes.
  • mz_invite — holds an invitation while it is being accepted, so the token stays out of the address bar. Minutes.

All of them are HttpOnly and sent only over HTTPS. Because they are strictly necessary for a service you asked for, no consent banner is required for them.

6. Legal bases

  • Performance of a contract (Art. 6(1)(b)) — creating and running the account and the register your organisation asked for.
  • Legitimate interests (Art. 6(1)(f)) — keeping the service secure: rate limiting, bot protection, session records and abuse prevention. We have weighed this against your interests and consider it proportionate, since it is the minimum needed to protect a shared public record.
  • Legal obligation (Art. 6(1)(c)) — where accounting or other law requires us to keep something.

7. Who else processes it

We keep the list short on purpose. We do not sell personal data, and we share it with no one for marketing.

  • Webdock.io ApS (Denmark, EU) — hosts the server that runs mapzaa and holds its database.
  • Resend — sends transactional email: invitations, sign-in codes, address verification and password resets. It receives the recipient's email address and the message.
  • Cloudflare — sits in front of this website as a CDN and handles the connection to it.
  • MapTiler — looks up the street address for a set of coordinates. This call is made by our server, so your browser never contacts MapTiler and no visitor IP address reaches it.
  • OpenFreeMap — serves the map tiles. These are fetched by your browser when you open the map, so your IP address is visible to that service, as it would be for any image on any page.

Each of these is bound by a processing agreement where one is required. Where a provider processes data outside the EU or EEA, that transfer relies on the European Commission's Standard Contractual Clauses or an adequacy decision.

8. Where it is stored

Your register and your account data live in a single database on a server in Denmark, within the European Union. They are not replicated outside the EU.

9. How long we keep it

  • Account data — for as long as the account exists.
  • Register content — for as long as your organisation exists. After an organisation is closed we keep it for 30 days so a mistake can be undone, then delete it permanently.
  • Sessions — up to 30 days, and immediately when you sign out, reset your password or are moved to another organisation.
  • Sign-in codes — 10 minutes, or five failed attempts.
  • Invitations — 72 hours, then they expire. An accepted invitation is deleted in the same moment the account is created.
  • Email correspondence — normally up to 24 months.

10. How we protect it

  • Passwords are hashed with argon2id and never stored or logged in the clear.
  • Session, invitation, verification and reset tokens are stored only as SHA-256 hashes — the usable value exists only in your cookie or your email.
  • Signing in requires a one-time code sent to the account's email address, every time.
  • Sign-in, invitation and code entry are rate limited, and protected by a proof-of-work challenge served from our own domain.
  • All traffic is over HTTPS, with a strict content security policy.
  • Each organisation's data is scoped at the database level, so a request for another organisation's record simply does not find it.

If a personal data breach occurs that is likely to present a risk, we will notify the Swedish supervisory authority within 72 hours and inform affected organisations without undue delay.

11. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and receive a copy;
  • have inaccurate data corrected;
  • have data erased where there is no overriding reason to keep it;
  • restrict or object to processing based on legitimate interests;
  • receive your data in a portable, machine-readable format.

Email [email protected] and we will answer within one month, free of charge. If your request concerns data inside an organisation's register, we will refer you to that organisation, since it is the controller for it.

You may also lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, imy.se) or with the supervisory authority where you live or work.

12. Changes and contact

If we change this policy we will update the version and date at the top of this page, and email organisation administrators about anything material.

Sverige Analytics AB · Reg. no. 559538-4917 · Umeå, Sweden · [email protected]

Questions about data protection?

Write to us directly — the same address handles privacy requests, support and demo bookings.