Senast uppdaterad: August 5, 2026
Who is the data controller?
Step In Faith AB (Swedish org. no. 559101-8873), Björlanda Västergården, 511 99 Sätila, Sweden, which operates aSongio, is the data controller for the information you provide. Contact us at support@asongio.com with data protection questions.
What data we process
- Account details: email address, name and language
- Order details: package, add-ons, price, delivery date and order history
- Project content: your story, the recipient's name, places, memories, pronunciation notes and lyric versions
- Uploaded files: photos, documents and any voice recording for pronunciation
- Consents: which terms and choices you approved, when and from which device
- Technical information: error logs and de-identified visitor statistics
Why we process it
- To create, deliver and administer your order (performance of a contract)
- To meet accounting and tax requirements (legal obligation)
- To protect the service against misuse and fraud (legitimate interest)
- For newsletters and marketing (only with separate consent)
- To showcase a song publicly as an example (only with separate, explicit consent)
Data about other people
A song is almost always about someone other than you. Only share what's needed for the song. Avoid information about health, religion, sex life, criminal offenses or other sensitive matters unless necessary.
The person the song is about has the same rights as you — including the right to know what data we process and the right to request deletion. Contact us and we'll help.
Children
If a song is about a child, extra safeguards apply: the song is never published publicly, never used as an example, and never distributed to streaming services.
AI and your content
We don't train any AI model on your content. Lyric suggestions are generated by calling an AI provider from our server. We choose providers that offer not to retain or train on the content, and we list them in our subprocessor register.
Where data is stored
Our database and files are stored within the EU/EEA. Communication is encrypted, files are only accessible via short, signed links, and access to customer content is role-based and logged internally.
How long we keep data
- Stories, uploaded files and lyric versions: de-identified or deleted 12 months after delivery unless you choose to keep them
- Internal working files and demos: deleted 90 days after delivery
- Accounting records: kept as long as required by law
- Consent logs: kept as long as they may be needed as evidence
Your rights
- Get a copy of your data (data portability)
- Correct inaccurate data
- Delete a project or your entire account
- Object to or restrict certain processing
- Withdraw consent at any time
- Lodge a complaint with the Swedish Authority for Privacy Protection (IMY) or your local data protection authority
Subprocessors
We use vendors for hosting, payment, email, AI writing support, error monitoring and analytics. An up-to-date list is published and maintained. We sign a data processing agreement with each of them.
If something goes wrong
In the event of a personal data breach, we investigate the scope, limit the damage, notify IMY within 72 hours when required, and inform affected individuals if the risk is high.
Draft. Must be reviewed by legal counsel before launch. A data protection impact assessment (DPIA) will be completed before launch, since the service processes personal stories about people who are not themselves customers.