Legal

Privacy Policy

Last updated: January 2026

1. About this policy

This privacy policy describes how Awarak AB (“we”, “us”), operating the Fairway Lab service, processes personal data when you use our AI-powered golf swing analysis. We have designed the service around the principle of data minimisation — we collect as little information as possible and delete anything we are not required to keep.

2. Data controller

Awarak AB is the data controller for the processing of your personal data on fairwaylab.se. Fairway Lab is operated by Awarak AB; Stripe payments are processed through Awarak AB's Stripe account and bank account.

[Awarak AB organisation number to be added here.]

For questions regarding privacy, personal data, data deletion requests, or GDPR rights, please contact us at: support@fairwaylab.se

3. What data we process and why

To deliver a swing analysis (performance of our contract with you under Article 6(1)(b) GDPR) we temporarily process two pieces of information:

  • Your uploaded golf swing video — used solely so the AI can analyse your swing technique.
  • The problem you describe in text — used solely so the AI can focus its feedback on what you actually want help with.

We do not collect your name, email address, phone number, or any other directly identifying information on our side. There are no user accounts.

Note on IP addresses. We never log your IP address in our application or database. However, like any internet service, our hosting provider and content-delivery network may briefly observe your IP address at the network edge for security and abuse prevention. Such edge logs are typically retained for up to 72 hours by the provider and are not accessible to us as personally identifiable data.

4. Storage and retention

We apply a strict short-retention policy:

  • The video file is permanently deleted from the server the moment OpenAI's API has returned its text response (typically within 30 seconds of upload). The video is never written to disk or object storage.
  • Your problem description and the AI response are stored together with the submission for up to 24 hours, so that you can safely refresh the page, switch tabs, briefly lose connection, or complete Stripe checkout without losing your analysis. After 24 hours the entire submission is automatically and permanently deleted by our database. You are welcome to copy the analysis or download it as a PDF from the results page to keep a copy.

The only thing we keep in the database beyond 24 hours is a Stripe transaction id and a timestamp, which is required for accounting and for handling any refunds (see section 6).

5. Third-party processors

To deliver the service we rely on the following sub-processors:

  • OpenAI (USA) — receives still frames from your video together with your problem description in order to generate the analysis. Data is transferred over an encrypted HTTPS API. OpenAI does not train its models on API inputs.
  • Stripe (Ireland / USA) — processes your payment. When you proceed to checkout you are redirected to a page hosted by Stripe where you enter your card number, billing address, country, and email directly into Stripe. That information is collected by Stripe, not by us; we never see or store it. Stripe acts as an independent data controller for those payment details and processes them under its own privacy policy.
  • Hosting provider — runs the application servers and the database. Edge logs may temporarily capture your IP address (see section 3).

All communication with these parties is encrypted in transit (HTTPS/TLS). Any international transfers rely on the EU–US Data Privacy Framework and/or the EU's Standard Contractual Clauses.

6. What we keep for accounting

To comply with Swedish bookkeeping law and to be able to handle refunds we store only the following per completed transaction:

  • Stripe transaction id (an opaque reference — not your identity)
  • Timestamp
  • Amount and currency
  • Status (success / refunded)

On our side this data contains no directly identifying personal data. The card details themselves remain encrypted with Stripe, not with us. Bookkeeping data is retained for seven years as required by Swedish law (Bokföringslagen 7 kap. 2 §).

7. Legal basis

We process your data on the following GDPR legal bases:

  • Contract (Art. 6(1)(b)) — to deliver the analysis you ordered and process your payment.
  • Consent (Art. 6(1)(a)) — your explicit tick of the “By starting the analysis you agree...” checkbox before the analysis is started.
  • Legal obligation (Art. 6(1)(c)) — to keep accounting records for the period required by Swedish law.

8. Security and storage technologies

All traffic between your device and our servers is encrypted with HTTPS/TLS. API keys and other secrets are stored in private environment variables and are never exposed in client code. The database runs on managed infrastructure with encryption-at-rest.

Cookies and similar technologies. The public Fairway Lab site does not set any tracking, advertising or analytics cookies. The only local-storage entries we use are (a) your consent choice if applicable, and (b) an authentication token used exclusively by Fairway Lab staff to access the internal admin dashboard.

Data breach notification. In the event of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the Swedish Authority for Privacy Protection (IMY) within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR, and we will inform affected individuals where Article 34 GDPR requires it.

Automated decision-making. The AI feedback we generate does not produce any decision that has a legal or similarly significant effect on you within the meaning of Article 22 GDPR. It is educational coaching content only.

8a. Age requirement

Fairway Lab is not directed at children. By using the service you confirm that you are at least 16 years old, or that you have the consent of a parent or guardian. If you believe a child has used the service, please contact us at support@fairwaylab.se and we will delete any related data.

9. Your rights

Under GDPR you have the right to:

  • request information about what data we hold about you (subject access — Art. 15),
  • have inaccurate data corrected (Art. 16),
  • have your data deleted (the “right to be forgotten” — Art. 17),
  • restrict or object to processing (Art. 18 / 21),
  • receive your data in a portable machine-readable format (Art. 20),
  • withdraw any consent you previously gave (Art. 7),
  • lodge a complaint with the Swedish Authority for Privacy Protection (IMY) if you believe we are processing your data unlawfully.

Because we deliberately do not store any directly identifying information about you, in most cases we cannot link a request back to a specific person. If you need us to delete a transaction id from our accounting records, send the relevant Stripe id from your payment confirmation to support@fairwaylab.se and we will help you (subject to the bookkeeping obligations we are required to meet under Swedish law).

10. Changes to this policy

We may update this policy from time to time. Material changes will be announced on the home page and the “Last updated” date above always reflects the current version.

Made with Emergent