Privacy Policy

Last updated: 23/08/2026

Dynamic Factory ("we", "us") operates d365guide.com and values your privacy. This policy describes how we collect, use, store and protect your personal data in accordance with the General Data Protection Regulation (GDPR) and applicable electronic-communications legislation.

1. Data controller

Dynamic Factory is the data controller for all processing described below. Contact details are in section 12.

2. Which personal data do we collect?

  • Contact details you provide — name, email, phone, company, role and message text via contact forms, partner applications, e-book downloads and lead forms.
  • Technical information — IP address (stored anonymised, see section 7), browser type, device, referrer and visited pages.
  • Interaction data — clicks on partner links, choices in matching guides, exposure to filter options.
  • Cookies and similar technologies — see section 9.

3. Purposes, legal basis and retention

ProcessingLegal basisRetention
Handling contact enquiries and advisoryLegitimate interest (respond to enquiry) / Contract performance24 months after last contact
Forwarding leads to partnersConsent (you actively choose to send an enquiry)36 months (for traceability and dispute resolution)
E-book / newsletterConsentUntil consent is withdrawn
Analytics via Google Analytics 4Consent (ePrivacy + GDPR)14 months (GA4 default)
Marketing (Google Ads, Snitcher)Consent13 months
Anonymised click and visitor statisticsLegitimate interest (anonymised data)36 months
Accounting and partner contractsLegal obligation (accounting law)7 years

4. Data processors and subprocessors

We use the following providers to process personal data on our behalf. Data Processing Agreements (DPA) are in place with each of them.

ProviderPurposeData location
Supabase (database, authentication)Storage of leads, partner data, statisticsEU (Frankfurt)
Lovable (hosting)Website operationEU / global CDN
AWS Simple Email Service (SES)Transactional email (leads, confirmations)EU (Stockholm/Ireland)
Google (Analytics 4, Ads)Analytics and conversion measurementUSA — transferred under EU-U.S. Data Privacy Framework + SCC
SnitcherB2B company identification (not individuals)EU
Lovable AI GatewayAI-driven analyses and recommendationsEU/USA via SCC

Transfers to third countries (USA): When data is transferred to US-based services (primarily Google) it takes place under the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework and, where required, Standard Contractual Clauses (SCC) with supplementary technical safeguards.

5. Sharing of personal data

  • Partners you actively choose to contact — when you send an enquiry through our platform your details are forwarded to the chosen Dynamics 365 partner. We never link directly to partner websites; all contact goes through our mediated lead system.
  • Subprocessors — per section 4.
  • Authorities — when we are legally required to disclose data.

6. Your rights

Under GDPR you have the right to:

  • Access — know what data we process about you.
  • Rectification — have inaccurate data corrected.
  • Erasure — be forgotten when the data is no longer needed.
  • Restriction — pause processing in certain cases.
  • Data portability — receive your data in a structured format.
  • Objection — object to processing based on legitimate interest.
  • Withdraw consent — at any time, without affecting the lawfulness of prior processing.

Contact us per section 12. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority.

7. Anonymised click analytics

To understand how visitors use the site we collect anonymised statistics when partner links are clicked:

  • Masked IP address — only the first two octets are stored (e.g. "192.168.x.x"), so individual users cannot be identified.
  • Click data — which partner, timestamp and source page.

Legal basis: legitimate interest in improving the service. Since data is anonymised at collection, no cookie consent is required for this processing.

8. B2B visitor identification

With your consent (category "Marketing") we use Snitcher to identify which companies visit the site — based on public IP registers. The service does not identify individuals, names or email addresses.

Legal basis: consent. You can change your choice at any time via the .

9. Cookies and consent

Under the ePrivacy Directive, active consent is required before non-essential cookies are set. When you visit the site only strictly necessary cookies are set. Other cookies are activated only when you click "Accept all" or select categories in the banner.

We use the following categories:

  • Necessary — session management, security, stored consent choice. No consent required.
  • Statistics — Google Analytics 4 with anonymised IP. Stored for 14 months.
  • Marketing — Google Ads conversion tracking and Snitcher B2B identification. Stored for up to 13 months.

How the consent flow works

  1. Before any choice — Google Consent Mode v2 is initialised with every category set to denied. Google Analytics is not loaded at all: the gtag.js script is only requested after consent is given.
  2. The banner appears — you can accept all, accept only necessary, or open "Customize" to toggle Statistics and Marketing separately.
  3. Your choice is stored in your browser (local storage key cookie-consent-v2) together with a timestamp. Nothing is sent to a server.
  4. Tags react immediately — accepting Statistics loads Google Analytics 4 during the same visit; accepting Marketing enables Google Ads conversion measurement and Snitcher. Declining keeps them switched off.
  5. Withdrawing consent — reopen the cookie settings and save a new choice. Consent Mode is updated instantly and no further analytics or marketing data is collected.

You can reopen the settings at any time from this page or from the "Cookie settings" link in the footer, on every page of the site.

10. Security

We apply technical and organisational measures to protect your personal data: TLS encryption, access control, Row-Level Security in the database, logging of admin access and regular security scans.

11. Changes to this policy

We may update this policy. The most recent version is always available here. Material changes will be communicated in a suitable way.

12. Contact us

Dynamic Factory

Email: thomas.laine@dynamicfactory.se

You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY), or your local supervisory authority, if you consider our processing to violate GDPR.