Privacy Policy

Last updated: 2 October 2026

Introduction

The website infrabase.ai, its public API and its MCP server (together the "Service") are operated by Andersson-Larsson Holding AB, company registration no. 559254-7078 ("we", "us", "our").

This Privacy Policy describes how we collect and process Personal Data when you visit the Service, submit a product, request a featured listing, sign up for our newsletter or contact us. It covers the legal basis for the processing, how long data is kept, who it is shared with and your rights under the GDPR. We handle Personal Data in accordance with the GDPR and the Swedish legislation that supplements it.

The latest version is always available at infrabase.ai/privacy.

Definitions

"Personal Data", "Processing", "Data Subject", "Sub-processor", "Personal Data Breach" and "Supervisory Authority" have the meaning given in article 4 of the GDPR (Regulation (EU) 2016/679).

What Personal Data We Collect

We work by the principles of purpose limitation and data minimisation. Browsing the directory requires no account and no Personal Data from you.

We collect Personal Data only when you give it to us:

  • Product submissions (/submit): your email address, the product details you enter, your answers to the optional checkboxes and your IP address.
  • Edit suggestions on a listing: your suggestion, an optional email address and your IP address.
  • Featured listing requests (/advertise, the API or the MCP server): your email address, the product and any message. These are sent to us by email and not stored in our database.
  • Newsletter signups: your email address and your IP address.
  • Feedback from AI agents and readers ("agent stories"): the text you send, an optional email address and your IP address.
  • "Want to try" clicks on a product page: an anonymous random identifier stored in a cookie and linked to the product, plus your IP address.
  • Emails you send us.

IP addresses are stored only to prevent spam and abuse. They are deleted after 90 days.

Giving us Personal Data is voluntary. Without an email address we cannot reply to a submission or request.

Cookies

Forms and product pages set a session cookie that is needed for the site to work, including protection against forged form submissions. The "Want to try" button sets a cookie only when you click it, to remember that click. We use no advertising or tracking cookies.

Usage Information

We use Plausible Analytics, which does not use cookies and does not identify individual visitors.

When the public API or the MCP server is used, our server sends Plausible a usage event: which endpoint or tool was called, the names of the parameters used (not their values) and the caller's user agent string. Plausible sees our server's IP address for these events, not the caller's.

Data published in the directory, such as product listings, prices and descriptions of companies, is information about products and businesses. It is published under CC-BY-4.0.

Why We Process Personal Data and the Legal Basis

  • Legitimate interests: to review and publish submissions, act on edit suggestions and featured requests, reply to you, prevent spam and abuse and understand how the Service is used. Sensitive Personal Data is never processed on this basis. You may object at any time.
  • Consent: for the newsletter. You can unsubscribe at any time.
  • Contract: if you buy a featured listing, to deliver it.
  • Legal obligation: payment records are kept as long as the Swedish Bookkeeping Act (1999:1078) requires.

Storage of Personal Data

We keep Personal Data only as long as it is needed for the purpose it was collected for:

  • Submissions, edit suggestions and agent stories: as long as they are relevant to the listing or the request they concern.
  • Newsletter signups: until you unsubscribe.
  • "Want to try" clicks: as long as the product is listed.
  • Emails and featured listing requests: as long as the conversation or customer relationship is relevant.
  • IP addresses: 90 days.
  • Payment records: as long as the law requires.

You can ask us to delete your Personal Data at any time (see below).

Third-Party Services

We use the following services to run the Service:

  • Hosting and database: Render (United States)
  • Content delivery, DNS and security: Cloudflare
  • Email delivery: Postmark
  • Analytics: Plausible Analytics (EU)
  • Image storage for listing logos and screenshots: Amazon Web Services (no Personal Data)
  • Payments for featured listings: Stripe

Sub-processors and Transfer of Personal Data

We may share Personal Data with Sub-processors to deliver the Service, comply with law, protect our legal interests, or detect and prevent technical or security issues. Some Sub-processors are located outside the EU/EEA. In those cases the transfer relies on appropriate safeguards under the GDPR, such as the EU Standard Contractual Clauses or an adequacy decision. You can ask us for a list of the Sub-processors involved in Processing your Personal Data and for a copy of the safeguards used.

We do not sell Personal Data.

Your Rights

Under the GDPR you have the right to:

  • information about what Personal Data we Process and who it is shared with
  • access your Personal Data
  • have incorrect Personal Data corrected
  • withdraw a consent you have given
  • object to Processing based on legitimate interests
  • have your Personal Data deleted
  • restrict the Processing of your Personal Data
  • receive your Personal Data in a portable format
  • complain to us, or to the Swedish Authority for Privacy Protection (IMY) or the supervisory authority in your country

Some rights apply only in certain situations.

We make no decisions based solely on automated Processing, including profiling.

Deletion of Personal Data

To have your Personal Data deleted, email [email protected]. Once we have verified the request, your Personal Data is deleted within 30 days, except where the law requires us to keep it.

Security

We take reasonable technical and organisational measures to protect Personal Data. Access to systems containing Personal Data is restricted and password protected.

Personal Data Breach

Personal Data Breaches are documented and reported to the Swedish Authority for Privacy Protection when the GDPR requires it.

Links to Other Websites

Listings link to third-party websites. We are not responsible for their content or their handling of Personal Data. Their own privacy policies apply.

Changes to This Policy

We may update this Privacy Policy. Changes are published on this page with a new "Last updated" date.

Contact

Questions about this Privacy Policy or our Processing of Personal Data: [email protected].

Is your product missing?

Add it here →