Privacy policy

How ReloClear handles personal data

This policy explains what we collect, why we collect it, how long we keep it, who helps us process it, and how you can use your privacy rights.

Last updated July 21, 2026

Plain-language summary

ReloClear uses your information to create immigration and relocation assessments, deliver results, secure accounts, prevent abuse, answer support requests, and run the service. We do not sell personal data. We do not use your assessment to make a government decision. Our assessment output is informational and does not approve, reject, or file an immigration application. Core application, assessment, report, and internal order records are stored in EU-region database infrastructure. Selected service providers may process limited personal data outside the EU/EEA for functions such as website delivery, email, payments, security, support, and AI-assisted report writing, subject to the safeguards described below.

1. Who is responsible for your data

The controller for the personal data described in this policy is Reloclear AB (trading as ReloClear), company registration number 559589-3032, with registered office at Sundspromenaden 31, 211 16 Malmö, Sweden. You can contact us at contact@reloclear.com.

Our Swedish VAT number is SE559589303201. The same company information appears in the legal notice.

2. When this policy applies

This policy applies when you:

  • visit the ReloClear website;
  • create or use a ReloClear account;
  • complete a free or paid immigration or relocation assessment;
  • receive verification, result, or service emails from us;
  • contact us for support, business enquiries, expert referrals, or legal rights requests;
  • buy a report or other digital service where it is offered.

3. Personal data we collect

Account and authentication data

  • Email address, password-authentication identifiers, user ID, account status, role, and email-verification status.
  • Authentication session data needed to keep you signed in, refresh your session, and protect your account.
  • Security and abuse-prevention signals, such as request metadata and HMAC-hashed rate-limit subjects.

Assessment data

The assessment asks for information needed to screen relevant immigration routes. Depending on your answers, this may include:

  • citizenship, EU/EEA status, country and destination-related answers;
  • passport status, including whether a passport appears valid and whether it is biometric;
  • age range, residence status in Sweden, previous Swedish residence permit status, and move timeline;
  • main purpose of moving, such as work, study, family, or jobseeking;
  • education level, work experience, occupation, SSYK occupation code, job title, salary, employment scope, collective-agreement signals, and employer-related answers;
  • study admission, programme length, maintenance funds, and health-insurance answers;
  • family relationship type, partner or close-family status, children moving with you, sponsor status, sponsor income, and housing-related answers;
  • selected previous immigration issues and limited criminal-history screening answers where relevant to route screening;
  • contact email used to deliver or resume an assessment result.

We try to avoid collecting more detail than needed for screening. You should not include sensitive free-text information unless the product clearly asks for it.

Generated assessment and report data

  • Route matches, band labels, result summaries, missing requirements, risk notes, next steps, and internal scoring events.
  • Published scoring rule version and country code used to generate the result.
  • AI-assisted explanatory wording and generation metadata where AI-assisted report writing is used.
  • Saved-result link metadata, including email address, token hash, expiry time, sent time, and revoked status.

Website, device, and storage data

  • Language preference, assessment draft storage in your browser, and strictly necessary cookies or similar storage.
  • IP-derived request information used for security, rate limits, logs, and fraud prevention. Where rate-limit tables store identifiers, they store HMAC hashes rather than raw IP addresses or raw email addresses.
  • Basic technical logs created by hosting, database, email, and security providers.

See the Cookie policy for details about cookies and local storage.

Payments and commercial records

When you buy a paid service, we create order, payment-status, tax, invoice, refund, and accounting records. Payment details are entered with the payment provider and are not collected or stored directly by ReloClear. We receive the information needed to confirm and support the order, such as billing email, amount, currency, tax, transaction references, payment status, refund status, and dispute information.

Support, business, and expert-referral communications

If you contact us, we process the information you choose to send, such as name, email address, company, role, message content, support history, and any files or context you provide.

4. Sensitive data, criminal-offence information, and children

ReloClear does not intentionally ask for GDPR special category data, such as health details, religion, political opinions, biometric identifiers used for identification, genetic data, or sexual orientation. Some immigration facts can still be sensitive in a practical sense, so we handle assessment data with care.

