1 Data controller
Fluit System AB (Swedish company reg. no. 559421-4909)
Hörnellgatan 4, SE-931 30 Skellefteå, Sweden
Email: info@fluit.se
Support: support@fluit.se
How we handle your personal data, transparently and in accordance with the GDPR. Forms Appendix 3 to Fluit's customer agreement. This is a translation; in case of discrepancy the Swedish version prevails.
Fluit System AB (Swedish company reg. no. 559421-4909)
Hörnellgatan 4, SE-931 30 Skellefteå, Sweden
Email: info@fluit.se
Support: support@fluit.se
We collect the following personal data:
We process personal data in order to:
Processing is based on performance of a contract (Art. 6(1)(b) GDPR) when you use the service, legitimate interest (Art. 6(1)(f)) for operations and security, and legal obligation (Art. 6(1)(c)) for accounting requirements.
We share personal data with:
If you use Fluit and have enabled integrations — accounting systems, carrier booking, email inbox, an external AI assistant — data is also sent to them. These are connections you enable yourself, and you have your own relationship with that recipient. You control which they are in the service.
For transfers outside the EU/EEA we rely on the European Commission's Standard Contractual Clauses (SCCs) or the recipient's certification under the EU–US Data Privacy Framework.
We never sell your personal data to third parties.
Fluit has a built-in AI assistant. When you ask it a question, the conversation — and the data the assistant retrieves from the system in order to answer — is sent to OpenRouter, which forwards it to the model you selected. Depending on the model, the recipient is Anthropic or Google (USA), or Mistral AI (France).
The content is not used to train the models. Every request is sent on the condition that the recipient may not retain it for training, and without silent fallback to another provider if the selected one is unavailable. The model selected determines which provider answers. We log which provider received each individual request.
AI is an optional module. If it is not enabled for your organisation, no data leaves our Azure environment on behalf of the built-in assistant. If you are a user at a customer that uses Fluit, it is that customer, not us, who decides whether the module is enabled.
We keep the conversations for troubleshooting and to improve the assistant. No decisions with legal or similarly significant effects are made automatically by the AI — it suggests and carries out tasks you ask for.
You can connect an external AI assistant, such as Claude, to Fluit using the Model Context Protocol (MCP). You make the connection yourself, with your own login. In a consent step you choose the company, which areas the assistant may access, and whether it may only read or also carry out actions.
What is sent to the assistant. When the assistant calls one of Fluit's tools, we return the tool's result — data from your system, such as a customer, an order or a stock level. The assistant can never reach more than you yourself are permitted to see and do in that company.
What Fluit receives. The name of the tool being called and the parameters the assistant sends with it, such as a search term or an order number. We do not receive your conversation with the assistant, and we do not read the assistant's memory, chat history or files.
Who receives the data. The data returned by the tools ends up with the assistant's provider, for example Anthropic. It is you, or the organisation you work for, who chooses to send it there, in the same way as when you enable an integration. The provider's processing is governed by your agreement and terms with that provider, not by this policy.
What we store.
Some tools in turn use Fluit's built-in AI, for example to write a product description. In that case the section on AI features above also applies.
How to end the connection. Under My settings → Connected apps in Fluit, or by removing the connection in the assistant. An administrator can revoke connections for the whole company. The connection also stops working if your account or your access to the company is removed.
Questions about the connection are answered at support@fluit.se.
We keep personal data for as long as your account is active or as long as needed to provide the service. After termination the data is deleted within 90 days, except for data that must be kept by law (e.g. accounting records for 7 years).
Under the GDPR you have the right to:
Contact us at info@fluit.se to exercise your rights.
Our website stores your cookie choice and light/dark mode locally in your browser (localStorage). This data never leaves your device.
If you consent via the cookie banner, we also use cookies for analytics (to understand how the website is used, via Google Tag Manager/Google Analytics) and marketing (campaign measurement, e.g. Google Ads). No such cookies are set, and no requests are sent to Google, before you have given your consent.
You can change or withdraw your choice at any time via Cookie settings (Cookieinställningar) at the bottom of the page, under Legal. There you see your current choice and can switch analytics or marketing off again. A withdrawal takes effect immediately: no further measurement takes place, and on the next page load the measurement tag is not loaded at all.
We take technical and organisational measures to protect your personal data, including encryption, access controls and regular security reviews.
If you believe we are processing your data incorrectly, you have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), www.imy.se.
We may update this policy. Material changes are announced by email or in the service.