Legal

Privacy Policy

Last updated: 22 June 2026

This policy explains what personal data we collect, why we collect it, and what you can do about it. It applies across the entire Human Delta ecosystem — including thehumandelta.com, START™ (start.thehumandelta.com), Pivot Report™ (pivot.thehumandelta.com), our newsletter, Thinking articles, contact forms, and future STRATOS™ properties.

Who we are

The Human Delta is an early-stage initiative based in Sweden. We are not yet registered as a legal entity. Until we are, the founder operates the ecosystem and acts as the data controller for the personal data described here.

For any privacy question, data request, or concern, contact us at privacy@thehumandelta.com.

What we collect

We try to collect as little as possible. In practice, that means:

  • Account data (START™, Pivot Report™, future STRATOS™): email address, name, password hash, and the answers, results, and preferences you create inside the product.
  • Newsletter: email address and the fact that you subscribed.
  • Contact / forms: whatever you choose to send us (name, email, message).
  • Payments (where applicable): handled by Stripe. We receive a transaction reference and basic billing details — we never see or store your full card number.
  • Technical data: standard server logs (IP address, browser, page visited, timestamp) used for security and reliability.

Why we use it (legal bases under GDPR)

  • To provide the product — contract (Art. 6(1)(b)).
  • To send the newsletter — your consent (Art. 6(1)(a)), withdrawable at any time via the unsubscribe link.
  • To keep the services secure and working — legitimate interest (Art. 6(1)(f)).
  • To comply with tax, accounting and legal duties — legal obligation (Art. 6(1)(c)).

Who we share it with (subprocessors)

We use trusted third parties to run the ecosystem. They process data on our behalf, under contract, and only for the purposes we set:

  • Lovable — hosting and backend infrastructure for our websites and products.
  • Stripe — payment processing where paid features apply.
  • STRATO — domain registration.

If we add another provider (for example a dedicated newsletter or analytics tool), we will update this list before relying on them.

International transfers

Some of our providers may process data outside the EU/EEA. When that happens, we rely on the European Commission's Standard Contractual Clauses or an adequacy decision to keep your data protected to EU standards.

How long we keep it

  • Account data: while your account is active, then deleted on request or after a reasonable inactivity period.
  • Newsletter: until you unsubscribe.
  • Contact messages: up to 24 months, then deleted.
  • Payment records: as required by Swedish tax and accounting law (typically 7 years).
  • Server logs: short rolling window for security and debugging.

Your rights

Under GDPR you can:

  • Ask for a copy of the data we hold about you.
  • Correct anything that is wrong.
  • Ask us to delete your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw consent (e.g. for the newsletter) at any time.

Email privacy@thehumandelta.com and we will respond within 30 days. You can also lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local EU supervisory authority.

Security

We use encryption in transit (HTTPS), access controls, and reputable infrastructure providers. No system is perfect — we will notify affected users without undue delay if a personal data breach is likely to put their rights at risk.

Children

The Human Delta is intended for adults. We do not knowingly collect data from children under 16. If you believe a child has shared data with us, email us and we will delete it.

Changes to this policy

If we make material changes we will update the date at the top and, where appropriate, notify subscribers by email.

See also our Terms of Use and Cookie Policy.