The assessment may ask limited yes/no and broad-severity questions about criminal history so that the result can flag when individual professional review may be needed. Information about criminal convictions and offences has separate protection under GDPR Article 10. We do not ask for offence descriptions, court records, or criminal-record documents in the standard assessment. This flow must only be used where its processing is permitted by applicable law and appropriate safeguards are in place.

The service is not intended for children to use directly. Some questions may ask whether children are moving with an adult applicant, but the current assessment is designed to avoid collecting child names, identity numbers, or documents. A parent or guardian should manage any child-related information.

5. Why we use personal data and our lawful bases

PurposeExamplesLegal basis
Provide assessments and reportsScore answers, generate result pages and explanatory report wording, deliver free or paid reports, save results for return links.Contract or steps before contract.
Create and secure accountsSign-up, login, email verification, session refresh, account dashboard.Contract and legitimate interests in service security.
Send service emailsVerification links, saved-result links, account notices, payment receipts.Contract, legitimate interests, and legal obligation where receipts are required.
Prevent abuse and protect the serviceRate limits, fraud prevention, security logs, abuse investigation.Legitimate interests and legal obligation where applicable.
Support and customer communicationAnswer questions, troubleshoot reports, manage deletion or access requests.Contract, legitimate interests, and legal obligation for privacy-rights requests.
Payments, tax, and accountingOrders, invoices, refunds, bookkeeping, tax records, chargeback handling.Contract and legal obligation.
Improve product qualityDebug scoring, monitor conversion, improve wording, analyze aggregated route demand.Legitimate interests. Consent where non-essential tracking is introduced.
Marketing, if enabledNewsletters, launch updates, product announcements.Consent or soft opt-in where legally available, with unsubscribe controls.

6. Automated scoring, profiling, and AI

ReloClear uses a structured scoring engine to compare your answers against route-specific immigration criteria and produce an informational screening result. This is profiling in the broad sense that your answers are used to classify possible routes, risks, and next steps.

ReloClear does not make an official immigration decision, does not grant or refuse a permit, does not submit an application, and does not create a lawyer-client relationship. The assessment does not itself produce a legal effect or a similarly significant effect in the sense of GDPR Article 22. A government authority, not ReloClear, decides immigration applications.

AI may be used to draft selected explanatory passages in a paid report. When it is used, selected profile facts and structured scoring output are sent to an AI service provider and an underlying model provider. The rules engine, not the AI service, determines the route ordering, result bands, review points, and source actions. Generated wording is accepted only in the report fields intended for explanatory text.

Current AI report requests are configured to require zero-data-retention routing and to deny provider data collection for model training. ReloClear stores the resulting report and limited generation metadata; providers may still retain limited operational, billing, security, or abuse-prevention metadata under their terms. If the AI service is unavailable or its output fails validation, the report uses deterministic fallback wording.

7. Who receives personal data

We share personal data only where needed to run ReloClear, comply with law, protect the service, or deliver a feature you request. Key provider categories include:

Recipient categoryPurposeData and location notes
Core application infrastructure providersDatabase, authentication, server functions, report storage, and scheduled jobs.Core application, assessment, report, and internal order records are stored in an EU database region.
Website, network, and security providersWebsite hosting, content delivery, server-side requests, security, and operational logs.Request and technical data may be processed where these providers and their subprocessors operate.
Transactional email providersTransactional email, including verification and saved-result emails.Email addresses, message content, and delivery or security events may be processed internationally.
Business communications and support providersBusiness email, documents, support communication, and internal administration.Data is limited to the communication or operational task and may be processed internationally.
Payment and accounting providersCheckout, payment confirmation, tax, refunds, bookkeeping, and invoices.Payment providers may process data internationally and may act as a processor or independent controller for parts of their service.
AI text-generation providersDraft selected explanatory passages for paid reports from structured profile and scoring facts.Requests may be processed outside the EU/EEA. Current report requests require zero-data-retention routing and deny provider data collection.
Expert or professional partnersReferral or handoff where you ask for expert help.Shared only with your request or clear permission.
Authorities, courts, and advisersLegal compliance, dispute handling, fraud prevention, or enforcing rights.Only where required or reasonably necessary.

