Privacy Policy
Privacy Policy
Last updated: August 2026
This Privacy Policy explains how Forsmangruppen Karlstad AB ("we", "us") handles information in connection with the website pelleforsman.com and the content tools we operate to publish to social media accounts — both our own and those of clients who have granted us access.
Who we are
Forsmangruppen Karlstad AB, org.nr 559427-7302, Bergsundsgatan 7, 117 37 Stockholm, Sweden — trading as Pelle Forsman. Contact: pelle@forsmangruppen.com.
Information we collect
We keep data collection to a minimum.
- Website: standard server logs (IP, browser, pages viewed) for security and basic analytics. If you use the on-site assistant, your message is sent to our AI provider to generate a reply and is not used for advertising.
- Social publishing: we use the official APIs of Instagram (Meta), TikTok, and YouTube (Google) to publish content to our own accounts and, where a client has granted us access, to theirs. Through those APIs we access only what publishing and reporting require: the access token, the account identifier, username and profile picture, the posts we schedule or publish, the engagement metrics returned for them, and — where the client asks us to manage it — comments on those posts. We never receive passwords, and we do not access private messages or follower lists. See Accounts we manage for clients below.
- Business outreach: we process business contact details in order to contact companies about our services. That processing is described in full in the section Business outreach below.
How we use information
To operate and secure the website, respond to inquiries, and publish our own posts to our own connected social accounts. We do not sell personal data.
Third-party services
We rely on Meta (Instagram/Facebook), TikTok, Google (YouTube), Cloudflare, and Vercel. Your use of, and their handling of data is governed by their respective privacy policies.
Accounts we manage for clients
We produce and publish content on social media accounts belonging to our clients. This section explains that arrangement, because it is the part of our work that involves an account we do not own.
How we get access
A client grants us access themselves — either by giving our business portfolio partner access to their Facebook Page and Instagram account, or by authorising our app directly through Meta's login flow. We never ask for and never accept a client's password. The client remains the owner of the account at all times and can withdraw our access at any moment, without our involvement, from their own Meta settings or from Instagram under Settings → Apps and websites.
What we access, and why
- The access token and account identifier — without these we cannot publish at all. Tokens are stored encrypted at rest, on our own infrastructure, and are never shared with anyone else.
- The content we publish — the videos, images and captions we produce for the client, which the client approves.
- Engagement metrics for those posts — reach, views, saves and follower counts, used to report to the client and to decide what to make next.
- Comments on those posts, only where the client has asked us to moderate or respond to them.
We do not access private messages, follower lists, ad accounts, or anything belonging to people who interact with the client's account beyond the public comments described above. We do not use client data to train models, and we never combine one client's data with another's.
Our role in law
For a client's account we act as a processor under the GDPR and the client is the controller: we act on their documented instructions, under a written agreement, and we do not decide the purposes of the processing. For our own accounts we are the controller.
Retention and ending the relationship
We keep a client's tokens and content for as long as we are engaged by them. When the engagement ends, or when the client withdraws access, we revoke and delete the token, delete the channel from our scheduler, and delete the media library we held for them. Content already published belongs to the client and stays on their account.
Anyone can request deletion at any time — see Data deletion for the two routes and what happens next.
AI-generated content
Some of the content we produce is generated or assisted by AI. Where that is the case it is disclosed on the content itself, in line with the EU AI Act and the platforms' own labelling rules.
Business outreach — how we handle your data if we contacted you
This section applies if you received an email, LinkedIn message or call from us and did not contact us first. It exists because Article 14 of the GDPR requires us to tell you what we hold and, in particular, where we got it.
Who is responsible
Forsmangruppen Karlstad AB, org.nr 559427-7302, Bergsundsgatan 7, 117 37 Stockholm, Sweden. Contact: pelle@forsmangruppen.com.
Why you are hearing from us
We contact businesses we believe our services are relevant to. The contact is addressed to you in your professional capacity, not as a private individual. We do not market to consumers.
What we process
Your name, professional role, employer, and business contact details (work email address, business phone number, LinkedIn profile). We do not process special-category data, and we do not collect private contact details.
Where the data came from
One or more of the following: the company's own public website, public company registers, LinkedIn or an equivalent professional network, and commercial business-contact databases. If you want to know precisely which source applies to your record, email us and we will tell you specifically.
Legal basis
Legitimate interest (GDPR Article 6(1)(f)) — our interest in offering relevant services to businesses, balanced against your privacy. We have documented that balancing assessment and will share it on request.
How long we keep it
Business contact details for a maximum of 24 months from our last contact with you. If you opt out, we keep only the minimum needed to make sure we do not contact you again — that is the entire purpose of that record.
Your rights
You have the right to object to direct marketing, and if you do we stop immediately and without argument. You also have the right of access, rectification, erasure, restriction, and data portability. Email pelle@accesslyai.com and we will respond within 30 days. You may also complain to the Swedish Authority for Privacy Protection (IMY, imy.se).
How to opt out
Reply to the message with "unsubscribe" (or "avregistrera"), or email pelle@accesslyai.com. One line is enough. We will not ask why, and we will not contact you again.
Data retention & your rights
We retain data only as long as needed for the purposes above. You may request access to, correction of, or deletion of any personal data we hold about you by emailing pelle@accesslyai.com. Access tokens for our own social accounts can be revoked at any time from the respective platform's settings.
Changes
We may update this policy; material changes will be reflected by the "last updated" date above.