Privacy Policy
Last updated: 17 July 2026
This Privacy Policy explains how Johannes Kieding AB processes personal data when you visit johanneskiedingconsulting.com, contact us, or express an interest in consultation, supervision, training, workshops or updates.
1. Data controller
Data controller: Johannes Kieding AB
Company registration number: 559589-3198
Postal address: Barbro Stigsdotters väg 106, 121 33 Enskededalen, Sweden
Email for privacy enquiries: johannes@acceleratedpsychotherapy.com
Website: johanneskiedingconsulting.com
2. Personal data we process
- Contact details: your name, email address and any other contact information you provide.
- Enquiries and communications: messages, requests for meetings or services, and correspondence.
- Registrations: information required for training, workshops, supervision or mailing lists.
- Contract and payment information: information needed for quotations, contracts, invoicing and accounting.
- Technical information: for example IP address, device, browser, time of access and security logs.
Please do not submit sensitive personal data, patient information or medical-record information through the website’s forms. The services offered through this website are not psychotherapy, psychological or medical treatment, or crisis care.
3. Purposes and lawful bases
- Enquiries and bookings: to take steps at your request before entering into a contract, where applicable, or on the basis of our legitimate interest in communicating with people who contact us.
- Delivery and administration: to perform a contract with you.
- Invoicing and accounting: to comply with legal obligations.
- News and updates: on the basis of your consent, which you may withdraw at any time.
- Website operation and security: on the basis of our legitimate interest in maintaining a secure and functional website. Cookies requiring consent are activated only after you have made a choice.
- Legal claims: where processing is necessary and permitted by law to establish, exercise or defend legal claims.
4. Where the data comes from
Personal data normally comes directly from you through forms, email, telephone calls, registrations or contracts. Technical data may be generated when you use the website.
5. Recipients and service providers
We may share personal data with service providers used for web hosting, website operation, forms, email, bookings, administration, accounting and IT security. They may process personal data only in accordance with our instructions and applicable agreements. Personal data may also be disclosed where required by law. We do not sell personal data.
6. Transfers outside the EU/EEA
If a service provider processes personal data outside the EU/EEA, we ensure that the transfer relies on a lawful mechanism, such as an adequacy decision or the European Commission’s Standard Contractual Clauses, together with supplementary safeguards where required.
7. Retention periods
- Contact enquiries are retained for as long as needed to respond to and follow up on the matter.
- Contract information is retained for the duration of the contract and afterwards for as long as needed for legal claims.
- Accounting records are retained for the period required by applicable accounting law.
- Mailing-list information is retained until you unsubscribe or withdraw your consent.
- Technical logs are retained only for as long as needed for security and website operation.
8. Your rights
Under the GDPR, you may have the right to request access to, rectification or erasure of your personal data, restriction of processing and data portability. You may object to processing based on legitimate interests and to direct marketing. You may withdraw consent at any time without affecting the lawfulness of processing carried out before the withdrawal.
We may need to verify your identity before responding to a request. Please contact us using the email address above. You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (IMY) via imy.se.
9. Automated decision-making
We do not use automated decision-making that produces legal effects or similarly significant effects concerning you.
10. Security
We use appropriate technical and organisational security measures based on the risks associated with the processing.
11. Cookies
For information about the cookies used on this website and how to manage your choices, please see our Cookie Policy.
12. Changes to this policy
We may update this policy when our processing activities or legal requirements change. The date at the top shows when it was last updated.