ReloClear does not sell personal data. ReloClear does not share assessment answers with immigration authorities unless you ask us to, a service you request explicitly requires it, or we are legally required to do so.

We publish recipient categories rather than a complete technical supplier inventory. You may contact us for current information about material recipients and the safeguards relevant to your personal data.

8. International transfers

ReloClear is established in Sweden. Core application, assessment, report, and internal order records are stored in EU-region database infrastructure. This storage location does not mean that every operation is performed only in the EU/EEA. Selected service providers and subprocessors may access or process limited personal data in the United States or other countries outside the EU/EEA for website delivery, email, payments, AI-assisted report writing, support, security, and related operations.

Where personal data is transferred outside the EU/EEA, we use a legally recognized transfer mechanism as applicable, such as an adequacy decision (including the EU-US Data Privacy Framework for eligible recipients) or the European Commission's Standard Contractual Clauses, together with contractual and technical safeguards appropriate to the service. You may contact us to request information about the safeguards relevant to your data.

9. How long we keep personal data

We keep personal data only as long as needed for the purposes above, unless a longer period is required by law, dispute handling, accounting, tax, fraud prevention, or security.

DataCurrent retention approach
Anonymous free score runsDeleted after 90 days under the current assessment retention job.
Saved-result magic linksLinks expire after 30 days. Expired or revoked link rows are deleted after a 14-day grace period.
Rate-limit bucketsHMAC-hashed IP or email buckets are deleted after 7 days under the current retention job.
Assessment draft in browser local storageStored on your device until you submit, clear the assessment, or clear browser storage.
Account dataKept while the account is active and for a reasonable period after closure where needed for security, disputes, or legal obligations.
Paid orders, invoices, taxes, and refundsKept for the period required by accounting, tax, consumer, and dispute rules.
AI-assisted report requestsCurrent report requests require zero-data-retention routing for prompt and response content. The resulting report and limited generation metadata are retained with the report under the applicable report and account retention period.
Support communicationsKept while needed to respond, maintain service history, handle disputes, and comply with legal obligations.
Aggregated or anonymized statisticsMay be kept longer if individuals are no longer identifiable.

10. Cookies, local storage, and signed-in sessions

ReloClear uses strictly necessary cookies and similar storage for login sessions, language choice, saved-result access, assessment drafts, and security. ReloClear does not currently use non-essential analytics or advertising cookies.

ReloClear uses a managed authentication provider. The access token is short-lived, while refresh-token rotation can keep a browser signed in until the user signs out, the session is revoked, the refresh flow fails, or a configured session timebox or inactivity timeout applies. This is why users should sign out on shared devices.

For details, see the Cookie policy.

11. Security

ReloClear uses technical and organizational measures intended to protect personal data, including server-side validation, email verification, private server secrets, role-based access controls where applicable, rate limits, token hashing for saved-result links, service-provider access controls, and restricted exposure of private scoring logic.

No online service can guarantee absolute security. If you believe your account or data may be at risk, contact us promptly at contact@reloclear.com.

12. Your privacy rights

Depending on where you live and which laws apply, you may have the right to:

  • request access to your personal data;
  • request correction of inaccurate or incomplete data;
  • request deletion of personal data;
  • request restriction of processing;
  • object to processing based on legitimate interests;
  • request data portability for data processed by automated means on consent or contract basis;
  • withdraw consent where processing is based on consent;
  • complain to a data protection authority.

To use these rights, contact contact@reloclear.com. We may need to verify your identity before acting on a request. Where GDPR applies, we generally aim to respond within one month, unless an extension is allowed by law.

In Sweden, the relevant supervisory authority is the Swedish Authority for Privacy Protection, IMY. You can also contact the supervisory authority in your country of residence or work.

13. Changes to this policy

We may update this policy when the product, providers, legal requirements, or data practices change. The date at the top shows when this version was last updated. Material changes should be communicated in a reasonable way, for example through the website, email, or account notices.